Pith. sign in

REVIEW 3 major objections 141 references

Time Is Money: Incentivized Causal Transaction Ordering

T0 review · 3 major / 0 minor · reviewed 2026-07-14 · grok-4.5

Pith's one-line read A power-weighted random lottery lets users deter front-running with one bid, so attackers rationally stay out and causal order holds.

desk verdict Solid mechanism-design paper that turns front-running into an unprofitable entry game via a power-weighted lottery; closed-form deterrence bid and SPNE are clean, practical k is far better than the analytic bound, but everything hinges on known constant γ. read the letter →

arxiv 2607.11496 v1 pith:655GJA5B submitted 2026-07-13 cs.CR cs.DC

classification cs.CRcs.DC
keywords front-runningtransactionorderingmechanismdesignentrydeterrencepower-weightedlotterysandwichattacksblockchainMEVsubgame-perfectequilibrium
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Front-running lets attackers snatch rewards from useful blockchain transactions once they see them in the mempool, which destroys the incentive to publish those transactions. Existing ordering rules either fail to enforce the true causal order or turn the problem into a pure bidding war. This paper offers PRECEDE: order every transaction by a randomized lottery whose winning probability is proportional to bid^k with k greater than 1. Under that rule a user who finds an opportunity first can post a single, closed-form “deterrence bid” that makes every later entrant’s expected revenue non-positive. When k is large enough the strategy is a subgame-perfect equilibrium, the user still keeps a positive share of the reward, spam is unprofitable, and sandwich attacks are blocked at the same cost. The only on-chain change required is the ordering function itself.

What carries the argument

The power-weighted randomized lottery (weight b^k, k>1) together with the closed-form deterrence bid derived from setting the attacker’s expected-revenue function non-positive for all positive counter-bids. Super-linearity squeezes both cheap and expensive counter-bids out of the profitable region, so a single user bid deters entry.

What would settle it

On a live Uniswap V2/V3 fork with measured γ, post the closed-form deterrence bid for a known arbitrage of size R and check whether any rational counter-bid still yields positive expected profit under the power-weighted lottery; a profitable counter-bid falsifies the claim.

Watch

Extended reading notes

Core claim

Under the power-weighted lottery w(b)=b^k the smallest bid that deters every rational attacker is the closed-form b^{k,γ}_dtr = R*((k-1)^{k-1}/(γ k^k))^{1/k}. When that bid is posted, attacker revenue is non-positive for every counter-bid; when k meets explicit thresholds the same strategy together with attacker abstention is a subgame-perfect Nash equilibrium of the multi-step game, simultaneously satisfying Causal Ordering, Anti-Spam and Profitability.

Load-bearing premise

Every participant must know the exact losing-fee rate γ in advance by local pre-execution, and that rate must stay fixed for the whole competition; if γ is mis-estimated or path-dependent the deterrence bid can fail.

Editorial extensions

If this is right

  • Any censorship-resistant chain can adopt PRECEDE by changing only its transaction-ordering function.
  • Users keep a strictly positive share of the reward (up to γ/(1+γ)R at the revenue-optimal k) instead of watching it competed away.
  • Sandwich attacks are deterred at a cost strictly less than the loss they would inflict under pure bid-priority ordering.
  • Spam is dominated once k ≥ ln 2 / ln(1+γ), so multi-transaction flooding is no longer rational.
  • A single conservative k can be fixed for a measured range of γ values and still keep deterrence an equilibrium.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The same super-linear weight that deters front-running may also reduce other MEV races whose value is realized only by being first, such as liquidation sniping.
  • Because the mechanism needs only public bids and a public random beacon, it can be layered on top of existing encrypted-mempool designs without requiring the mempool itself to stay secret.
  • If chains raise the losing-fee rate γ, user revenue under PRECEDE rises for every k, giving protocol designers a direct lever to improve user surplus.
  • The multi-step SPNE proof suggests that even continuous-time arrival models with latency advantages for the attacker should still admit a pure deterrence equilibrium once k is large enough.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 0 minor

Summary. The paper proposes PRECEDE, a power-weighted randomized transaction ordering rule (weight b^k, k>1) that aims to enforce causal ordering against front-running by economic entry deterrence rather than by timestamps or encryption. A user who first discovers a reward R publishes a closed-form deterrence bid b^{k,γ}_dtr = R*((k-1)^{k-1}/(γ k^k))^{1/k}; under the model this makes every later entrant's expected revenue non-positive (Lemma 1, Theorem 1). The authors prove an anti-spam threshold k ≥ ln 2 / ln(1+γ) under which single bids dominate multi-bid strategies (Theorem 2), show that the same bound yields strictly positive user revenue (Proposition 2), and establish that deterrence plus attacker abstention is an SPNE of a multi-step sequential game when k is large enough that deterrence utility exceeds accommodation utility (Theorems 3–4, Corollaries 1–2). They also reduce sandwich defense to the same front-running game with R = V and discuss parameter selection using measured Uniswap gas ratios γ.

Significance. If the results hold under realistic conditions, PRECEDE is a genuine alternative to receive-order fairness and encrypted-mempool designs: it requires only a censorship-resistant collection phase, a public random beacon, and a change to the ordering function, and it targets incentive compatibility rather than cryptographic hiding. Strengths include explicit closed forms (deterrence weight/bid, anti-spam threshold, revenue-optimal k = 1 + 1/γ), full appendix proofs, a careful partial-pay contest model that matches blockchain fee mechanics better than classical all-pay Tullock contests, and independent mainnet-fork measurements of γ. The sandwich reduction and the anti-spam merging argument are particularly clean contributions to the MEV literature.

major comments (3)
  1. §3.2 and Lemma 1 / Eq. (3): The deterrence weight W^{k,γ}_dtr scales as 1/γ and the entire equilibrium apparatus (Theorem 1, Corollaries 1–2) assumes every participant knows an exact, constant losing-fee rate γ in advance by local pre-execution. In practice γ is path-dependent: gas on the revert path can change after a competing transaction has already mutated state, so the pre-execution estimate is only valid under a hypothesized order. An under-estimate of γ leaves a positive-revenue counter-bid for the true γ, so Causal Ordering fails for the published bid. The manuscript needs either a robustness margin (e.g., a conservative γ_min with a proved safety factor) or an explicit sensitivity analysis showing how much mis-estimation the deterrence bid tolerates; neither appears in the main theorems or in the numerical k-selection of §6 / App. J.
  2. Corollary 1 vs §6 / App. J: The only closed-form sufficient condition for the SPNE is k ≥ max{2, exp(1/γ)/γ}, which for the measured Uniswap V2 γ ≈ 0.259 forces k ≈ 184 and leaves the user only ~0.026R. The paper then relies on a numerical search claiming that the much smaller anti-spam bound k ≈ 3.010 already satisfies u^{k,γ}_dtr > u^{k,γ}_acc. That numerical claim is load-bearing for any practical deployment recommendation, yet it is confined to an appendix, uses a bounded search (k ≤ 20), and is not elevated to a theorem or even a formal conjecture with stated precision. Either strengthen the analytic bound or move a fully specified, reproducible numerical certificate into the main body and clearly separate 'formal SPNE' from 'numerically observed SPNE'.
  3. §5.1.1–5.1.2: Modeling a single colluding attacker is presented as worst-case, but the multi-step game also assumes perfect alternating observation, non-decreasing bids only, and that the attacker always moves last. The paper does not show that the deterrence SPNE survives (i) simultaneous or out-of-order moves, (ii) multiple non-colluding attackers who can free-ride on each other's entry attempts, or (iii) a validator who can both reorder and choose which of her own bids to include after seeing the random beacon. These are standard adversarial capabilities in the MEV setting the introduction targets; without at least a discussion of which of them break the SPNE, the equilibrium claim is narrower than the deployment claim in the abstract and conclusion.

