Key facts
- The Ethereum MEV bot JaredFromSubway suffered a $7.5 million loss.
- The attack exploited the bot's logic through fake tokens and fraudulent smart contracts.
- JaredFromSubway is known for employing sandwich attacks.
A prominent Ethereum MEV bot known as JaredFromSubway lost approximately $7.5 million due to a sophisticated attack involving fake tokens and fraudulent smart contracts. The bot's operator has threatened legal action if stolen funds are not returned.

This incident underscores the ongoing risks and vulnerabilities within decentralized finance, even for sophisticated trading bots. It highlights the potential for significant financial losses due to exploits and the complex legal and ethical considerations surrounding MEV strategies and illicit fund recovery.
A prominent Ethereum MEV (Maximal Extractable Value) bot, known as JaredFromSubway, has reportedly lost approximately $7.5 million in a sophisticated attack. The incident occurred over the weekend, marking a significant setback for the bot, which has gained a reputation for executing profitable sandwich attacks on decentralized exchanges.
According to security firm Blockaid, the attack involved the use of fake tokens and fraudulent smart contracts. These misleading opportunities exploited JaredFromSubway's logic, which allows certain entities permission to move funds on its behalf to execute trades. While some of these permissions are designed to be revoked upon completion, the attacker's crafted transactions did not include this safeguard, leaving the bot vulnerable.
In response to the exploit, the operator of JaredFromSubway offered a "50% white hat bounty" for the return of 2,150 Ethereum, valued at roughly $3.7 million, within 48 hours. The operator also threatened to pursue legal remedies and involve law enforcement if the funds were not returned.
Sandwich attacks, a strategy where trades are placed around pending transactions to manipulate price execution, fall under the umbrella of MEV. This exploit highlights that even sophisticated bots are not infallible.
Following the attack, security firm PeckShield observed that a portion of the stolen funds, including wrapped Ethereum and stablecoins, was swapped and partially deposited into Tornado Cash, a privacy-focused service commonly used to obscure the flow of illicit gains.