A leaked lower bound on swap size can make a sandwich profitable at every size the leak permits. The boundary is exact for the fee-free constant-product pool studied by Lin, Li and Lai; to first order, it is execution cost divided by the victim's slippage tolerance. Their pool uses the Uniswap v2 pricing rule with the fee removed. The derivation is clean. The policy advice needs more care than the abstract's one-line prescription gives it.

The trade the leak exposes

The victim buys token Y with token X from reserves (X, Y). Swap size q is hidden, while direction and slippage tolerance τ are public. The authors treat public direction as a substantive assumption. What leaks is an interval containing q: either [ℓ, u] or (0, u]. The attacker buys Y ahead of the victim, lets the victim fill at a worse price, then sells back. Gross profit is in token X and does not depend on Y at all.

The front-run has to leave the victim at least (1 − τ) of its honest output for every q the leak permits. Otherwise the slippage guard reverts a trade at some consistent size. Two or more symmetric, risk-neutral traders bid in a first-price auction for the single slot. There is no data. The paper reports no experiments; its only empirical anchors are cited counts: McLaughlin, Kruegel and Vigna found 63,257 sandwich attacks, and Bai et al. found 60,946 sandwich events in 210,000 Ethereum blocks.

The smallest possible victim sets the size

The victim's output after a front-run, measured as a fraction of honest output, rises with q. A smaller victim therefore takes the larger proportional hit, making ℓ the binding size for the slippage constraint. Feasible front-runs occupy [0, a_max(ℓ, τ)]. The endpoint a_max, the largest front-run allowed by the leak, depends only on X, τ and ℓ.

Profit also rises with front-run size and victim size. Choosing a_max thus maximizes pointwise, expected and worst-case profit alike; sizing presents no tradeoff among them. Worst-case gross profit is τℓ(X+ℓ)/(X+τℓ). We re-derived the key identity by hand. It makes the profit derivative in a equal to qX² times a positive term over D², and it holds.

An implementer can take the formulas for a_max, W and the threshold λc straight from the paper. None requires a posterior.

Where does the guarantee begin?

In the authors' worked example, X = 10^6, τ = 0.02 and c = 100. Costs are 10^-4 of the input reserve. They obtain λc/X ≈ 0.0049757, or λc ≈ 4,976. A leaked floor of a few hundred units gives no guarantee; a floor near 5,000 does. The first-order estimate c/τ also gives 5,000, close to the exact boundary at that tolerance.

The gap grows at tighter tolerances. With c/X = 10^-4 and τ = 0.001, the authors' table gives 0.09162; c/τ gives 0.1, about 9% above the exact value. Use the exact square-root formula for implementation and c/τ for a mental check. Across that table row, λc/X falls from 0.09162 at τ = 0.001 to 0.00498 at τ = 0.02. Halving the victim's tolerance roughly doubles the lower bound that can leak without guaranteeing a profitable sandwich.

Bit-prefix leakage, which reveals leading bits of swap size, shows what this means for disclosure. At τ = 1%, c = 10^-4 X and sizes up to 0.06X, more revealed bits expose more bins. Each bin is the size range fixed by the first d bits. The unexposed range contracts toward λc ≈ 0.0099X and always contains (0, λc].

Below the floor, expected profit remains

A trader or mempool designer should keep the distinction in view. λc marks the point where an attack pays at every consistent size. An attack can still pay in expectation below it. The authors say: "Perfect hiding thus removes the uniform guarantee, while attacks that pay in expectation can remain." With a leak of (0, Q], the front-run a0 = X((1−τ)^(-1/2) − 1) is feasible at every size. Put enough posterior weight near Q for R_s > 0, and a sandwich still occurs on path. The auctioneer collects R_s.

The authors limit their prescription to sandwiches "that profit at every consistent size". That scope matters. As the paper notes, R_s determines whether the auction places a sandwich. When R_s > 0, the winning bid is R_s: posterior expected gross profit from a_max minus c. The posterior covers the whole interval. The abstract says "the upper end of the range is irrelevant", with the qualification appearing only in Section 4. The claim holds for feasibility and λc. Whether a sandwich happens on path depends on u and the prior through R_s. Keeping every leaked floor below λc rules out guaranteed-profit sandwiches alone. In the chance-constrained variant, a lower posterior quantile q_ε takes the place of ℓ. This weakly enlarges the feasible set and makes the threshold depend on the distribution.

Post-trade arbitrage survives even perfect pre-trade hiding.

If an outside market still quotes Y at the pool's pre-trade price, an observer of the post-trade reserves can take up to q²/(X+q) gross.

The auctioneer takes the rent

For R_s > 0, every pure-strategy perfect Bayesian equilibrium gives the slot to a_max at payment R_s. The winner has zero expected utility; the auctioneer receives the full net rent. This rests on symmetric traders, a fixed cost and deterministic tie-breaking. The authors note that discrete bids, asymmetric costs or random ties would bring in mixed strategies. For a searcher, the implication is blunt: whoever sells ordering owns the edge in this model.

Limits of the closed forms

Checking how often R_s is positive on chain requires pool reserves, pending swaps and their slippage limits, plus control of ordering. Price bars supply none of these.

The threshold is exact and can cap any lower bound a disclosure policy leaks. An on-chain estimate of R_s under realistic leaks would show whether staying below λc protects anyone in practice. If that estimate were near zero, we would rate the paper's policy value higher.