Circularity Check

0 steps flagged · score 1.0 of 10

No significant circularity: deterrence bid, anti-spam threshold and SPNE are derived from the stated payment/weight model by direct calculus and backward induction; empirical γ is used only for parameter selection.

full rationale

The core objects are defined first (power weight w(b)=b^k, partial-pay revenue u(b;W) in Eq. 2, losing-fee γ known a priori). Lemma 1 maximises g(b)=R b^{k-1}-b^k by differentiation to obtain the closed-form deterrence weight W_dtr=(k-1)^{k-1}/(γ k^k) R^k; Theorem 1 and the bid b_dtr follow immediately. Anti-spam (Theorem 2) reduces revenue comparison of multi-bid versus equal-weight single bid to a payment inequality that is proved by calculus on binary splits plus a merging argument; the bound k≥ln2/ln(1+γ) is necessary and sufficient under the model. Profitability (Prop. 2) is the same bound. The multi-step SPNE (Thm. 4 / Cor. 2) is obtained by backward induction on the finite-horizon perfect-information game whose utilities depend only on final bids, using only the already-derived deterrence/accommodation comparison. Empirical γ values (App. A) are measured independently on a mainnet fork and appear solely in the practical k-selection of §6; they do not define any theoretical object. No equation equates a claimed prediction to a fitted constant by construction, and no load-bearing uniqueness or ansatz is imported by self-citation. The single minor self-citation (Chen et al. PRRR) is background only. Hence circularity score is 1 (near-zero).

Assumptions & free parameters 2 free parameters · 6 assumptions · 2 invented entities

The central claims rest on a standard rational-agent model plus a small set of blockchain-specific domain assumptions (censorship resistance, known γ, unpredictable beacon). The free parameter k is chosen by the designer; γ is measured. No new physical entities are postulated—only a new ordering rule and its associated strategy.

free parameters (2)
  • exponent k = ≈3.010 for γ∈[0.259,1.087]
    Protocol design parameter fixed by the chain; must satisfy anti-spam and equilibrium lower bounds that depend on γ. Chosen numerically for measured Uniswap ranges.
  • losing-fee rate γ = ≈0.259 (V2), [0.867,1.087] (V3)
    Measured empirically on Uniswap V2/V3 pools (Appendix A); treated as known constant in all closed forms. Varies by pool and path.
assumptions (6)
  • domain assumption All participants are rational expected-revenue maximizers; no altruism or spite.
    Stated in §3.1; used throughout the game analysis.
  • domain assumption The ordering protocol is censorship-resistant: every transaction published in [0,T] enters TX_all.
    §3.3; required for the deterrence strategy to be observed by attackers.
  • domain assumption An external unpredictable random beacon Q is available at ordering time.
    §3.1; used to realize the weighted lottery via score s(tx)=r(tx)^{1/b^k}.
  • domain assumption Bids are non-decreasing; a participant cannot lower an already-published bid.
    §3.3; standard on current chains and used in the multi-step game.
  • domain assumption γ is known exactly to every participant before bidding (via local pre-execution).
    §3.2; enters the closed-form deterrence bid (Eq. 3) and all revenue expressions.
  • standard math Existence of pure-strategy SPNE in finite-horizon perfect-information games with compact continuous action sets (Hellwig–Leininger 1987).
    Invoked in Lemma 4 after compactification of the bid space.
invented entities (2)
  • PRECEDE power-weighted lottery (weight b^k)
    purpose: Ordering rule that realizes entry deterrence while preserving anti-spam.
    Defined in §4.2; the paper’s central design object. Independent evidence is the closed-form analysis and numerical checks, not external measurement.
  • deterrence bid / deterrence weight W^{k,γ}_dtr
    purpose: Minimal bid that makes every later entrant’s expected revenue ≤0.
    Derived in Lemma 1 / Eq. 3; purely mathematical construct of the model.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Time Is Money: Incentivized Causal Transaction Ordering." pith.science (2026). https://pith.science/paper/655GJA5B

@misc{pith2026260711496,
  author       = {Pith},
  title        = {Pith review of: Time Is Money: Incentivized Causal Transaction Ordering},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/655GJA5B}},
  note         = {Machine review of arXiv:2607.11496}
}
read the original abstract

Front-running is a subtle and persistent problem for blockchains. A blockchain is a stateful virtual machine executing instructions called transactions. Users earn rewards by publishing functional transactions essential to the system. Attackers observe these transactions and publish their own ahead of the users', seizing the reward and eroding users' incentive to publish functional transactions. Preventing front-running means enforcing causality: If an attacker receives transaction tx_A and then publishes transaction tx_B, then tx_A must be ordered before tx_B. However, this causality is only observed by the attacker. Practical systems order transactions by bid amount, so transactions willing to pay more get executed first, but this only results in a bidding war eroding users' rewards. Though numerous ordering approaches have been proposed, none achieves causality, leaving users vulnerable to front-running. We present PRECEDE, a mechanism-design approach that enforces transaction causality by removing the economic incentive to front-run. PRECEDE orders transactions by a power-weighted randomized lottery, whose winning probability grows super-linearly in the bid. The user's strategy of publishing a transaction with a deterring bid forms an equilibrium where the attacker refrains from competing. Moreover, PRECEDE prevents the prominent sandwich attack, which relies on front-running. PRECEDE can be directly deployed in any censorship-resistant blockchain with a simple change to its transaction ordering mechanism.

Discussion (0). Sign in to comment.

