Solana Heavyweights Wage War Against Private Mempool Operators
Validators found to be facilitating sandwich attacks face stiff penalties.

A group of Solana
Over 30 validator operators were kicked off the Solana Foundation Delegation Program over the weekend, a source familiar with the matter said. While they remain validators on the network, they're no longer eligible to receive what amounted to payout boosters for validating transactions on the Solana blockchain. Many of the operators were Russians, another source said.
The purge escalates a months-long shadow war between heavyweights of the Solana validator ecosystem and an underground economy of validators believed to be exploiting traders for profit through what's known as a "sandwich attack," whereby bots frontrun and backfill trades that haven't yet been executed.
It's among the more notorious maximal extractable value, or MEV, strategies possible on blockchains that rely on mempools, which are essentially waiting rooms for unconfirmed transactions. Solana doesn't have a native mempool, but the wildly popular validator software developed by Jito Labs once did.
In March, at the height of Solana's meme coin frenzy, Jito Labs shut off the mempool function because it was exposing traders to near-constant and costly sandwich attacks. Jito's CEO framed the move as being in the best interest of the Solana ecosystem even if it cut off one potential revenue stream for validators, the server operators who keep things running on this decentralized network.
Rather than completely solve the problem, Jito's move pushed it underground. Whispers quickly emerged of private mempools whose operators were making at times hundreds of thousands of dollars by enabling sandwich attacks.
One proposal from infrastructure operator DeezNode offered validators who opted into its private mempool 50% of the profits generated by MEV, according to documents reviewed by CoinDesk.
A Jito Foundation governance post from late Sunday indicates 10% of the JitoSOL pool is being delegated to validators running private mempools. The Jito Foundation has proposed imposing further economic penalties on those validators by way of restricting yet more staked SOL.
Solana Foundation's own delegation blacklist is small as a portion of the delegation program. It targets a total of 32 operators that together had 1.5 million SOL, about 0.5% of program stake, a source said.
"Enforcement actions are on going as we detect operators participating in mempools which allow sandwich attacks," a representative for the Solana Foundation said Sunday.
Більше для вас
Protocol Research: GoPlus Security

Що варто знати:
- As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
- GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
- Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.
Більше для вас
Telegram Ring Ran Pump-and-Dump Network That Netted $800K in a Month: Solidus Labs

A Solidus Labs investigation details how an invite-only Telegram group used bots, fake narratives and rapid token deployments across Solana and BNB Chain to manipulate markets.
Що варто знати:
- PumpCell orchestrated synchronized token launches, sniper-bot buys and meme-driven hype campaigns to inflate micro-cap tokens to seven-figure valuations within minutes, according to a new forensic investigation by Solidus Labs.
- The group generated an estimated $800,000 in October 2025, moving funds through centralized exchanges and an OTC cash broker to allegedly evade compliance controls.
- Solidus says crypto’s AMM-driven markets, bot execution and cross-chain pseudonymity make such schemes difficult for legacy monitoring tools to detect — and warns PumpCell reflects a broader, evolving pattern of digital-asset abuse.











