Ethereum's most prolific sandwich-attack bot, jaredfromsubway.eth, lost $7.5 million on June 20, 2026, after an unknown attacker deployed a counter-MEV honeypot that exploited the bot's own automated approval logic. The drain — confirmed by blockchain security firm Blockaid — involved no smart co...
"Ironically, in the process, it provided the attacker the keys to millions in the bot's treasury." — Raz Niv, CTO at Blockaid
Ethereum's most prolific sandwich-attack bot, jaredfromsubway.eth, lost $7.5 million on June 20, 2026, after an unknown attacker deployed a counter-MEV honeypot that exploited the bot's own automated approval logic. The drain — confirmed by blockchain security firm Blockaid — involved no smart contract bug, no phishing, and no private-key compromise. Instead, 66 fake token contracts fed the bot seemingly profitable arbitrage routes over 97 blocks, tricking it into granting standing token approvals to attacker-controlled contracts. The attacker then swept 1,474.58 WETH, ~2.87 million USDC, and ~2 million USDT in a single transaction.
The incident exposes a structural vulnerability in MEV infrastructure that has gone largely unexamined: automated bots that extract value from ordinary users are themselves high-value targets with predictable behavior. Jaredfromsubway.eth, responsible for an estimated 70% of all Ethereum sandwich attacks between November 2024 and October 2025, had extracted tens of millions of dollars from DeFi traders since 2023. The attack amounts to a forced redistribution — albeit into the hands of another anonymous actor who routed proceeds through Tornado Cash, not back to sandwich victims.
At 18:49 UTC on June 20, 2026, an attacker executed a single sweep transaction that drained jaredfromsubway.eth of $7.5 million in real assets: 1,474.58 WETH, approximately 2.87 million USDC, and roughly 2 million USDT. The preparation had taken weeks.
The attack vector was an approval exploit, not a code vulnerability. According to analysis by Yearn developer Banteg, the attacker deployed 66 fake token contracts designed to mimic legitimate assets — WETH, USDC, and USDT — and paired them with sham liquidity pools. These were structured to appear as profitable MEV opportunities to jaredfromsubway's automated execution system.
Over the course of 97 blocks, the bot was offered small, real-token profits on what appeared to be legitimate fake-DEX arbitrage opportunities. During these transactions, the bot's contracts approved attacker-controlled child contracts to spend real WETH, USDC, and USDT. In the early interactions, those approvals were consumed immediately — appearing benign. But the attacker gradually introduced routes that left some approvals unused, creating standing permissions that persisted on-chain.
ERC-20 token approvals do not expire. Every approval a wallet grants to a smart contract remains active until explicitly revoked. Once enough of these dormant approvals had accumulated across multiple bot addresses, the attacker executed a coordinated transferFrom sweep, draining genuine assets in a single transaction.
Blockaid confirmed there was no smart contract bug, no phishing attack, and no private-key compromise involved. The bot's own profit-seeking logic was the sole vulnerability.
Jaredfromsubway.eth is an ENS-named Ethereum address operated by an unidentified party since early 2023. The bot executes sandwich attacks — placing one transaction immediately before a target swap (front-running) and another immediately after (back-running) — causing the victim's trade to execute at a worse price while the bot captures the spread.
Scale of operations:
The bot's dominance made it the single largest source of MEV extraction on Ethereum for much of 2024 and 2025.
Sandwich attacks impose a measurable cost on DeFi traders. The data:
The economic reality: MEV extraction functions as an invisible tax on DeFi users. Unlike exchange fees, which are disclosed, sandwich attack costs are embedded in worse execution prices and visible only through on-chain analysis.
The jaredfromsubway operator's response followed a pattern common in DeFi exploits — escalating bounty offers met with silence.
Timeline of recovery attempts:
A separate X account claiming to represent jaredfromsubway asserted total losses of $15 million and offered a $1 million bounty, but multiple security researchers flagged the account as a likely impersonator. Blockaid's confirmed figure remains $7.5 million.
The funds are effectively unrecoverable. The attacker's use of Tornado Cash — a sanctioned mixing protocol — severs the on-chain trail. The legal threat carries limited weight against a pseudonymous actor who has already laundered the majority of proceeds.
The jaredfromsubway exploit illustrates a broader security dynamic that the MEV ecosystem has largely ignored: MEV bots are high-value targets with predictable, exploitable behavior.
Structural vulnerabilities in MEV operations:
Automated approval grants: MEV bots must interact with arbitrary smart contracts at high speed to capture fleeting opportunities. This requires granting token approvals to contracts they encounter — and revoking every approval would introduce latency that eliminates profitability. The result is a growing inventory of standing approvals to potentially hostile contracts.
Predictable decision-making: Sandwich bots follow deterministic logic: identify profitable swap, front-run, back-run. An attacker who understands this logic can construct inputs specifically designed to exploit it — as demonstrated by the 66 fake token contracts.
Concentrated value: Successful MEV bots accumulate large token balances in their operational wallets. Jaredfromsubway held $7.5 million in liquid assets in contracts that were actively interacting with untrusted code. The concentration of value creates a target worth sophisticated, multi-week attack campaigns.
No regulatory recourse: MEV operators typically operate pseudonymously. When attacked, they cannot rely on law enforcement in the same way that regulated financial entities can, particularly when their own operations exist in a legal gray zone.
This is not the first time an MEV bot has been drained. In April 2023, a validator exploit drained multiple MEV bots for approximately $25 million by reordering their transactions within proposed blocks. The attack surface has shifted — from block-level manipulation to application-level approval traps — but the fundamental dynamic persists: MEV bots are both predators and prey.
Tools to protect users from MEV extraction exist but remain underutilized relative to the scale of the problem.
Flashbots Protect:
MEV Blocker (CoW Protocol):
MEV-Boost adoption by validators:
The gap: while validator-side MEV tools are near-universal, user-side protection reaches only a fraction of DEX traders. The 97% of Ethereum transactions that do not flow through Flashbots Protect remain exposed to sandwich attacks and other MEV extraction.
The jaredfromsubway exploit does not signal the end of MEV extraction on Ethereum. Sandwich bots remain profitable, and new operators will fill any vacuum. What it demonstrates is that the MEV supply chain has its own predator-prey dynamics. Bots that extract value from users accumulate assets and behavioral patterns that make them targets for more sophisticated actors.
The $7.5 million drain is small relative to the $550 million in annual MEV extraction on Ethereum. It is, however, a proof of concept for counter-MEV as a category — attacks designed to exploit the exploiters. Whether this leads to more robust bot security, reduced MEV extraction, or simply a more adversarial equilibrium among automated actors remains to be seen.
For ordinary DeFi users, the incident changes nothing in the near term. The 1.2% of DEX trades that get sandwiched will continue to incur hidden costs until MEV protection tools achieve broader adoption. The economic value extracted by MEV bots flows to anonymous operators, not to protocol treasuries or users — a distribution pattern that persists regardless of which predator sits at the top of the food chain.