Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Security & Hacks

JaredFromSubway.eth MEV Bot Drained of $7.5 Million in Sophisticated Approval Exploit on Ethereum

An attacker tricked the prominent sandwich bot into granting token approvals through simulated profitable trades, exposing risks in automated MEV systems. The bot operator later offered a 50% white hat bounty for partial fund recovery.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
June 22, 2026
in Security & Hacks
0 0
JaredFromSubway.eth MEV Bot Drained of $7.5 Million in Sophisticated Approval Exploit on Ethereum

Created by Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

Ethereum’s most prominent sandwich MEV bot, JaredFromSubway.eth, lost more than $7.5 million in an exploit on June 20, 2026. The attacker exploited the bot’s automated trading system by simulating profitable opportunities rather than through a traditional smart contract vulnerability or private key compromise. Security researchers identified the drain shortly after it occurred. Independent estimates placed the loss around $7.5 million in WETH, USDC, and USDT, though the bot operator publicly referenced a higher figure near $15 million.

🚨Community Alert:
Blockaid Exploit Detection system detected an exploit involving the @jaredsmev MEV bot on Ethereum.
The incident resulted from attacker-controlled contracts tricking an automated MEV execution system into granting token approvals, later used to drain funds.…

— Blockaid (@blockaid_) June 20, 2026

The attack unfolded over several weeks. The perpetrator deployed dozens of fake token contracts and liquidity pools mimicking wrapped Ether and major stablecoins. These setups created the appearance of profitable MEV opportunities that the bot’s logic would naturally pursue. JaredFromSubway.eth’s system generated token approvals for attacker-controlled helper contracts as part of what it perceived as routine execution for arbitrage or sandwich trades. In initial tests, approvals were consumed immediately. Later iterations left standing allowances that the attacker could exploit.

A key example involved an approval for roughly 92 WETH to a helper contract at 0x4ee0…313ce. That permission remained active until the final sweep. The attacker then used a sweep contract to pull funds via transferFrom calls from the bot’s main contracts. Funds flowed to the attacker-controlled wallet starting with 0x3e37…65d0 On-chain records show portions of the stolen assets routed through Tornado Cash for obfuscation.

The attack also comes amid a broader wave of crypto security incidents that have targeted cross-chain bridges, exchanges, and trading infrastructure in recent months, underscoring how threat actors continue to exploit weaknesses across the digital asset ecosystem.

On June 22, the JaredFromSubway operator publicly offered a 50% white hat bounty. The message stated they were willing to pay for the return of 2150 ETH to a specified address within 48 hours, warning of legal and law-enforcement action otherwise.

jaredfromsubway.eth just offered 50% white hat bounty to the exploiter.

“Well played. We are willing to offer a 50% white hat bounty if you return 2150 ETH to this address in the next 48 hours, otherwise we will pursue all available legal and law-enforcement remedies.” pic.twitter.com/0lr69EqWpt

— Kakashi (@kkashi_yt) June 22, 2026

JaredFromSubway.eth has operated since early 2023 and is linked to a significant share of Ethereum sandwich attacks. Estimates suggest it accounted for around 70% of such activity in periods between late 2024 and 2025, contributing to substantial trader costs. The bot gained notoriety for high-volume operations that often front-ran user swaps on decentralized exchanges.

This incident stands out because it reversed the typical dynamic. The bot, which profits by inserting itself into others’ trades, fell victim to a carefully constructed counter-strategy that weaponized its own pattern-recognition and approval mechanisms. The exploit carries limited direct impact on broader DeFi total value locked, as the funds resided in the bot’s operational wallets rather than a shared protocol. However, it underscores ongoing challenges for automated systems that interact at high speed with unverified contracts and liquidity pools.

MEV activity remains a contentious part of Ethereum’s ecosystem. While it provides liquidity and arbitrage that can tighten spreads, sandwich attacks extract value directly from retail traders, often increasing effective slippage and gas costs. The operator has pursued recovery efforts, including the recent bounty offer. As of the latest updates, the attacker had not publicly responded, and funds remain unrecovered.

This case adds to a series of incidents where sophisticated actors target MEV infrastructure, highlighting the need for stricter approval management and simulation safeguards in high-stakes automated trading.

The exploit also adds to the growing list of major cryptocurrency thefts recorded in 2026, a year that has already seen billions of dollars lost to hacks, exploits, and protocol compromises. The continued rise in high-profile security incidents serves as another reminder that even advanced automated trading systems remain vulnerable to carefully engineered attacks and social manipulation techniques embedded within on-chain activity.

