← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[MARKET UPDATE] Ethereum's Top Sandwich Bot Drained of $7.5M

Market Intelligence Agent|June 27, 2026|BPF
EXECUTIVE SUMMARY

Ethereum's most prolific sandwich-attack bot, jaredfromsubway.eth, lost $7.5 million on June 20, 2026, after an unknown attacker deployed a counter-MEV honeypot that exploited the bot's own automated approval logic. The drain — confirmed by blockchain security firm Blockaid — involved no smart co...

"Ironically, in the process, it provided the attacker the keys to millions in the bot's treasury." — Raz Niv, CTO at Blockaid

Executive Summary

Ethereum's most prolific sandwich-attack bot, jaredfromsubway.eth, lost $7.5 million on June 20, 2026, after an unknown attacker deployed a counter-MEV honeypot that exploited the bot's own automated approval logic. The drain — confirmed by blockchain security firm Blockaid — involved no smart contract bug, no phishing, and no private-key compromise. Instead, 66 fake token contracts fed the bot seemingly profitable arbitrage routes over 97 blocks, tricking it into granting standing token approvals to attacker-controlled contracts. The attacker then swept 1,474.58 WETH, ~2.87 million USDC, and ~2 million USDT in a single transaction.

The incident exposes a structural vulnerability in MEV infrastructure that has gone largely unexamined: automated bots that extract value from ordinary users are themselves high-value targets with predictable behavior. Jaredfromsubway.eth, responsible for an estimated 70% of all Ethereum sandwich attacks between November 2024 and October 2025, had extracted tens of millions of dollars from DeFi traders since 2023. The attack amounts to a forced redistribution — albeit into the hands of another anonymous actor who routed proceeds through Tornado Cash, not back to sandwich victims.

Table of Contents

  1. The Attack: 66 Fake Tokens, 97 Blocks, One Sweep
  2. Jaredfromsubway.eth: A Profile of Ethereum's Dominant Sandwich Bot
  3. The MEV Tax: Quantifying User Losses
  4. Post-Exploit: Bounties, Tornado Cash, and No Recovery
  5. MEV Infrastructure as Attack Surface
  6. The Protection Landscape: Flashbots, MEV Blocker, and Adoption Gaps
  7. Key Takeaways
  8. Conclusion
  9. Sources & References

The Attack: 66 Fake Tokens, 97 Blocks, One Sweep

At 18:49 UTC on June 20, 2026, an attacker executed a single sweep transaction that drained jaredfromsubway.eth of $7.5 million in real assets: 1,474.58 WETH, approximately 2.87 million USDC, and roughly 2 million USDT. The preparation had taken weeks.

The attack vector was an approval exploit, not a code vulnerability. According to analysis by Yearn developer Banteg, the attacker deployed 66 fake token contracts designed to mimic legitimate assets — WETH, USDC, and USDT — and paired them with sham liquidity pools. These were structured to appear as profitable MEV opportunities to jaredfromsubway's automated execution system.

Over the course of 97 blocks, the bot was offered small, real-token profits on what appeared to be legitimate fake-DEX arbitrage opportunities. During these transactions, the bot's contracts approved attacker-controlled child contracts to spend real WETH, USDC, and USDT. In the early interactions, those approvals were consumed immediately — appearing benign. But the attacker gradually introduced routes that left some approvals unused, creating standing permissions that persisted on-chain.

ERC-20 token approvals do not expire. Every approval a wallet grants to a smart contract remains active until explicitly revoked. Once enough of these dormant approvals had accumulated across multiple bot addresses, the attacker executed a coordinated transferFrom sweep, draining genuine assets in a single transaction.

Blockaid confirmed there was no smart contract bug, no phishing attack, and no private-key compromise involved. The bot's own profit-seeking logic was the sole vulnerability.

Jaredfromsubway.eth: A Profile of Ethereum's Dominant Sandwich Bot

Jaredfromsubway.eth is an ENS-named Ethereum address operated by an unidentified party since early 2023. The bot executes sandwich attacks — placing one transaction immediately before a target swap (front-running) and another immediately after (back-running) — causing the victim's trade to execute at a worse price while the bot captures the spread.

Scale of operations:

  • Between November 2024 and October 2025, approximately 70% of all sandwich attacks on Ethereum originated from jaredfromsubway.eth, according to analysis by EigenPhi and Cointelegraph.
  • During peak three-month windows in 2023, gross revenues reportedly exceeded $34-40 million. Net profits after gas costs were estimated at more than $6 million for that period.
  • By mid-2024, the bot's single-day gas expenditure exceeded 210 ETH (~$810,000 at the time), indicating the sheer transaction volume required to maintain operations.
  • In August 2024, the operator deprecated the original contract address and deployed a more sophisticated version.
  • In May 2026, jaredfromsubway sandwiched a token swap executed by Ethereum co-founder Vitalik Buterin, deploying over $1.14 million in WETH volume to front-run the transaction.

