JaredFromSubway.eth MEV Bot Hack

Reported loss $7.5M
ethereum
Other

What happened

In 20th June 2026, the highly prominent Ethereum-based sandwich-attack MEV bot operated by JaredFromSubway.eth suffered a devastating business logic exploit, resulting in a loss of approximately $7.5 million.

The incident was a sophisticated "reverse honeypot" trap targeting the bot’s automated execution and routing logic rather than an inherent vulnerability within the Ethereum network or standard DeFi protocols. Over several weeks of preparation, the attacker deployed 66 fake token wrapper contracts and sham liquidity pools designed to closely mimic legitimate assets like WETH, USDC, and USDT. The attacker then fed malicious, artificial trading opportunities into the memepool to bait the automated sandwiching bot.

When the MEV bot executed its standard arbitrage routine on these decoy pairs, its routing logic was tricked into granting unrestricted token approvals to the attacker-controlled helper contracts. Once these multi-million dollar token allowances were securely trapped and preserved, the attacker executed a sweep transaction using transferFrom, pulling real WETH, USDC, and USDT directly out of the bot's wallet. The attacker swapped the extracted assets for roughly 4,400 ETH, aggressively routing the proceeds through Tornado Cash.

Protocol details

Classification Other / Market Manipulation
Protocol Type Exploit/Other
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.