Reference graph

Works this paper leans on

141 extracted references · 13 linked inside Pith

  1. [1]

    Crypto market cap tops $3 trillion as bitcoin and ether reach record highs,

    Y . Khatri, “Crypto market cap tops $3 trillion as bitcoin and ether reach record highs,” https://www.theblock.co/linked/123762/ crypto-market-cap-3-trillion-bitcoin-ether-reach-record-highs, Nov. 2021, accessed, January 2026

  2. [2]

    Defi TVL rebounds to $170b, erasing Terra-era bear market losses,

    O. Knight, “Defi TVL rebounds to $170b, erasing Terra-era bear market losses,” https://www.coindesk.com/business/2025/09/18/ defi-tvl-rebounds-to-usd170b-erasing-terra-era-bear-market-losses, 2025, accessed, November 2025

  3. [3]

    Ethereum white paper,

    V . Buterin, “Ethereum white paper,”GitHub repository, vol. 1, no. 22-23, pp. 5–7, 2013

  4. [4]

    Bitcoin: A peer-to-peer electronic cash system,

    S. Nakamoto, “Bitcoin: A peer-to-peer electronic cash system,” 2008

  5. [5]

    Solana: A new architecture for a high perfor- mance blockchain v0.8.13,

    A. Yakovenko, “Solana: A new architecture for a high perfor- mance blockchain v0.8.13,” https://solana.com/solana-whitepaper. pdf, 2018, accessed, April 2024

  6. [6]

    Improved price oracles: Constant function market makers,

    G. Angeris and T. Chitra, “Improved price oracles: Constant function market makers,” inProceedings of the 2nd ACM Conference on Advances in Financial Technologies, 2020, pp. 80–91

  7. [7]

    Prrr: Personal random rewards for blockchain reporting,

    H. Chen, Y . Ke, X. Deng, and I. Eyal, “Prrr: Personal random rewards for blockchain reporting,” in2026 IEEE Symposium on Security and Privacy (SP). IEEE, 2026, pp. 3835–3853

  8. [8]

    Resilient alerting protocols for blockchains,

    M. Mouallem, L. Breidenbach, I. Eyal, and A. Juels, “Resilient alerting protocols for blockchains,” inProceedings of the 33rd ACM Conference on Computer and Communications Security (CCS ’26). Association for Computing Machinery, 2026, to appear

Show all 141 references
  1. [9]

    Flash boys 2.0: Frontrunning in decentralized exchanges, miner extractable value, and consensus instability,

    P. Daian, S. Goldfeder, T. Kell, Y . Li, X. Zhao, I. Bentov, L. Breiden- bach, and A. Juels, “Flash boys 2.0: Frontrunning in decentralized exchanges, miner extractable value, and consensus instability,” in 2020 IEEE Symposium on Security and Privacy (SP). IEEE, 2020, pp. 910–927

  2. [10]

    Frontrunner Jones and the raiders of the dark forest: An empirical study of frontrunning on the Ethereum blockchain,

    C. F. Torres, R. Camino, and R. State, “Frontrunner Jones and the raiders of the dark forest: An empirical study of frontrunning on the Ethereum blockchain,” in30th USENIX Security Symposium, 2021, pp. 1343–1359

  3. [11]

    High- frequency trading on decentralized on-chain exchanges,

    L. Zhou, K. Qin, C. F. Torres, D. V . Le, and A. Gervais, “High- frequency trading on decentralized on-chain exchanges,” in2021 IEEE Symposium on Security and Privacy (SP). IEEE, 2021, pp. 428–445

  4. [12]

    A theoretical basis for MEV,

    M. Bartoletti and R. Zunino, “A theoretical basis for MEV,” inInter- national Conference on Financial Cryptography and Data Security. Springer, 2025, pp. 225–242

  5. [13]

    Sok: Preventing transaction reordering manipulations in decentralized finance,

    L. Heimbach and R. Wattenhofer, “Sok: Preventing transaction reordering manipulations in decentralized finance,” inProceedings of the 4th ACM Conference on Advances in Financial Technologies, 2022, pp. 47–60

  6. [14]

    Sui Lutris: A blockchain combining broadcast and consensus,

    S. Blackshear, A. Chursin, G. Danezis, A. Kichidis, L. Kokoris- Kogias, X. Li, M. Logan, A. Menon, T. Nowacki, A. Sonninoet al., “Sui Lutris: A blockchain combining broadcast and consensus,” in Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Sec...

  7. [15]

    Demystifying DeFi MEV activities in flashbots bundle,

    Z. Li, J. Li, Z. He, X. Luo, T. Wang, X. Ni, W. Yang, X. Chen, and T. Chen, “Demystifying DeFi MEV activities in flashbots bundle,” inProceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, 2023, pp. 165–179

  8. [16]

    A large scale study of the Ethereum arbitrage ecosystem,

    R. McLaughlin, C. Kruegel, and G. Vigna, “A large scale study of the Ethereum arbitrage ecosystem,” in32nd USENIX Security Symposium (USENIX Security 23), 2023, pp. 3295–3312

  9. [17]

    Order-fairness for Byzantine consensus,

    M. Kelkar, F. Zhang, S. Goldfeder, and A. Juels, “Order-fairness for Byzantine consensus,” inAdvances in Cryptology - CRYPTO 2020: 40th Annual International Cryptology Conference, Santa Barbara, CA, USA, Proceedings, Part III, 2020, pp. 451–480

  10. [18]

    Themis: Fast, strong order-fairness in Byzantine consensus,

    M. Kelkar, S. Deb, S. Long, A. Juels, and S. Kannan, “Themis: Fast, strong order-fairness in Byzantine consensus,” inProceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, 2023, pp. 475–489

  11. [19]

    Wendy, the good little fairness widget: Achieving order fairness for blockchains,

    K. Kursawe, “Wendy, the good little fairness widget: Achieving order fairness for blockchains,” inProceedings of the 2nd ACM Conference on Advances in Financial Technologies, 2020, pp. 25– 36

  12. [20]

    Byzantine or- dered consensus without Byzantine oligarchy,

    Y . Zhang, S. Setty, Q. Chen, L. Zhou, and L. Alvisi, “Byzantine or- dered consensus without Byzantine oligarchy,” in14th USENIX Sym- posium on Operating Systems Design and Implementation (OSDI 20), 2020, pp. 633–649

  13. [21]

    On frontrunning risks in batch-order fair systems for blockchains,

    E. Park, T. Yoon, H. Nam, D. Maram, and M. S. Kang, “On frontrunning risks in batch-order fair systems for blockchains,” in Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security, 2025, pp. 918–932

  14. [22]

    Transaction set canonical order- ing,

    XRPLF, “Transaction set canonical order- ing,” https://github.com/XRPLF/rippled/blob/ e32bc674aa2a035ea0f05fe43d2f301b203f1827/src/ripple/app/ misc/CanonicalTXSet.cpp, 2022, accessed, February 2026

  15. [23]

    Blindperm: Efficient MEV mitigation with an encrypted mempool and permuta- tion,

    A. Kavousi, D. V . Le, P. Jovanovic, and G. Danezis, “Blindperm: Efficient MEV mitigation with an encrypted mempool and permuta- tion,” in29th International Conference on Principles of Distributed Systems (OPODIS 2025). Schloss Dagstuhl–Leibniz-Zentrum f ¨ur Informatik, 2026, pp. 36–1

  16. [24]

    Timing games: Probabilistic backrunning and spam,

    B. Mazorra, C. Schlegel, and A. Mamageishvili, “Timing games: Probabilistic backrunning and spam,”arXiv preprint arXiv:2602.22032, 2026

