A sandwich attack on Solana pulled 13.27 SOL from a user trade in less than a second, equal to about $1,117 based on the figures cited in the source. The transaction took place at 01:27:37 AM on March 7, 2026, when the victim was trying to buy OILVAULT through Pump.Fun.
According to Dave, the attacker detected the pending transaction and quickly placed an 11.65 SOL buy order. By slightly raising the transaction fee, the attacker secured inclusion ahead of the victim’s trade, pushing up the token price for a brief moment. The attacker then sold back into that move, completing the sandwich and capturing the spread.
How a 13.04 SOL purchase became the trigger
The report says the victim’s order size was 13.04 SOL. That buy was large enough to cause a short-lived jump in the OILVAULT price, which gave the attacker a clean exit point. Execution costs were tiny. The source states the attacker spent only 0.00004 SOL to carry out the trade sequence and still walked away with 13.27 SOL in profit.
This is the standard sandwich pattern: buy before the target order, let the target push the price higher, then sell immediately after. It happens in narrow windows and relies on transaction timing. On fast chains where ordering can be anticipated, the tactic remains highly effective.
Why RPC endpoints are part of the risk
Dave pointed to RPC infrastructure as a key exposure point. In his words: “When you send a transaction through an RPC endpoint, the operator can inspect, delay, or prioritize it, even front-run transactions.”
That shifts attention from bots alone to the path a trade takes before it lands on-chain. If an endpoint operator can influence sequencing, the user’s transaction flow itself becomes vulnerable. For traders chasing quick execution, transaction ordering is not a minor technical detail. It can decide whether a trade clears normally or becomes a target.
PUMP transfers to Bitget add sell-off concerns
The article also ties recent Pump.Fun-related token movements to market sentiment. Data from March 6 showed the project team moving PUMP tokens to Bitget. One transfer involved 1.75 billion PUMP, valued in the source at roughly $3.54 million. Another transfer involved 5,000 PUMP, worth about $10.
Transfers from private wallets to centralized exchanges often raise questions about possible selling pressure. The source says Pump.Fun has remained largely neutral in its public posture, leaving sentiment to be shaped mostly by retail traders and on-chain participants. In that setting, team wallet activity draws extra scrutiny.
The report also referenced a software supply chain attack
The piece compares the Solana incident with a recent software supply chain case. Last September, a phishing email targeted the account of qix, described in the source as a prominent Node.js contributor. Attackers then used that access to distribute popular software packages carrying crypto-focused payloads.
The source draws a clear line between the two cases. Unlike that earlier incident, the Solana sandwich attack resulted in an immediate financial loss. In this case, the damage came from the combination of transaction ordering, front-running, and very low-cost execution.

