Cointelegraph
DOGE$0.07001 2.24%
TRX$0.3298 0.17%
LINK$8.36 0.72%
ZEC$477.21 4.22%
ADA$0.1638 0.24%
XRP$1.09 0.09%
ETH$1,866.31 0.86%
BTC$64,167.52 0.31%
XMR$367.20 3.69%
BNB$568.45 2.04%
XLM$0.1784 1.04%
SOL$74.00 0.06%
HYPE$57.36 1.54%
Written by Felix Ngstaff editorReviewed by Bryan O'Sheastaff editor

Notorious ‘sandwich attack’ bot Jaredfromsubway.eth exploited for $7.5M

Latest NewsPublishedJun 21, 2026

Jaredfromsubway.eth was responsible for 70% of sandwich attacks on Ethereum between November 2024 and October 2025.

Update July 23 at 11:20 pm UTC: Added additional detail about how the exploit occurred from post-mortem reports from Chainalysis and CertiK.

One of the most successful MEV bots in crypto, Jaredfromsubway.eth, has been drained for $7.5 million, with an attacker exploiting the bot’s automated systems, the same ones that have netted it hundreds of millions over the years. 

According to Blockaid, the incident on Saturday resulted from attacker-controlled contracts tricking Jaredfromsubway.eth’s automated MEV (maximal extractable value) execution system bot into granting token approvals that were later used to drain funds.

“This is not a classic phishing attack and not a traditional smart-contract vulnerability in the victim contract,” Blockaid said on X.

It’s a rare setback for MEV bots like Jaredfromsubway.eth, which are automated programs that monitor unconfirmed transactions on blockchain networks and manipulate their order to extract profit, a kind of “invisible tax” on DeFi users. 

Cointelegraph Research previously found that sandwich attacks on Ethereum have resulted in about $60 million in annual losses for traders. The research also found that between November 2024 and October 2025, there were 60,000 to 90,000 sandwich attacks per month, with roughly 70% of them associated with Jaredfromsubway.eth.

How Jaredfromsubway.eth was exploited

“This was a counter-MEV honeypot attack, as it specifically targeted the automated, trust-minimized decision-making logic that MEV bots utilize,” Blockaid chief technology officer Raz Niv told Cointelegraph.

To prepare for the exploit, the attacker deployed fake arbitrage pools and bait tokens that mimicked the names and interfaces of Wrapped ETH (WETH), USDC (USDC), and USDt (USDT), said Niv. 

CertiK later said 131 bait-token contracts were deployed overall, appearing in the form of restaked WETH/USDC tokens, with some pools seeded and deliberately imbalanced with real assets to attract automated trading bots.

On Friday, Jaredfromsubway’s bot took the bait and interacted with one of the attacker-controlled pools. The first trade worked normally, as the bot approved a wrapper contract to spend its WETH, the allowance was consumed, and the bot earned a small profit, making the setup appear legitimate.

The attacker later configured the bait contracts so trades no longer consumed the bot’s approvals, and because the bot didn’t check whether each allowance had been consumed or revoked, the malicious contracts retained permission to spend its real tokens.

“Over multiple transactions, it kept granting approvals to these malicious contracts — permissions that were never revoked,” Chainalysis said in a post-mortem. “Once enough had accumulated, a tripwire smart contract activated and drained JaredfromSubway.eth of at least $7.5 million.”

CertiK said the attacker ultimately activated 66 bait contracts, 60 of which held approvals from the bot, and used the lingering allowances to drain approximately 2.87 million USDC, 2.03 million USDT and 1,474 WETH.

Some of the stolen funds have already been sent to crypto mixing service Tornado Cash, according to onchain data.

In May, Ethereum co-founder Vitalik Buterin was sandwich attacked by Jaredfromsubway.eth while swapping 26,544 DigitalBits (worth $2.11 at the time of writing). The losses were minimal, but they show that even the smallest transactions can be a target for MEV bots.

“We shouldn’t be happy about this; no one should celebrate ... but if you’ve ever been sandwiched by this ... I’m pretty sure you’re not upset about this news,” crypto investor and commentator David Gokhshtein said.

Magazine: The end of anon? AI could unmask crypto’s hidden identities

1 minute letter

Subscribe to daily byte-sized crypto news from Cointelegraph

Subscribe
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

More on the subject