  17. [25]

    Random ordering of equally- priced transactions incentivises competitive spam,

    go-ethereum Contributors, “Random ordering of equally- priced transactions incentivises competitive spam,” https://github.com/ethereum/go-ethereum/issues/21350, 2023, accessed, February 2026

  18. [26]

    Blockspace under pressure: An analysis of spam MEV on high- throughput blockchains,

    W. Wang, A. Saraf, L. Heimbach, K. Babel, and F. Zhang, “Blockspace under pressure: An analysis of spam MEV on high- throughput blockchains,”arXiv preprint arXiv:2604.00234, 2026

  19. [27]

    A ripple for change: Analysis of frontrunning in the XRP ledger,

    V . Tumas, B. B. F. Pontiveros, C. F. Torres, and R. State, “A ripple for change: Analysis of frontrunning in the XRP ledger,” in2023 IEEE International Conference on Blockchain and Cryptocurrency (ICBC). IEEE, 2023, pp. 1–9

  20. [28]

    F3b: A low-overhead blockchain architec- ture with per-transaction front-running protection,

    H. Zhang, L.-H. Merino, Z. Qu, M. Bastankhah, V . Estrada- Gali˜nanes, and B. Ford, “F3b: A low-overhead blockchain architec- ture with per-transaction front-running protection,”arXiv preprint arXiv:2205.08529, 2022

  21. [29]

    Adding fairness to order: Preventing front-running attacks in BFT protocols using TEEs,

    C. Stathakopoulou, S. R ¨usch, M. Brandenburger, and M. Vukoli ´c, “Adding fairness to order: Preventing front-running attacks in BFT protocols using TEEs,” in2021 40th International Symposium on Reliable Distributed Systems (SRDS). IEEE, 2021, pp. 34–45

  22. [30]

    FairPoS: Input fairness in proof-of-stake with adaptive security

    J. H.-y. Chiang, B. David, I. Eyal, and T. Gong, “FairPoS: Input fairness in proof-of-stake with adaptive security.”IACR Cryptol. ePrint Arch., vol. 2022, p. 1442, 2022

  23. [31]

    Commitment against front-running at- tacks,

    A. Canidio and V . Danos, “Commitment against front-running at- tacks,”Management Science, vol. 70, no. 7, pp. 4429–4440, 2024

  24. [32]

    BEAT-MEV: Epochless approach to batched threshold encryption for MEV prevention,

    J. Bormet, S. Faust, H. Othman, and Z. Qu, “BEAT-MEV: Epochless approach to batched threshold encryption for MEV prevention,” in 34th USENIX Security Symposium (USENIX Security 25), 2025, pp. 3457–3476

  25. [33]

    On the limits of encrypted mempools,

    P. Garimidi, J. Bonneau, and L. Heimbach, “On the limits of encrypted mempools,” a16z crypto Research, Jul

  26. [34]

    Available: https://a16zcrypto.com/posts/article/ limits-encrypted-mempools/

    [Online]. Available: https://a16zcrypto.com/posts/article/ limits-encrypted-mempools/

  27. [35]

    Time, clocks, and the ordering of events in a distributed system,

    L. Lamport, “Time, clocks, and the ordering of events in a distributed system,”Communications of the ACM, vol. 21, no. 7, pp. 558–565, 1978

  28. [36]

    How to securely replicate ser- vices,

    M. K. Reiter and K. P. Birman, “How to securely replicate ser- vices,”ACM Transactions on Programming Languages and Systems (TOPLAS), vol. 16, no. 3, pp. 986–1009, 1994

  29. [37]

    Secure and efficient asynchronous broadcast protocols,

    C. Cachin, K. Kursawe, F. Petzold, and V . Shoup, “Secure and efficient asynchronous broadcast protocols,” inAnnual International Cryptology Conference. Springer, 2001, pp. 524–541

  30. [38]

    Secure causal atomic broadcast, revisited,

    S. Duan, M. K. Reiter, and H. Zhang, “Secure causal atomic broadcast, revisited,” in2017 47th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN). IEEE, 2017, pp. 61–72

  31. [39]

    MAD-HTLC: because HTLC is crazy-cheap to attack,

    I. Tsabary, M. Yechieli, A. Manuskin, and I. Eyal, “MAD-HTLC: because HTLC is crazy-cheap to attack,” in2021 IEEE Symposium on Security and Privacy (SP). IEEE, 2021, pp. 1230–1248

  32. [40]

    Checkmate: Automated game-theoretic security reasoning,

    L. S. Brugger, L. Kov ´acs, A. Petkovic Komel, S. Rain, and M. Raw- son, “Checkmate: Automated game-theoretic security reasoning,” in Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, 2023, pp. 1407–1421

  33. [41]

    Uncle maker:(time) stamping out the competition in Ethereum,

    A. Yaish, G. Stern, and A. Zohar, “Uncle maker:(time) stamping out the competition in Ethereum,” inProceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, 2023, pp. 135–149

  34. [42]

    Bdos: Blockchain denial-of-service,

    M. Mirkin, Y . Ji, J. Pang, A. Klages-Mundt, I. Eyal, and A. Juels, “Bdos: Blockchain denial-of-service,” inProceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Secu- rity, 2020, pp. 601–619

  35. [43]

    On the instability of Bitcoin without the block reward,

    M. Carlsten, H. Kalodner, S. M. Weinberg, and A. Narayanan, “On the instability of Bitcoin without the block reward,” inProceedings of the 2016 ACM SIGSAC conference on computer and communi- cations security, 2016, pp. 154–167

  36. [44]

    Majority is not enough: Bitcoin mining is vulnerable,

    I. Eyal and E. G. Sirer, “Majority is not enough: Bitcoin mining is vulnerable,”Communications of the ACM, vol. 61, no. 7, pp. 95– 102, 2018

  37. [45]

    Combating front-running in the blockchain ecosystem,

    J. Byers, “Combating front-running in the blockchain ecosystem,” Master’s thesis, Lehigh University, 2022

  38. [46]

    Analysis of front running vulnerabilities in solidity smart contracts,

    H. Zecirovic, “Analysis of front running vulnerabilities in solidity smart contracts,” Ph.D. dissertation, Technische Universit ¨at Wien, 2024

  39. [47]

    Front-running attack in sharded blockchains and fair cross-shard consensus,

    J. Zhang, W. Chen, S. Luo, T. Gong, Z. Hong, and A. Kate, “Front-running attack in sharded blockchains and fair cross-shard consensus,”arXiv preprint arXiv:2306.06299, 2023

  40. [48]

    No fish is too big for flash boys! frontrun- ning on DAG-based blockchains,

    J. Zhang and A. Kate, “No fish is too big for flash boys! frontrun- ning on DAG-based blockchains,” in2025 IEEE Annual Computer Security Applications Conference (ACSAC). IEEE, 2025, pp. 1065– 1080

  41. [49]

    Time- manipulation attack: Breaking fairness against proof of authority Aura,

    X. Zhang, R. Li, Q. Wang, Q. Wang, and S. Duan, “Time- manipulation attack: Breaking fairness against proof of authority Aura,” inProceedings of the ACM Web Conference 2023, 2023, pp. 2076–2086

  42. [50]

    Transfront: Bi-path feature fusion for detecting front-running attack in decentralized finance,

    Y . Zhang, G. Wang, P. Li, X. Li, W. Gu, M. Chen, and H. Chen, “Transfront: Bi-path feature fusion for detecting front-running attack in decentralized finance,” in2024 IEEE 23rd International Confer- ence on Trust, Security and Privacy in Computing and Communi- cations (TrustC...