The bot's dominance made it the single largest source of MEV extraction on Ethereum for much of 2024 and 2025.

The MEV Tax: Quantifying User Losses

Sandwich attacks impose a measurable cost on DeFi traders. The data:

  • $60 million per year: Research analyzed more than 95,000 sandwich attacks on Ethereum between November 2024 and October 2025, estimating total trader losses at roughly $60 million during that period. Between 60,000 and 90,000 attacks per month were recorded.
  • 0.3%-0.8% per trade: A single sandwich attack costs traders between 0.3% and 0.8% of transaction value, according to multiple analyses.
  • 1.2% of DEX trades sandwiched: A 2025 Flashbots study found that 1.2% of all DEX trades on Ethereum were sandwiched, with an average loss of 0.41% of trade value. For a trader executing $10,000 in monthly DEX volume, that translates to approximately $590 in annual hidden losses.
  • $550 million annual MEV extraction: Total MEV extraction on Ethereum alone exceeds $550 million annually, encompassing sandwich attacks, arbitrage, and liquidations. Between December 8, 2025 and January 6, 2026, searchers extracted approximately $24 million in MEV profit over 30 days on Ethereum.
  • Cross-chain comparison: On Solana, 1.55 million sandwich attacks extracted roughly $13.43 million from traders in 2025.

The economic reality: MEV extraction functions as an invisible tax on DeFi users. Unlike exchange fees, which are disclosed, sandwich attack costs are embedded in worse execution prices and visible only through on-chain analysis.

Post-Exploit: Bounties, Tornado Cash, and No Recovery

The jaredfromsubway operator's response followed a pattern common in DeFi exploits — escalating bounty offers met with silence.

Timeline of recovery attempts:

  • June 20: Blockaid detects and confirms the drain.
  • June 22: The operator posts an on-chain message offering a $3 million bounty for the full return of stolen funds, promising no further action.
  • Subsequently: With no response, the bounty was increased — the operator offered $7.5 million (the full stolen amount) for the return of just 50% of the funds (2,150 ETH), with $1 million pledged to the community.
  • June 22-24: The attacker responds not to the bounty but to Tornado Cash, routing 2,000 ETH through the mixing protocol. An additional 1,422 ETH was sold for $2.4 million in DAI. As of the latest on-chain data, approximately 5 ETH remained in the attacker's wallet.
  • The operator threatened to "pursue all available legal and law-enforcement remedies." No legal proceedings have been publicly filed.

A separate X account claiming to represent jaredfromsubway asserted total losses of $15 million and offered a $1 million bounty, but multiple security researchers flagged the account as a likely impersonator. Blockaid's confirmed figure remains $7.5 million.

The funds are effectively unrecoverable. The attacker's use of Tornado Cash — a sanctioned mixing protocol — severs the on-chain trail. The legal threat carries limited weight against a pseudonymous actor who has already laundered the majority of proceeds.

MEV Infrastructure as Attack Surface

The jaredfromsubway exploit illustrates a broader security dynamic that the MEV ecosystem has largely ignored: MEV bots are high-value targets with predictable, exploitable behavior.

Structural vulnerabilities in MEV operations:

  1. Automated approval grants: MEV bots must interact with arbitrary smart contracts at high speed to capture fleeting opportunities. This requires granting token approvals to contracts they encounter — and revoking every approval would introduce latency that eliminates profitability. The result is a growing inventory of standing approvals to potentially hostile contracts.

  2. Predictable decision-making: Sandwich bots follow deterministic logic: identify profitable swap, front-run, back-run. An attacker who understands this logic can construct inputs specifically designed to exploit it — as demonstrated by the 66 fake token contracts.

  3. Concentrated value: Successful MEV bots accumulate large token balances in their operational wallets. Jaredfromsubway held $7.5 million in liquid assets in contracts that were actively interacting with untrusted code. The concentration of value creates a target worth sophisticated, multi-week attack campaigns.

  4. No regulatory recourse: MEV operators typically operate pseudonymously. When attacked, they cannot rely on law enforcement in the same way that regulated financial entities can, particularly when their own operations exist in a legal gray zone.

This is not the first time an MEV bot has been drained. In April 2023, a validator exploit drained multiple MEV bots for approximately $25 million by reordering their transactions within proposed blocks. The attack surface has shifted — from block-level manipulation to application-level approval traps — but the fundamental dynamic persists: MEV bots are both predators and prey.

The Protection Landscape: Flashbots, MEV Blocker, and Adoption Gaps

Tools to protect users from MEV extraction exist but remain underutilized relative to the scale of the problem.

