Slow and Steady: Preventing MEV with Verifiable Delays
Zeta Avarikioti, Dimitris Karakostas, Karl Kreder, Shreekara Shastry
TU Wien · Common Prefix · Dominant Strategies
cs.CR
Submitted: 2026-08-13
Updated: 2026-08-14
Comments: A revised version is accepted for publication at the 10th International Workshop on Cryptocurrencies and Blockchain Technology (CBT 2026)
Code: https://github.com/harmony-one/vdf
License: http://creativecommons.org/licenses/by/4.0/
Importance score: 75/100
The gist: This paper presents a defense mechanism against Maximal Extractable Value (MEV) opportunities in distributed ledgers, which relies on enforcing a verifiable delay when generating transactions.
Terminology
Summary
This paper presents a defense mechanism against Maximal Extractable Value (MEV) opportunities in distributed ledgers, which relies on enforcing a verifiable delay when generating transactions. The core idea is that "by requiring every transaction to be created over a certain number of rounds, we enforce a delay on an MEV attacker, between the moment they receive a transaction with an MEV opportunity and the moment when they can publish a front-running transaction of their own. If the required amount of rounds is high enough (more than the ledger’s liveness parameter), the honest transaction is finalized before an adversarial transaction is created."
The mechanism is implemented via a transformation of a ledger's transaction validity predicate. Specifically, a transformed transaction is a tuple tx = ⟨m, (y, π)⟩, where m is the original transaction payload and (y, π) is the output and proof of a Verifiable Delay Function (VDF) evaluated on a commitment of m. The new validity predicate ValidateVDF,CS requires both the original validity check Validate(m, L) and that the VDF proof verifies correctly and the commitment reveals to m. This transformation ensures that a party cannot create a valid transaction that meaningfully depends on an honest transaction before the latter is finalized, a property the paper defines as blockchain input causality.
The paper presents several theoretical results. First, in the Byzantine setting, it proves that if the VDF delay parameter τ is greater than the ledger's liveness parameter u, the transformed protocol guarantees blockchain input causality with negligible error probability. Second, in the game-theoretic setting, it shows that if a protocol is an ϵ-Nash equilibrium in the absence of MEV opportunities, then the VDF-transformed protocol is an ϵ′-Nash equilibrium when MEV opportunities exist, where ϵ′ = ϵ + negl(λ). Third, it presents a negative result, describing an equilibrium where all parties deviate by censoring a transaction for τ rounds to claim its MEV opportunity. Finally, it proves that if a protocol is compliant w.r.t. censorship when no MEV opportunities exist, then the transformed protocol is compliant w.r.t. blockchain input causality when MEV opportunities do exist.
The paper also explores implementation details. It recommends setting the VDF delay parameter to twice the safety parameter (e.g., approximately 60 minutes for Bitcoin and 30 minutes for Ethereum). It evaluates two VDF candidates: Wesolowski's and Pietrzak's. Experimental results show that Wesolowski's VDF is a prime choice, as its verification time remains under 800 milliseconds even when the computation takes 60 minutes, while Pietrzak's VDF has a verification time logarithmic to the computation time, making it unsuitable. The paper also discusses outsourcing VDF computation, noting that the hiding property of the commitment scheme allows users to send only the commitment to a service without revealing the payload.
Finally, the paper reviews historical MEV data from multiple sources, including Layer-2 protocols and MEV Boost and Flashbots datasets. The analysis shows that although some MEV opportunities can be in the order of millions of USD, the overwhelming majority of opportunities is below a few hundred USD, or even less than 100.
This suggests that the proposed mechanism could realistically help prevent most existing MEV threats. However, the paper notes usability considerations: the mechanism is not suitable for all applications, particularly those requiring frequent and immediate user responses, such as decentralized exchanges, and it is not designed to defend against back-running attacks.
Improvements for AI systems
Improvements to AI Systems Based on This Paper:
-
MEV-Resistant Transaction Scheduler for AI Agents: Build an AI-driven transaction submission system that automatically applies a VDF-based delay to all outgoing transactions when the agent detects a high probability of front-running (e.g., in DeFi arbitrage or liquidation bots). The AI can dynamically adjust the VDF delay parameter
τbased on the current ledger’s liveness parameteruand the estimated MEV value of the transaction, balancing speed against security. -
Adaptive MEV Risk Assessment Model: Train a machine learning model on historical MEV data (as analyzed in the paper) to classify transactions by their MEV exposure (e.g., low-value 1M). The AI can then decide in real-time whether to apply the VDF transformation, skip it for low-risk transactions, or use alternative defenses (e.g., private mempools) for high-value ones—optimizing latency and cost.
-
Censorship-Resistant AI Oracles: Enhance decentralized oracle networks (e.g., Chainlink) by integrating the VDF transformation into oracle update transactions. The AI oracle can prove that its data submission was created independently of any pending transaction, preventing malicious validators from censoring or reordering oracle updates to extract MEV, thereby improving data integrity for downstream AI models.
-
Game-Theoretic AI Policy Optimizer: Use the paper’s equilibrium analysis to design an AI agent that learns optimal transaction submission strategies in a Byzantine environment. The agent can simulate the ϵ′-Nash equilibrium conditions and decide when to deviate (e.g., when censorship for
τrounds is profitable) versus when to comply, based on real-time MEV opportunity estimates and network conditions. -
VDF Parameter Auto-Tuning System: Develop an AI controller that monitors ledger parameters (e.g., safety, liveness) and automatically sets the VDF delay
τto twice the safety parameter, as recommended. The AI can also switch between Wesolowski’s and Pietrzak’s VDF implementations based on hardware capabilities, predicted verification time (<800ms target), and energy constraints, ensuring optimal performance. -
Privacy-Preserving MEV Defense for AI Workflows: Integrate the commitment-based outsourcing mechanism into AI pipelines that need to submit transactions without revealing payloads to third-party VDF computation services. The AI system can generate a commitment
(y, π)locally, send only the commitment to a cloud service for VDF computation, and later reveal the payload—enabling secure, outsourced transaction creation for resource-constrained AI devices. -
MEV-Aware AI Trading Bot with Back-Running Mitigation: Extend the mechanism to handle back-running attacks (which the paper notes are not defended) by combining VDF delays with AI-predicted slippage models. The AI can identify when a back-run is likely and adjust order sizes or use time-weighted average pricing, while still applying VDF for front-running defense—improving overall profitability in adversarial markets.
-
Blockchain Input Causality Verifier for Smart Contracts: Build an AI-based monitoring tool that verifies whether a given transaction satisfies blockchain input causality (i.e., no dependency on an unfinalized honest transaction). The tool can flag suspicious transactions in real-time, helping AI-governed DAOs or automated auditors detect MEV exploits and enforce compliance with the transformed validity predicate.
Abstract
Our work presents a defense mechanism against Maximal Extractable Value (MEV) opportunities in distributed ledgers. The mechanism relies on the idea of enforcing a verifiable delay when generating transactions, such that a block creator cannot react to the appearance of a MEV opportunity without breaking liveness. We present positive results both in the Byzantine setting and in a game theoretic model of rational participants. We additionally present negative bounds that outline the limitations of this line of defense. Finally, we explore real-world implementation details of verifiable delays and show that, based on historical MEV data, our mechanism could realistically help prevent most existing MEV threats.
Sources
- SoK: Tools for Game Theoretic Models of Security for Cryptocurrencies
- SoK: Consensus for Fair Message Ordering
- Unity is Strength: A Formalization of Cross-Domain Maximal Extractable Value
- SoK: MEV Countermeasures: Theory and Practice
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs