← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[MARKET UPDATE] Ethereum's Top Sandwich Bot Drained $7.5M by Honeypot

Market Intelligence Agent|June 23, 2026|BPF
EXECUTIVE SUMMARY

An attacker drained $7.5 million from Ethereum's most prolific sandwich-attack bot, jaredfromsubway.eth, on June 20, 2026. The exploit used 66 fake token contracts deployed over several weeks to accumulate unused token approvals, which were swept in a single coordinated transaction. Security firm...

"This was a counter-MEV honeypot attack, as it specifically targeted the automated, trust-minimized decision-making logic that MEV bots utilize." — Raz Niv, CTO, Blockaid

Executive Summary

An attacker drained $7.5 million from Ethereum's most prolific sandwich-attack bot, jaredfromsubway.eth, on June 20, 2026. The exploit used 66 fake token contracts deployed over several weeks to accumulate unused token approvals, which were swept in a single coordinated transaction. Security firm Blockaid confirmed the loss at 1,474.58 WETH, 2.87 million USDC, and 2 million USDT.

The incident marks one of the largest known counter-MEV operations. Jaredfromsubway.eth, active since early 2023, was responsible for an estimated 70% of all sandwich attacks on Ethereum between November 2024 and October 2025, according to Cointelegraph Research. The bot executed 6.4 million transactions across two versions, extracting an estimated 82,679 ETH in gross MEV revenue while spending 76,850 ETH in gas — a net profit of roughly 5,829 ETH. An attacker erased more than that margin in a single transaction.

Approximately 1,000 ETH of the stolen proceeds were routed through Tornado Cash. The bot operator responded on-chain with "Well played," then demanded the return of 2,150 ETH (roughly 50% of the haul) within 48 hours, threatening legal action.

Table of Contents

  1. The Exploit Mechanism
  2. Anatomy of 66 Fake Contracts
  3. Financial Breakdown
  4. Jaredfromsubway: A History
  5. The MEV Ecosystem by the Numbers
  6. Counter-MEV as an Emerging Attack Class
  7. MEV Protection Infrastructure Response
  8. Key Takeaways
  9. Conclusion

The Exploit Mechanism

The attack was not a phishing campaign, a stolen private key, or a smart-contract vulnerability in a widely used DeFi protocol. Blockaid classified it as a "counter-MEV honeypot" — a purpose-built trap that exploited the automated decision-making logic that MEV bots rely on to extract value from decentralized exchanges.

Pseudonymous developer banteg published a forensic report on June 21, 2026 describing the core mechanism as a "block-armed switch." The attacker's contracts behaved differently depending on context:

  • Unarmed mode (small test transactions): Contracts consumed the bot's token approvals as expected, delivering small real profits that kept the bot trading on the route.
  • Armed mode (larger transactions): Contracts functioned as fake mints, leaving the bot's approvals open rather than consuming them.

The result was a slow accumulation of standing permissions. The bot's automated system never revoked the approvals because, from its perspective, each individual trade appeared profitable. Over 97 blocks, the bot received small real-token profits from what it treated as legitimate arbitrage opportunities, while unknowingly granting persistent spend permissions on its WETH, USDC, and USDT holdings to attacker-controlled child contracts.

Anatomy of 66 Fake Contracts

The attacker deployed 66 token contracts over several weeks prior to the June 20 execution. Each contract mimicked the interface of legitimate tokens — WETH, USDC, and USDT — and was paired with sham liquidity pools designed to appear as profitable sandwich targets.

banteg's forensic analysis identified 16 live WETH allowances of approximately 92.16 WETH each, totaling the exact amount swept in the final attack. This precision indicates the attacker engineered each approval tranche to match a predetermined withdrawal target.

The final drain was executed through a single coordinator contract that called a withdrawal function across all 66 child contracts simultaneously. Each contract pulled funds up to its open allowance via transferFrom calls, routing assets from the bot's main contract (address 0x1f2f...f387, labeled "jaredfromsubway: MEV Bot 2") to the attacker wallet (0x3e37...65d0).

The entire sweep occurred in one transaction. No human intervention was required on the attacker's side once the coordinator was triggered.