  43. [51]

    The blockchain imitation game,

    K. Qin, S. Chaliasos, L. Zhou, B. Livshits, D. Song, and A. Ger- vais, “The blockchain imitation game,” in32nd USENIX Security Symposium, 2023, pp. 3961–3978

  44. [52]

    Front-running attacks in Hash-based transaction sharding blockchains,

    Y . Wang, J. Lou, Z. Wang, and J. Li, “Front-running attacks in Hash-based transaction sharding blockchains,” in23rd IEEE Inter- national Conference on Trust, Security and Privacy in Computing and Communications, TrustCom, 2024, pp. 205–212

  45. [53]

    Eliminating sandwich attacks with the help of game theory,

    L. Heimbach and R. Wattenhofer, “Eliminating sandwich attacks with the help of game theory,” inProceedings of the 2022 ACM on Asia Conference on Computer and Communications Security, 2022, pp. 153–167

  46. [54]

    Credible decentralized exchange design via verifiable sequencing rules,

    M. V . Xavier Ferreira and D. C. Parkes, “Credible decentralized exchange design via verifiable sequencing rules,” inProceedings of the 55th Annual ACM Symposium on Theory of Computing, 2023, pp. 723–736

  47. [55]

    A Geth-based real-time detection system for sandwich attacks in Ethereum,

    D. Li, K. Zhang, L. Wang, and G. Du, “A Geth-based real-time detection system for sandwich attacks in Ethereum,”Discover Com- puting, vol. 27, no. 1, p. 11, 2024

  48. [56]

    Don’t let MEV slip: The costs of swapping on the Uniswap protocol,

    A. Adams, B. Y . Chan, S. Markovich, and X. Wan, “Don’t let MEV slip: The costs of swapping on the Uniswap protocol,” inInterna- tional Conference on Financial Cryptography and Data Security. Springer, 2024, pp. 172–191

  49. [57]

    Regulatory implications of MEV mit- igations,

    Y . Ji and J. Grimmelmann, “Regulatory implications of MEV mit- igations,” inInternational Conference on Financial Cryptography and Data Security. Springer, 2024, pp. 335–363

  50. [58]

    n-MVTL attack: Opti- mal transaction reordering attack on DeFi,

    J. Wang, J. Li, Z. Li, X. Deng, and B. Xiao, “n-MVTL attack: Opti- mal transaction reordering attack on DeFi,” inEuropean Symposium on Research in Computer Security. Springer, 2023, pp. 367–386

  51. [59]

    Maximiz- ing extractable value from automated market makers,

    M. Bartoletti, J. H.-y. Chiang, and A. Lluch Lafuente, “Maximiz- ing extractable value from automated market makers,” inInterna- tional Conference on Financial Cryptography and Data Security. Springer, 2022, pp. 3–19

  52. [60]

    Sok: Mitigation of front-running in decentralized fi- nance,

    C. Baum, J. Hsin-yu Chiang, B. David, T. K. Frederiksen, and L. Gentile, “Sok: Mitigation of front-running in decentralized fi- nance,” inInternational Conference on Financial Cryptography and Data Security. Springer, 2022, pp. 250–271

  53. [61]

    Fairness notions in DAG-based DLTs,

    M. Raikwar, N. Polyanskii, and S. M ¨uller, “Fairness notions in DAG-based DLTs,” in2023 5th Conference on Blockchain Research & Applications for Innovative Networks and Services (BRAINS). IEEE, 2023, pp. 1–8

  54. [62]

    The Swirlds hashgraph consensus algorithm: Fair, fast, Byzantine fault tolerance,

    L. Baird, “The Swirlds hashgraph consensus algorithm: Fair, fast, Byzantine fault tolerance,”Swirlds Tech Reports SWIRLDS-TR- 2016-01, Tech. Rep, vol. 34, pp. 9–11, 2016

  55. [63]

    Condorcet’s paradox,

    W. V . Gehrlein, “Condorcet’s paradox,”Theory and Decision, vol. 15, no. 2, pp. 161–197, 1983

  56. [64]

    Condorcet attack against fair transaction ordering,

    M. A. Vafadar and M. Khabbazian, “Condorcet attack against fair transaction ordering,”arXiv preprint arXiv:2306.15743, 2023

  57. [65]

    Order-fair consensus in the permissionless setting,

    M. Kelkar, S. Deb, and S. Kannan, “Order-fair consensus in the permissionless setting,” inProceedings of the 9th ACM on ASIA Public-Key Cryptography Workshop, 2022, pp. 3–14

  58. [66]

    Quick order fairness,

    C. Cachin, J. Mi ´ci´c, N. Steinhauer, and L. Zanolini, “Quick order fairness,” inInternational Conference on Financial Cryptography and Data Security. Springer, 2022, pp. 316–333

  59. [67]

    Rashnu: data- dependent order-fairness,

    H. Nagda, S. P. Singhal, M. J. Amiri, and B. T. Loo, “Rashnu: data- dependent order-fairness,”Proceedings of the VLDB Endowment, vol. 17, no. 9, 2024

  60. [68]

    DAG of DAGs: Order-fairness made practical,

    H. Nagda, S. Sankhe, S. Sinha, K. Attarha, M. J. Amiri, and B. T. Loo, “DAG of DAGs: Order-fairness made practical,”Proceedings of the ACM on Management of Data, vol. 3, no. 6, pp. 1–27, 2025

  61. [69]

    An optimistic approach to transaction-order fairness protocols,

    Y . Hay, O. Rottenstreich, and D. Cohen, “An optimistic approach to transaction-order fairness protocols,” in2025 IEEE International Conference on Blockchain and Cryptocurrency (ICBC). IEEE, 2025, pp. 1–5

  62. [70]

    Dikaios: position- anchored group ordering with reputation for fair and efficient Byzan- tine consensus,

    Y . Wang, X. Xing, G. Wang, Y . Zhang, and P. Li, “Dikaios: position- anchored group ordering with reputation for fair and efficient Byzan- tine consensus,”Computer Networks, vol. 269, p. 111423, 2025

  63. [71]

    Proof-carrying fair ordering: Asymmetric verification for BFT via incremental graphs,

    P. Ren, H. Dong, N. Sohrabi, Z. Tari, and P. Zhang, “Proof-carrying fair ordering: Asymmetric verification for BFT via incremental graphs,”CoRR, vol. abs/2510.14186, 2025

  64. [72]

    FairDAG: con- sensus fairness over multi-proposer causal design,

    D. Kang, J. Chen, T. T. A. Dinh, and M. Sadoghi, “FairDAG: con- sensus fairness over multi-proposer causal design,”arXiv preprint arXiv:2504.02194, 2025

  65. [73]

    Quick order fairness: Implementation and evaluation,

    C. Cachin and J. Mi ´ci´c, “Quick order fairness: Implementation and evaluation,” in2024 IEEE International Conference on Blockchain and Cryptocurrency (ICBC). IEEE, 2024, pp. 230–234

  66. [74]

    Efficient fair ordering protocol with 2-hop receiver fairness,

    J. Yu, S. Duan, and Z. Fang, “Efficient fair ordering protocol with 2-hop receiver fairness,” in2025 44th International Symposium on Reliable Distributed Systems (SRDS). IEEE, 2025, pp. 195–206

  67. [75]

    Fair ordering in replicated systems via streaming social choice,

    G. Ramseyer and A. Goel, “Fair ordering in replicated systems via streaming social choice,” inInternational Conference on Web and Internet Economics. Springer, 2024, pp. 438–456

  68. [76]

    Wendy grows up: More order fairness,

    K. Kursawe, “Wendy grows up: More order fairness,” inInterna- tional Conference on Financial Cryptography and Data Security. Springer, 2021, pp. 191–196

  69. [77]

    A fair and resilient decentralized clock network for trans- action ordering,

    A. Constantinescu, D. Ghinea, L. Heimbach, Z. Wang, and R. Wat- tenhofer, “A fair and resilient decentralized clock network for trans- action ordering,” in27th International Conference on Principles of Distributed Systems, OPODIS 2023, ser. LIPIcs, vol. 286, 2023, pp. 8:1–8:20

  70. [78]

    Chronos: an efficient asynchronous Byzantine ordered consensus,

    Z. Zhang, L. Zhang, Z. Wang, Y . Li, R. Lu, and Y . Yu, “Chronos: an efficient asynchronous Byzantine ordered consensus,”The Computer Journal, vol. 67, no. 3, pp. 1153–1162, 2024

  71. [79]

    AOAB: optimal and fair ordering of financial transactions,

    V . Gramoli, Z. Lu, Q. Tang, and P. Zarbafian, “AOAB: optimal and fair ordering of financial transactions,” in2024 54th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN). IEEE, 2024, pp. 377–388

  72. [80]

    Aion: secure transaction ordering using TEEs,

    P. Zarbafian and V . Gramoli, “Aion: secure transaction ordering using TEEs,” inEuropean Symposium on Research in Computer Security. Springer, 2023, pp. 332–350

  73. [81]

    Phalanx: A practical Byzantine ordered consensus protocol,

    G. Wang, L. Cai, F. Gai, and J. Niu, “Phalanx: A practical Byzantine ordered consensus protocol,”CoRR, vol. abs/2209.08512, 2022

  74. [82]

    Travelers: A scalable fair ordering BFT system,

    B. Xue and S. Kannan, “Travelers: A scalable fair ordering BFT system,”arXiv preprint arXiv:2401.02030, 2024

  75. [83]

    Ordering transactions with bounded unfairness: definitions, complexity and constructions,

    A. Kiayias, N. Leonardos, and Y . Shen, “Ordering transactions with bounded unfairness: definitions, complexity and constructions,” in Annual International Conference on the Theory and Applications of Cryptographic Techniques. Springer, 2024, pp. 34–63

  76. [84]

    Weighted batched threshold encryption with applications to mempool privacy,

    A. Agarwal, K. Babel, S. Das, B. P. Gilkalaye, A. Mondal, B. Pinkas, P. Rindal, and A. Yadav, “Weighted batched threshold encryption with applications to mempool privacy,”Cryptology ePrint Archive, 2025

  77. [85]

    Helix: A fair blockchain consensus protocol resistant to ordering manipulation,

    D. Yakira, A. Asayag, G. Cohen, I. Grayevsky, M. Leshkowitz, O. Rottenstreich, and R. Tamari, “Helix: A fair blockchain consensus protocol resistant to ordering manipulation,”IEEE Transactions on Network and Service Management, vol. 18, no. 2, pp. 1584–1597, 2021

  78. [86]

    Maximal extractable value (MEV) protection on a DAG,

    D. Malkhi and P. Szalachowski, “Maximal extractable value (MEV) protection on a DAG,”arXiv preprint arXiv:2208.00940, 2022

  79. [87]

    BEAST-MEV: Batched threshold encryption with silent setup for MEV prevention,

    J. Bormet, A. R. Choudhuri, S. Faust, S. Garg, H. Othman, G.-V . Policharla, Z. Qu, and M. Wang, “BEAST-MEV: Batched threshold encryption with silent setup for MEV prevention,”Cryptology ePrint Archive, 2025

  80. [88]

    EquiBFT: A framework for achieving fairness in BFT consensus,

    S. Cai, L. Fan, S. Liu, and H.-S. Zhou, “EquiBFT: A framework for achieving fairness in BFT consensus,” in2025 IEEE 45th Inter- national Conference on Distributed Computing Systems (ICDCS). IEEE, 2025, pp. 341–351

  81. [89]

    Lyra: Fast and scalable resilience to reordering attacks in blockchains,

    P. Zarbafian and V . Gramoli, “Lyra: Fast and scalable resilience to reordering attacks in blockchains,” in2023 IEEE International Parallel and Distributed Processing Symposium (IPDPS). IEEE, 2023, pp. 929–939

  82. [90]

    Universally composable transaction order fairness: Refined definitions and adaptive secu- rity,

    M. Ciampi, A. Kiayias, and Y . Shen, “Universally composable transaction order fairness: Refined definitions and adaptive secu- rity,” inInternational Conference on the Theory and Application of Cryptology and Information Security. Springer, 2025, pp. 305–337

  83. [91]

    Fairblock: Preventing blockchain front-running with minimal overheads,

    P. Momeni, S. Gorbunov, and B. Zhang, “Fairblock: Preventing blockchain front-running with minimal overheads,” inInternational Conference on Security and Privacy in Communication Systems. Springer, 2022, pp. 250–271

  84. [92]

    Practical mempool privacy via one-time setup batched threshold encryption,

    A. R. Choudhuri, S. Garg, G. V . Policharla, and M. Wang, “Practical mempool privacy via one-time setup batched threshold encryption,” in34th USENIX Security Symposium (USENIX Security 25), 2025, pp. 3477–3495

  85. [93]

    Mempool privacy via batched threshold encryption: Attacks and defenses,

    A. R. Choudhuri, S. Garg, J. Piet, and G.-V . Policharla, “Mempool privacy via batched threshold encryption: Attacks and defenses,” in 33rd USENIX Security Symposium (USENIX Security 24), 2024, pp. 3513–3529

  86. [94]