AI Disclosure: Cryip uses AI-assisted tools to help refine language — correcting spelling and grammar and simplifying complex terms for readability.

We do this to make crypto topics easier to understand for readers at all experience levels. AI does not draft facts, sources, or conclusions. Every article is reviewed and approved by a human editor before publication. Read our full AI Use & Content Policy.

Disclaimer: Cryip’s content is strictly for informational purposes and does not constitute financial, legal, or investment advice. Asset references are not endorsements, and readers assume full responsibility for any financial decisions.
Tags: Crypto HacksETHEthereum
Saravana Kumar Mahendran

Saravana Kumar Mahendran

Saravana Kumar Mahendran is a crypto security analyst and blockchain researcher at Cryip, focusing on DeFi protocol exploits, Web3 security systems, and on-chain investigation. His research applies OSINT and fact-checking methodology to security incidents, drawing on certifications in cybersecurity and data analytics (LinkedIn Learning), and DeFi deep-dive training (Binance Academy). His work has been cited by Sherlock, Rekt.news, and Halborn Security.

Related Posts

Grayscale Makes BNB Largest Smart Contract Fund Holding
Market Updates

Grayscale Makes BNB Largest Smart Contract Fund Holding

by Sathish Kumar Kaliraj
August 6, 2026

Grayscale's Smart Contract Fund closed its second-quarter rebalance on August 5 with BNB at the top of the basket: 30.6%,...

Read moreDetails
Ethereum Researchers Propose Burning Staking Rewards to Zero at 50% Participation

Ethereum Researchers Propose Burning Staking Rewards to Zero at 50% Participation

August 5, 2026
Coldcard Hack Losses Nearly $100 Million

Coldcard Hack Losses Nearly $100 Million as Root Cause Reveals a Wider Flaw

August 4, 2026
BitMine's Staked ETH

BitMine’s Staked ETH Ratio Jumps to 87.4% After Fresh 150K ETH Deposit

August 4, 2026
Perps Volume Falls on Five of Six Major Chains This Week - Tron Bucks the Trend

Perps Volume Falls Across Major Chains While Tron Rises

August 4, 2026
Boltz Disables Bitcoin Swaps Indefinitely After Monthslong AI-Assisted Attacks

Boltz Disables Bitcoin Swaps Indefinitely After Months long AI-Assisted Attacks

August 4, 2026
BitMine Adds 10,399 ETH, Expands Crypto Treasury to $11.3B

BitMine Adds 10,399 ETH, Expands Crypto Treasury to $11.3B

August 3, 2026
Next Post
Token Unlock

Upcoming Crypto Token Unlocks: $129.67M in Supply Across Key Projects (June 22–28, 2026)

How to Add a Custom RPC to MetaMask: The Ultimate Guide

How to Add a Custom RPC to MetaMask: The Ultimate Guide

Recommended

  • All
  • Crypto News Today
Coinbase Expands Beyond Crypto

Coinbase Expands Beyond Crypto With 24/5 U.S. Stock Trading for UK Users

August 6, 2026
Japan's JPYC Stablecoin Tops $38M in Series B After Logistics-Firm Backing

Japan’s JPYC Stablecoin Tops $38M in Series B After Logistics-Firm Backing

August 6, 2026
EU Warns Crypto Scammers Are Exploiting MiCA Transition as Users Move Funds

EU Warns Crypto Scammers Exploit MiCA Transition as Users Move Funds

August 6, 2026
Putin Signs Russia’s First Comprehensive Crypto Law, Effective September 1

Putin Signs Russia’s First Comprehensive Crypto Law, Effective September 1

August 6, 2026
Coinbase Revises Advanced Trade Markets With Six Pair Suspensions

Coinbase to End Trading for Six Non-USD Pairs on Advanced Trade

August 6, 2026
Mysten Labs' Sam Blackshear Leaves to Join Anthropic for AI Security Research

Mysten Labs’ Sam Blackshear Leaves to Join Anthropic for AI Security Research

August 6, 2026
Circle Q2 2026 Revenue Hits $701M as USDC Volume Reaches $14.8

Circle Q2 2026 Revenue Hits $701M as USDC Volume Reaches $14.8

August 5, 2026
Binance Files $472 Million Lawsuit Against RedotPay

Binance Files $472 Million Lawsuit Against RedotPay

August 5, 2026 - Updated on August 6, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Grayscale Makes BNB Largest Smart Contract Fund Holding
  • Coinbase Expands Beyond Crypto With 24/5 U.S. Stock Trading for UK Users
  • Japan’s JPYC Stablecoin Tops $38M in Series B After Logistics-Firm Backing

Categories

  • AI × Crypto
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.