An attacker drained more than $7.5 million from jaredfromsubway.eth, Ethereum's most prolific MEV sandwich bot, by exploiting the automated trading logic that has made it one of the network's most controversial actors. The exploit was not a traditional contract bug or phishing attack—instead, the perpetrator spent weeks luring the bot into approving malicious helper contracts before using those same permissions to pull funds.

Market Context

The incident landed during a period of heightened focus on MEV extraction across Ethereum. Sandwich attacks—when automated traders spot pending transactions, buy ahead of them, let victims trade at worse prices, then immediately sell—have drawn increasing scrutiny as the practice has industrialized. Jaredfromsubway.eth alone has been responsible for roughly 70% of all sandwich attacks on Ethereum since early 2023.

Analysis

Security firm Blockaid said Saturday's exploit targeted jaredfromsubway.eth's decision-making system rather than a vulnerability in its smart contract code. Over several weeks, the attacker deployed dozens of fake token contracts and fraudulent liquidity pools that mimicked legitimate assets including wrapped ether (WETH), USDC and USDT. The bait worked: Jaredfromsubway.eth's bot detected what appeared to be profitable MEV opportunities and generated approvals for attacker-controlled helper contracts to spend tokens on its behalf.

In earlier tests, those approvals were consumed immediately as part of routine trades. But the attacker later created routes where approvals remained open, giving them standing permission to transfer funds. The attacker exploited that access to drain WETH, USDC and USDT from Jaredfromsubway.eth's contracts before routing some proceeds through Tornado Cash, on-chain data reviewed by CoinDesk showed.

The irony was not lost on observers. Jaredfromsubway.eth has long operated as a predatory presence on Ethereum, skimming value from traders who never saw it coming while contributing to gas fee spikes that affect all network users. The bot even sandwiched a small swap by Ethereum co-founder Vitalik Buterin in May—putting up $1.14 million to frontrun his trade and netting just $4 after fees.

Key Numbers

- More than $7.5 million drained from jaredfromsubway.eth

- Roughly 70% of all Ethereum sandwich attacks attributed to the bot since early 2023

- Sandwich attacks cost traders approximately $60 million annually

- 60,000 to 90,000 attack attempts per month between November 2024 and October 2025

- Dozens of fake token contracts and liquidity pools deployed during the multi-week setup

What to Watch

On-chain investigators will monitor wallet addresses associated with the exploit for movement patterns. The incident raises broader questions about MEV bot security: if pattern-recognition systems can be fooled at scale, what does that mean for automated trading strategies across DeFi? Traders should watch whether this attack prompts changes to how sandwich bots handle approvals or whether copycat exploits target other high-profile MEV actors.

The use of Tornado Cash for fund mixing also puts the attacker on potential sanctions radar, given the mixer remains blocked for U.S. persons despite its decentralized structure. No arrests have been announced and attribution remains unclear.