    Seahorse: Efficiently mixing encrypted and normal transactions,

    B. Riva, A. Sonnino, and L. Kokoris-Kogias, “Seahorse: Efficiently mixing encrypted and normal transactions,” inFinancial Cryptog- raphy and Data Security - 29th International Conference, FC 2025. Springer, 2025, pp. 36–52

  87. [95]

    Trusted execution environment: What it is, and what it is not,

    M. Sabt, M. Achemlal, and A. Bouabdallah, “Trusted execution environment: What it is, and what it is not,” in2015 IEEE Trust- com/BigDataSE/ISPA, vol. 1, 2015, pp. 57–64

  88. [96]

    Transaction fairness in blockchains, revisited,

    R. Li, X. Hu, Q. Wang, S. Duan, and Q. Wang, “Transaction fairness in blockchains, revisited,”IEEE Transactions on Dependable and Secure Computing, 2025

  89. [97]

    Universal composable trans- action serialization with order fairness,

    M. Ciampi, A. Kiayias, and Y . Shen, “Universal composable trans- action serialization with order fairness,” inAnnual International Cryptology Conference. Springer, 2024, pp. 147–180

  90. [98]

    Cryptographically enforced fairness protocols for algorithmic trading on distributed ledger infrastructures,

    M. Rodriguez, L. R. Motati, and T. Mohamed, “Cryptographically enforced fairness protocols for algorithmic trading on distributed ledger infrastructures,”Artificial Intelligence, Machine Learning, and Autonomous Systems, vol. 9, pp. 212–245, 2025

  91. [99]

    A mempool encryption scheme for Ethereum via multiparty delay encryption,

    A. Khajehpour, H. Akbarinodehi, M. Jahanara, and C. Feng, “A mempool encryption scheme for Ethereum via multiparty delay encryption,” Cryptology ePrint Archive, Paper 2023/1612, 2023

  92. [100]

    Timelock shield: A robust defense against MEV and censorship attacks in blockchain,

    S. Agrawal and V . J. Ribeiro, “Timelock shield: A robust defense against MEV and censorship attacks in blockchain,” inCrypto Valley Conference, CVC 2025. IEEE, 2025, pp. 127–137

  93. [101]

    Prof: Protected order flow in a profit-seeking world,

    K. Babel, N. Jean-Louis, Y . Ji, U. Misra, M. Kelkar, K. Y . Mudiyanselage, A. Miller, and A. Juels, “Prof: Protected order flow in a profit-seeking world,”arXiv preprint arXiv:2408.02303, 2024

  94. [102]

    Fair- TraDEX: A decentralised exchange preventing value extraction,

    C. McMenamin, V . Daza, M. Fitzi, and P. O’Donoghue, “Fair- TraDEX: A decentralised exchange preventing value extraction,” inProceedings of the 2022 ACM CCS Workshop on Decentralized Finance and Security, 2022, pp. 39–46

  95. [103]

    Private, anonymous, collateraliz- able commitments vs. MEV,

    C. McMenamin and V . Daza, “Private, anonymous, collateraliz- able commitments vs. MEV,” inIEEE International Conference on Blockchain and Cryptocurrency, ICBC 2024. IEEE, 2024, pp. 521– 527

  96. [104]

    Mempool privacy: An economic perspective,

    A. Rondelet and Q. Kilbourn, “Mempool privacy: An economic perspective,”arXiv preprint arXiv:2307.10878, 2023

  97. [105]

    Data independent order policy enforce- ment: Limitations and solutions,

    S. Wadhwa, L. Zanolini, A. Asgaonkar, F. D’Amato, C. Fang, F. Zhang, and K. Nayak, “Data independent order policy enforce- ment: Limitations and solutions,” inProceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Secu- rity, 2024, pp. 378–392

  98. [106]

    The AMMazing frontrunner: Practical frontrunning on the XRP ledger automated market maker,

    V . Tumas and A. Malhotra, “The AMMazing frontrunner: Practical frontrunning on the XRP ledger automated market maker,” in2024 IEEE International Conference on Blockchain and Cryptocurrency (ICBC). IEEE, 2024, pp. 1–7

  99. [107]

    Differential privacy in constant function market makers,

    T. Chitra, G. Angeris, and A. Evans, “Differential privacy in constant function market makers,” inInternational Conference on Financial Cryptography and Data Security. Springer, 2022, pp. 149–178

  100. [108]

    Batching trades on automated market makers,

    A. Canidio and R. Fritsch, “Batching trades on automated market makers,” in5th Conference on Advances in Financial Technologies (AFT 2023), 2023, pp. 24–1

  101. [109]

    Mechanism design for automated market makers,

    T. Chan, K. Wu, and E. Shi, “Mechanism design for automated market makers,”arXiv preprint arXiv:2402.09357, 2024

  102. [110]

    Eating sand- wiches: Modular and lightweight elimination of transaction reorder- ing attacks,

    O. Alpos, I. Amores-Sesar, C. Cachin, and M. Yeo, “Eating sand- wiches: Modular and lightweight elimination of transaction reorder- ing attacks,”arXiv preprint arXiv:2307.02954, 2023

  103. [111]

    A2MM: Mitigating frontrunning, transaction reordering and consensus instability in decentralized exchanges,

    L. Zhou, K. Qin, and A. Gervais, “A2MM: Mitigating frontrunning, transaction reordering and consensus instability in decentralized exchanges,”ArXiv, vol. abs/2106.07371, 2021

  104. [112]

    ARMM: Sandwich-attack resilient automated market maker,

    S. Jiang, J. Chen, J. Li, Z. Liu, and Y . Li, “ARMM: Sandwich-attack resilient automated market maker,”IEEE Transactions on Services Computing, 2025

  105. [113]

    Mitigating blockchain extractable value threats by distributed transaction se- quencing,

    X. Zhao, H.-W. Long, Z. Li, J. Liu, and Y .-W. Si, “Mitigating blockchain extractable value threats by distributed transaction se- quencing,”Digital Communications and Networks, vol. 11, no. 5, pp. 1394–1409, 2025

  106. [114]

    The monotone priority system: Foundations of contract-specific sequencing,

    N. Durvasula, “The monotone priority system: Foundations of contract-specific sequencing,”arXiv preprint arXiv:2601.20783, 2026

  107. [115]

    Myochain: A blockchain protocol for delay bounded transaction confirmation,

    A. Ahuja, R. Vigneswaran, M. Rajan, and S. Lodha, “Myochain: A blockchain protocol for delay bounded transaction confirmation,” in 2023 15th International Conference on Communication Systems & Networks (COMSNETS). IEEE, 2023, pp. 114–118

  108. [116]

    Age-aware fairness in blockchain transaction ordering,

    Y . Sokolik and O. Rottenstreich, “Age-aware fairness in blockchain transaction ordering,” in2020 IEEE/ACM 28th International Sym- posium on Quality of Service (IWQOS). IEEE, 2020, pp. 1–9

  109. [117]

    Adversary-augmented simulation to evaluate order-fairness on Hy- perledger Fabric,

    E. Mahe, R. Abdallah, S. Tucci-Piergiovanni, and P.-Y . Piriou, “Adversary-augmented simulation to evaluate order-fairness on Hy- perledger Fabric,” inProceedings of the 13th Latin-American Sym- posium on Dependable and Secure Computing, 2024, pp. 126–135

  110. [118]

    Order fairness evaluation of DAG-based ledgers,

    E. Mahe and S. Tucci-Piergiovanni, “Order fairness evaluation of DAG-based ledgers,” in2025 7th International Conference on Blockchain Computing and Applications (BCCA). IEEE, 2025, pp. 106–114

  111. [119]

    On fair ordering and differential privacy,

    S. Cohen, N. Basu, S. Basu, and L. Alvisi, “On fair ordering and differential privacy,”CoRR, vol. abs/2501.05535, 2025

  112. [120]

    Ordered consensus with equal opportunity,

    Y . Zhang, H. Ni, S. Basu, S. Cohen, M. Yin, L. Alvisi, R. van Renesse, Q. Chen, and L. Zhou, “Ordered consensus with equal opportunity,”CoRR, vol. abs/2509.09868, 2025

  113. [121]

    Transparent transaction ordering in blockchain-based collaborative processes,

    H. Atwi, T. Lichtenstein, C. Pautasso, and M. Weske, “Transparent transaction ordering in blockchain-based collaborative processes,” inBusiness Process Management: Blockchain, Robotic Process Au- tomation, Central and Eastern European, Educators and Industry Forum - BPM 2024, ...

  114. [122]

    Lo: An accountable mempool for MEV resistance,

    B. Nasrulin, G. Ishmaev, J. Decouchant, and J. Pouwelse, “Lo: An accountable mempool for MEV resistance,” inProceedings of the 24th International Middleware Conference, 2023, pp. 98–110

  115. [123]

    On the effectiveness of mempool-based transaction auditing,

    J. Albrecht and G. Karame, “On the effectiveness of mempool-based transaction auditing,” inProceedings of the ACM Web Conference 2026, WWW 2026, H. Hacid, Y . Maarek, F. Bonchi, I. Guy, and E. Yilmaz, Eds., 2026, pp. 2983–2994

  116. [124]

    Block-STM: Scaling blockchain execution by turning ordering curse to a performance blessing,

    R. Gelashvili, A. Spiegelman, Z. Xiang, G. Danezis, Z. Li, D. Malkhi, Y . Xia, and R. Zhou, “Block-STM: Scaling blockchain execution by turning ordering curse to a performance blessing,” inProceedings of the 28th ACM SIGPLAN Annual Symposium on Principles and Practice of Paral...

  117. [125]

    Buying time: Latency racing vs. bidding for transaction ordering,

    A. Mamageishvili, M. Kelkar, J. C. Schlegel, and E. W. Felten, “Buying time: Latency racing vs. bidding for transaction ordering,” in5th Conference on Advances in Financial Technologies, AFT 2023, vol. 282, 2023, pp. 23:1–23:22

  118. [126]

    Efficient rent seeking,

    G. Tullock, “Efficient rent seeking,”Toward a Theory of the Rent- Seeking Society, vol. 97, p. 112, 1980

  119. [127]

    Contest success functions,

    S. Skaperdas, “Contest success functions,”Economic Theory, vol. 7, no. 2, pp. 283–290, 1996

  120. [128]

    L. Gao, J. Lu, and Z. Wang,Equilibria in Two-Player Sequential Tullock Contests. SSRN, 2023

  121. [129]

    Optimal sequential contests,

    T. Hinnosaar, “Optimal sequential contests,”Theoretical Economics, vol. 19, no. 1, pp. 207–244, 2024

  122. [130]

    SPURT: Scalable distributed randomness beacon with transparent setup,

    S. Das, V . Krishnan, I. M. Isaac, and L. Ren, “SPURT: Scalable distributed randomness beacon with transparent setup,” in2022 IEEE Symposium on Security and Privacy (SP). IEEE, 2022, pp. 2502–2517

  123. [131]

    Randpiper– reconfiguration-friendly random beacons with quadratic communi- cation,

    A. Bhat, N. Shrestha, Z. Luo, A. Kate, and K. Nayak, “Randpiper– reconfiguration-friendly random beacons with quadratic communi- cation,” inProceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, 2021, pp. 3502–3524

  124. [132]

    Foundations of transaction fee mechanism design,

    H. Chung and E. Shi, “Foundations of transaction fee mechanism design,” inProceedings of the 2023 Annual ACM-SIAM Symposium on Discrete Algorithms (SODA). SIAM, 2023, pp. 3856–3899

  125. [133]

    Weighted random sampling with a reservoir,

    P. S. Efraimidis and P. G. Spirakis, “Weighted random sampling with a reservoir,”Information Processing Letters, vol. 97, no. 5, pp. 181–185, 2006

  126. [134]

    V on Stackelberg,Market structure and equilibrium

    H. V on Stackelberg,Market structure and equilibrium. Springer Science & Business Media, 2010

  127. [135]

    A general theory of equilibrium selection in games,

    J. C. Harsanyi and R. Selten, “A general theory of equilibrium selection in games,”MIT Press Books, vol. 1, 1988

  128. [136]

    Simple versus optimal contracts,

    P. D ¨utting, T. Roughgarden, and I. Talgam-Cohen, “Simple versus optimal contracts,” inProceedings of the 2019 ACM Conference on Economics and Computation, 2019, pp. 369–387

  129. [137]

    Efficient prior-free mechanisms for no-regret agents,

    N. Collina, A. Roth, and H. Shao, “Efficient prior-free mechanisms for no-regret agents,” inProceedings of the 25th ACM Conference on Economics and Computation, 2024, pp. 511–541

  130. [138]

    On the existence of subgame-perfect equilibrium in infinite-action games of perfect information,

    M. Hellwig and W. Leininger, “On the existence of subgame-perfect equilibrium in infinite-action games of perfect information,”Journal of Economic Theory, vol. 43, no. 1, pp. 55–75, 1987

  131. [139]

    Uniswap v2 core,

    H. Adams, N. Zinsmeister, and D. Robinson, “Uniswap v2 core,” https://app.uniswap.org/whitepaper.pdf, 2020, accessed: jun 2026

  132. [140]

    Uniswap v3 core,

    H. Adams, N. Zinsmeister, M. Salem, R. Keefer, and D. Robin- son, “Uniswap v3 core,” https://app.uniswap.org/whitepaper-v3.pdf, 2021, accessed: jun 2026

  133. [141]

    Foundry,

    Foundry Development Team, “Foundry,” https://github.com/ foundry-rs/foundry, Jun. 2026, gitHub repository. Appendix A. Practical Losing-Fee Rates We measure practical values of the losing-fee rateγfor arbitrage on Ethereum. A transaction consumes resources measured ingasand bi...

Pith tools

Reviewed July 14, 2026 · model on record in the stance chip above.