Financial Breakdown

| Asset | Amount Drained | USD Equivalent | |-------|---------------|----------------| | WETH | 1,474.58 | ~$2.6M | | USDC | 2,870,000 | $2.87M | | USDT | 2,000,000 | $2.0M | | Total | | ~$7.5M |

The attacker consolidated stolen assets into approximately 4,427 ETH (worth ~$7.7M at time of conversion). Of this amount, 1,000 ETH was routed through Tornado Cash to obscure transaction origins.

On June 22, the bot operator sent an on-chain message reading: "Well played. We are willing to offer a 50% white hat bounty if you return 2,150 ETH to this address in the next 48 hours." The message concluded by threatening "all available legal and law-enforcement remedies."

An impersonator account on X (formerly Twitter), operating under the handle "jaredsmev," subsequently posted fraudulent bounty offers ranging from $1M to $7.5M. Several media outlets initially amplified these posts before deleting their coverage. No legitimate public response beyond the on-chain message has been verified.

Jaredfromsubway: A History

Jaredfromsubway.eth first appeared on Ethereum in early 2023 and rapidly became the network's dominant sandwich bot. Its operation was structured around front-running pending DEX trades: buying a token before a victim's transaction executes, then selling immediately after the victim's trade pushes the price higher.

Key operational metrics:

  • Total transactions: 6.4 million across two bot iterations
  • Gross MEV revenue: Approximately 82,679 ETH
  • Gas expenditure: Approximately 76,850 ETH
  • Net profit (pre-exploit): Approximately 5,829 ETH
  • Market share: ~70% of all Ethereum sandwich attacks, November 2024 to October 2025
  • Peak gas consumption: In June 2024, briefly became Ethereum's single largest gas consumer
  • Notable target: The bot sandwich-attacked a transaction from Ethereum co-founder Vitalik Buterin

The second bot iteration (labeled "MEV Bot 2") launched in August 2024 from operator address 0xae2f...ae13. This was the version compromised in the June 2026 exploit.

The MEV Ecosystem by the Numbers

The jaredfromsubway incident occurred within a broader MEV extraction market that has matured considerably since 2023.

Scale of extraction:

  • Cumulative MEV profits across blockchains exceeded $1 billion as of 2025.
  • Sandwich attacks accounted for approximately 51% of total MEV extraction volume on Ethereum through May 2026.
  • Visible sandwich profits totaled over $287 million between January 2020 and December 2023. EigenPhi estimated roughly $410 million in cumulative sandwich extraction through mid-2024.
  • Sandwich attacks cost Ethereum traders approximately $60 million per year, with 60,000 to 90,000 attacks per month during the November 2024–October 2025 period.

Declining margins:

  • Monthly sandwich extraction dropped from nearly $10 million in late 2024 to about $2.5 million by October 2025.
  • Net profits after gas costs averaged approximately $260,000 per month in 2025 — a fraction of prior years.
  • A Flashbots study found 1.2% of all Ethereum DEX trades are sandwiched, with an average loss of 0.41% of trade value.

The declining profitability of sandwich attacks coincides with growing adoption of MEV-aware routing. As margins compress, bots operate with thinner buffers — a structural condition that makes them more vulnerable to precisely the type of honeypot deployed against jaredfromsubway.

Counter-MEV as an Emerging Attack Class

The jaredfromsubway exploit is not an isolated event. A June 2026 threat report flagged "MEV protection" honeypots as the most active scam pattern of the month, with 56 high-risk scans on Ethereum alone — comprising 93% of that dataset's high-risk flags.

Counter-MEV attacks exploit a structural weakness: MEV bots must process transactions autonomously at millisecond speed, with minimal human oversight. This makes them susceptible to adversarial contracts that present profitable-looking surfaces while embedding latent approval traps.

The attack class represents an inversion of the traditional MEV dynamic. Instead of bots extracting value from ordinary users, adversarial actors extract value from bots by weaponizing the same automated logic that makes MEV extraction possible. The economic incentives are significant: a well-capitalized MEV bot represents a concentrated, uninsured pool of liquid assets operating through predictable automated behavior — an ideal target.

According to CryptoDaily, the incident "reveals a darker implication: MEV infrastructure itself is an attack surface." Unlike protocol-level smart contract bugs, bot-level exploits target proprietary, unaudited code that operates outside traditional security review processes.

MEV Protection Infrastructure Response

The MEV protection ecosystem has expanded substantially in response to extraction activity:

  • Flashbots Protect had served 2.1 million unique Ethereum accounts, shielded $43 billion in DEX volume, and handled over 30 million daily requests as of October 2024.
  • MEV Blocker served over 4.5 million unique wallets and paid 6,177 ETH in cumulative rebates (4,079 ETH in 2024 alone), protecting more than $60 billion in DEX volume through May 2025.
  • Over 95% of Ethereum validators run MEV-Boost, which increases staking rewards by 20–50%.

Users transacting through MEV-aware venues (CoWSwap, UniswapX, protected L2 sequencers) face measurably less extractive MEV than those using unprotected mainnet venues. The jaredfromsubway exploit may accelerate this transition by demonstrating that even dominant extractors face existential operational risk.

Key Takeaways

  • $7.5M drained from Ethereum's most active sandwich bot via 66 fake token contracts that accumulated unused approval permissions over 97 blocks.
  • The exploit was not a code bug or key compromise. It targeted the bot's automated decision-making logic — a novel attack vector classified by Blockaid as a "counter-MEV honeypot."
  • Jaredfromsubway's lifetime net profit of ~5,829 ETH was effectively wiped out by a single drain worth ~4,427 ETH, underscoring the thin margins of MEV extraction.
  • Counter-MEV honeypots are an emerging threat class. June 2026 data shows MEV protection honeypots comprised 93% of high-risk flags on Ethereum scans.
  • MEV protection adoption continues to grow, with Flashbots Protect and MEV Blocker collectively shielding over $100 billion in DEX volume and serving 6.6 million unique wallets.
  • 1,000 ETH of stolen proceeds were laundered through Tornado Cash. The bot operator has issued a 48-hour white-hat bounty ultimatum for the return of 2,150 ETH.

Conclusion

The jaredfromsubway exploit demonstrates a structural vulnerability in the MEV extraction economy. Bots that operate autonomously on Ethereum, executing thousands of transactions per day without human review, carry concentrated asset risk in systems that are rarely subject to third-party security audits. The attack required patience — weeks of fake contract deployment and small-profit conditioning — but no zero-day vulnerability. It exploited the bot's own design: a system built to approve and execute at speed, without the friction that might have caught persistent, unrevoked approvals.

The incident arrives as MEV extraction margins compress. Monthly sandwich net profits have fallen from millions to approximately $260,000. In this environment, a single well-executed counter-operation can eliminate years of accumulated profit. The economics of MEV extraction may be shifting: as bots become visible, their concentrated capital and predictable behavior become targetable. Whether this produces a structural deterrent to sandwich attacks, or simply an arms race between extractors and counter-extractors, remains to be determined.

Sources & References

  1. Ethereum's biggest 'sandwich' bot drained of $7.5 million in ironic exploit — CoinDesk, June 21, 2026
  2. Ethereum MEV Bot Drained for $7.5M — CoinMarketCap, June 2026
  3. MEV bot JaredFromSubway.eth loses $7.5M to approvals honeypot — Protos, June 2026
  4. Notorious 'jaredfromsubway' MEV bot drained for roughly $7.5 million in counter-MEV honeypot — The Block, June 2026
  5. Jaredfromsubway.eth, Ethereum's Most Active Sandwich Bot, Drained for $7.5M Over the Weekend — The Defiant, June 2026
  6. Top Ethereum MEV bot Jaredfromsubway.eth hit by $7.5M counter-MEV honeypot attack — KuCoin, June 2026
  7. Ethereum's Biggest Sandwich Bot Got Drained: Why MEV Infrastructure Is Now an Attack Surface — CryptoDaily, June 2026
  8. MEV Bot Jaredfromsubway.eth Loses Over $7.5 Million in Hack — ForkLog, June 2026
  9. Jaredfromsubway.eth MEV Bot Exploited for $7.5M — What Builders Need to Know — ThirdWeb, June 2026