This is the exact failure mode threshold-shielded routing is built to remove.
The 1–4 block lead here exists because the route was visible before execution. If the intent had been shielded and computed by a private committee instead of probed on public transactions, there'd have been nothing to lead on.
By utilizing Occlusion Protocol, solvers stake $OCLU in the Solver Registry to operate. The bond gets slashed if an ex-post audit finds a trade routed worse than the public benchmark, and the slashed amount is paid to the affected trader. Routing priority scales with a solver's integrity score and the size of that bond.
Separately, any holder can stake $OCLU into the protocol's revenue pool and earn a share of routing fees and the treasury's cut of slashed bonds. No solver operation required.
Hey @fomo, @seyong and @RelayProtocol, check your team or partners: someone is front-running your users (sandwich attack) on the Robinhood chain, likely using private order info.
Wallet: 0x44c0ba0b734d4b7705fcd07ddae9fbbc078d74dd
Contract (since Sep 24): 0x68a04a63fd1d8eabf167ef48ed0a0ef06c2374d9
Solver affected: 0xccc88a9d1b4ed6b0eaba998850414b24f1c315be
Impact on your users: ~$14k+ in the first day
Sandwich attacks: 328
Typical lead over your solver: 1–4 blocks
Solver volume hit: ~$412k
Every launch on this chain is starting to look the same. Fresh pair goes live, volume shows up in the first block, and a wallet nobody has seen before extracts most of the upside before real buyers get a fill. The wallet changes every time. The mechanism doesn't.
That mechanism is observability. Routing state, pending intents, and pool deltas are all readable before settlement, so anyone watching the mempool can price a launch's first few blocks better than the people actually buying into it.
Occlusion is built around removing that observability rather than reacting to whoever is currently exploiting it. A trade intent gets committed as an Orchard-style note, hashed and unreadable the moment it lands on chain. That commitment is Shamir-split across a rotating MPC committee selected each epoch by Bittensor's stake-weighted consensus, so pricing math and route selection both happen across shares held by different nodes, no single party ever holding the plaintext order. Only at the exact moment the swap executes are the nullifier and the intent revealed, in the same transaction, so there's no window between "known" and "settled" for anyone to act on.
The part we think actually matters for launches specifically: since there's nothing to read pre-settlement, there's no calibration signal either. A lot of the extraction we've been seeing depends on small probing transactions that measure how a pool responds before committing to the real attack. Shield the intent and that probe returns nothing.
We're not proving routing was optimal in real time, that's not practically provable. Instead every fill gets checked after the fact, publicly, by the same subnet, and a solver that delivers a bad fill gets slashed, the trader made whole from that solver's bond.
$OCLU secures this as solver bonding collateral.
0x449ca622a0a6137bf3ad492b5d7c58b866859b95
Wiring in the subnet and the rest of the live infrastructure today, registration, committee formation, the solver registry, and the audit pipeline.
The Dashboard will continue to update as each piece comes online.
Sandwich attacks on solvers that route on-chain aren't a coin flip. The attacker has to calibrate perturbation size precisely, big enough to profit, small enough that the solver's own probe-and-revert logic doesn't reroute to a different pool. That precision only exists because the probes are public.
Occlusion removes the signal entirely. Intent is shielded, routing is computed by a private MPC committee, and the trade reveals only at settlement. No probes, no boundary to calibrate against.
Solvers bond $OCLU to operate under this model, slashed if an audit later finds a trade routed worse than the public benchmark.
$OCLU: 0x449ca622a0a6137bf3ad492b5d7c58b866859b95
Mechanically: the intent (pair, size, max slippage) is Shamir secret-shared across a rotating committee, threshold t-of-n. No single node ever holds enough shares to reconstruct it.
The committee jointly evaluates routing using mixed-protocol MPC, arithmetic sharing for the pricing math, garbled circuits for the comparison logic that picks the best pool. The output is a threshold-signed route decision. No plaintext amount ever touches a public transaction until execution.
Reveal and execution happen atomically, same block. There's no interval where the trade is public but not yet settled, which is the exact window this kind of attack lives in.
@fomo@seyong@RelayProtocol
A new attacker address every few days is a sign the underlying leak, not the wallet, is the real problem. Blocklisting one address just relocates the extraction to the next one.
Occlusion shields the intent before it's a target, computes routing through a private MPC committee, and reveals the trade only at the moment it settles. There is nothing to rotate toward.
FINALLY found the "@FOMO MEV ATTACKER" 🚨
this is the guy destroying your FOMO entries:
0x44c0ba0b734d4b7705fcd07ddae9fbbc078d74dd
They frontrun FOMO buyers actively...
A new victim every minute!!!
they switch addresses every other day. current one:
0xb49deec1a52eea46f3a6a158f8f9b155809b8c44
@seyong your users are being affected by these sandwich attacks every minute. FIX THIS ASAP.
Solvers stake $OCLU in the Solver Registry to operate. The bond gets slashed if an ex-post audit finds a trade routed worse than the public benchmark, and the slashed amount is paid to the affected trader. Routing priority scales with a solver's integrity score and the size of that bond.
Separately, any holder can stake $OCLU into the protocol's revenue pool and earn a share of routing fees and the treasury's cut of slashed bonds. No solver operation required.
◘ Intent: shielded via an Orchard-derived commitment
◘ Routing: computed privately by a rotating MPC committee
◘ Execution: route and amount revealed atomically
◘ Audit: every fill checked against the public benchmark after
◘ Bonding: solvers stake $OCLU, slashed on proven bad execution.
Introducing Occlusion.
Shielded execution for Robinhood Chain.
A trade's route stays unreadable until the block that settles it. Solvers compute privately through a threshold MPC committee, post collateral in $OCLU, and get audited after every fill.