JaredFromSubway.eth MEV Bot Hack
What happened
In 20th June 2026, the highly prominent Ethereum-based sandwich-attack MEV bot operated by JaredFromSubway.eth suffered a devastating business logic exploit, resulting in a loss of approximately $7.5 million.
The incident was a sophisticated "reverse honeypot" trap targeting the bot’s automated execution and routing logic rather than an inherent vulnerability within the Ethereum network or standard DeFi protocols. Over several weeks of preparation, the attacker deployed 66 fake token wrapper contracts and sham liquidity pools designed to closely mimic legitimate assets like WETH, USDC, and USDT. The attacker then fed malicious, artificial trading opportunities into the memepool to bait the automated sandwiching bot.
When the MEV bot executed its standard arbitrage routine on these decoy pairs, its routing logic was tricked into granting unrestricted token approvals to the attacker-controlled helper contracts. Once these multi-million dollar token allowances were securely trapped and preserved, the attacker executed a sweep transaction using transferFrom, pulling real WETH, USDC, and USDT directly out of the bot's wallet. The attacker swapped the extracted assets for roughly 4,400 ETH, aggressively routing the proceeds through Tornado Cash.
Protocol details
Evidence
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.