How a sandwich works
Your pending swap is visible before it is included. A searcher submits a buy of the same token ahead of yours, your trade executes at the price their buy created, and they sell immediately after into the price your trade created.
Their profit is bounded by your slippage tolerance. Everything they take was inside the band you publicly agreed to accept.
What makes a trade worth attacking
Size relative to pool depth, a generous slippage tolerance, and a pair volatile enough that nobody questions the result. A small swap on a deep stable pair is not worth the gas to attack; a large swap on a thin pair with 5% tolerance is.
The attacker needs your transaction to be visible and your tolerance to leave room. Remove either and the attack stops being profitable.
Practical defences
Set tolerance to the smallest value that reliably executes for that pair. Split large orders so no single transaction is worth sandwiching. Prefer deeper pools, which may mean a different supported network for the same pair.
Where a private transaction route is available from your wallet or the network, it removes mempool visibility entirely, which is the strongest available defence.
The part no interface can fix
No front end can promise MEV protection it does not control. Block ordering belongs to validators and builders, and an interface that claims to eliminate extraction is overstating what it can do.
FBT Swap shows the quote, the price impact and your tolerance before you sign, and does not add a hidden spread of its own. That is the honest boundary: visibility and a tight band, not immunity.