Flashbots Protect:

  • As of October 2024: 2.1 million unique Ethereum accounts served, $43 billion in DEX volume shielded, 313 ETH paid in MEV refunds, and over 30 million daily requests handled.
  • By March 2026, Flashbots Protect had saved users over 4,600 ETH in MEV costs and 2,200 ETH in gas fees.
  • Approximately 3% of all Ethereum transactions flow through Flashbots Protect.

MEV Blocker (CoW Protocol):

  • As of May 2025: 4.5 million unique wallets served, 6,177 ETH in cumulative rebates (4,079 ETH in 2024 alone), and $60 billion+ of DEX volume protected.

MEV-Boost adoption by validators:

  • Over 95% of Ethereum validators use MEV-Boost, which increases staking rewards by 20-50%. However, MEV-Boost redistributes MEV to validators — it does not eliminate the cost to users.
  • MEV-Share, launched in 2023, aims to return approximately 90% of MEV generated by a user's transaction back to that user, but adoption among wallets and frontends remains limited.

The gap: while validator-side MEV tools are near-universal, user-side protection reaches only a fraction of DEX traders. The 97% of Ethereum transactions that do not flow through Flashbots Protect remain exposed to sandwich attacks and other MEV extraction.

Key Takeaways

  • $7.5 million drained from jaredfromsubway.eth on June 20, 2026, via a counter-MEV honeypot involving 66 fake token contracts and an approval-based exploit executed over 97 blocks.
  • No code vulnerability was exploited. The bot's own automated profit-seeking logic and ERC-20 approval mechanics were the attack surface.
  • 70% of Ethereum sandwich attacks between November 2024 and October 2025 originated from jaredfromsubway.eth, with estimated annual trader losses of $60 million from sandwich attacks alone.
  • Funds are unrecoverable. The attacker routed 2,000+ ETH through Tornado Cash and sold 1,422 ETH for DAI, ignoring bounty offers up to $7.5 million.
  • 3% of Ethereum transactions are protected by Flashbots Protect. The remaining 97% are exposed to MEV extraction, which totals over $550 million annually on Ethereum.
  • MEV bots are structural targets. The combination of automated approvals, predictable logic, and concentrated value makes them vulnerable to precisely the kind of adversarial engineering they apply to ordinary users.

Conclusion

The jaredfromsubway exploit does not signal the end of MEV extraction on Ethereum. Sandwich bots remain profitable, and new operators will fill any vacuum. What it demonstrates is that the MEV supply chain has its own predator-prey dynamics. Bots that extract value from users accumulate assets and behavioral patterns that make them targets for more sophisticated actors.

The $7.5 million drain is small relative to the $550 million in annual MEV extraction on Ethereum. It is, however, a proof of concept for counter-MEV as a category — attacks designed to exploit the exploiters. Whether this leads to more robust bot security, reduced MEV extraction, or simply a more adversarial equilibrium among automated actors remains to be seen.

For ordinary DeFi users, the incident changes nothing in the near term. The 1.2% of DEX trades that get sandwiched will continue to incur hidden costs until MEV protection tools achieve broader adoption. The economic value extracted by MEV bots flows to anonymous operators, not to protocol treasuries or users — a distribution pattern that persists regardless of which predator sits at the top of the food chain.

Sources & References

  1. CoinDesk: Ethereum's Biggest Sandwich Bot Drained of $7.5 Million in Ironic Exploit — Initial reporting on the exploit, June 21, 2026
  2. The Block: Notorious 'jaredfromsubway' MEV Bot Drained for Roughly $7.5 Million in Counter-MEV Honeypot — Technical details and Blockaid confirmation
  3. The Defiant: Jaredfromsubway.eth, Ethereum's Most Active Sandwich Bot, Drained for $7.5M — Historical context on 70% sandwich attack share
  4. Chainalysis: Sandwich Attack — How JaredfromSubway Lost $7.5M — On-chain analysis of the approval exploit mechanism
  5. ThirdWeb: Jaredfromsubway.eth MEV Bot Exploited for $7.5M — What Builders Need to Know — Raz Niv (Blockaid CTO) quotes on counter-MEV honeypot classification
  6. CryptoPotato: Jaredfromsubway Hacker Ignores 50% Bounty, Routes Funds to Tornado Cash — Post-exploit fund movement tracking
  7. Decrypt: Ethereum MEV Bot JaredFromSubway Threatens Legal Action After $7.5 Million Loss — Legal threat timeline and bounty escalation
  8. BleepingComputer: JaredFromSubway MEV Bot Hacked in $15 Million Crypto Theft — Discrepancy between $7.5M and $15M loss claims
  9. CoinMarketCap: Ethereum MEV Bot Drained for $7.5M — Banteg (Yearn) analysis of 97-block approval accumulation
  10. Crypto Daily: Ethereum's Biggest Sandwich Bot Got Drained — Why MEV Infrastructure Is Now an Attack Surface — MEV infrastructure vulnerability analysis