Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
No Result
View All Result
Home News Security & Hacks

JaredFromSubway.eth MEV Bot Drained of $7.5 Million in Sophisticated Approval Exploit on Ethereum

An attacker tricked the prominent sandwich bot into granting token approvals through simulated profitable trades, exposing risks in automated MEV systems. The bot operator later offered a 50% white hat bounty for partial fund recovery.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
June 22, 2026
in Security & Hacks
0 0
JaredFromSubway.eth MEV Bot Drained of $7.5 Million in Sophisticated Approval Exploit on Ethereum

Created by Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

Ethereum’s most prominent sandwich MEV bot, JaredFromSubway.eth, lost more than $7.5 million in an exploit on June 20, 2026. The attacker exploited the bot’s automated trading system by simulating profitable opportunities rather than through a traditional smart contract vulnerability or private key compromise. Security researchers identified the drain shortly after it occurred. Independent estimates placed the loss around $7.5 million in WETH, USDC, and USDT, though the bot operator publicly referenced a higher figure near $15 million.

🚨Community Alert:
Blockaid Exploit Detection system detected an exploit involving the @jaredsmev MEV bot on Ethereum.
The incident resulted from attacker-controlled contracts tricking an automated MEV execution system into granting token approvals, later used to drain funds.…

— Blockaid (@blockaid_) June 20, 2026

The attack unfolded over several weeks. The perpetrator deployed dozens of fake token contracts and liquidity pools mimicking wrapped Ether and major stablecoins. These setups created the appearance of profitable MEV opportunities that the bot’s logic would naturally pursue. JaredFromSubway.eth’s system generated token approvals for attacker-controlled helper contracts as part of what it perceived as routine execution for arbitrage or sandwich trades. In initial tests, approvals were consumed immediately. Later iterations left standing allowances that the attacker could exploit.

A key example involved an approval for roughly 92 WETH to a helper contract at 0x4ee0…313ce. That permission remained active until the final sweep. The attacker then used a sweep contract to pull funds via transferFrom calls from the bot’s main contracts. Funds flowed to the attacker-controlled wallet starting with 0x3e37…65d0 On-chain records show portions of the stolen assets routed through Tornado Cash for obfuscation.

The attack also comes amid a broader wave of crypto security incidents that have targeted cross-chain bridges, exchanges, and trading infrastructure in recent months, underscoring how threat actors continue to exploit weaknesses across the digital asset ecosystem.

On June 22, the JaredFromSubway operator publicly offered a 50% white hat bounty. The message stated they were willing to pay for the return of 2150 ETH to a specified address within 48 hours, warning of legal and law-enforcement action otherwise.

jaredfromsubway.eth just offered 50% white hat bounty to the exploiter.

“Well played. We are willing to offer a 50% white hat bounty if you return 2150 ETH to this address in the next 48 hours, otherwise we will pursue all available legal and law-enforcement remedies.” pic.twitter.com/0lr69EqWpt

— Kakashi (@kkashi_yt) June 22, 2026

Related Story

TrustedVolumes Attacker Returns 1,122 ETH

TrustedVolumes Attacker Returns 1,122 ETH, Retains Funds After Settlement

July 18, 2026
Airbnb CEO Brian Chesky Confirms X Account Hack After Fake Crypto Thread

Airbnb CEO Brian Chesky Confirms X Account Hack After Fake Crypto Thread

July 17, 2026

JaredFromSubway.eth has operated since early 2023 and is linked to a significant share of Ethereum sandwich attacks. Estimates suggest it accounted for around 70% of such activity in periods between late 2024 and 2025, contributing to substantial trader costs. The bot gained notoriety for high-volume operations that often front-ran user swaps on decentralized exchanges.

This incident stands out because it reversed the typical dynamic. The bot, which profits by inserting itself into others’ trades, fell victim to a carefully constructed counter-strategy that weaponized its own pattern-recognition and approval mechanisms. The exploit carries limited direct impact on broader DeFi total value locked, as the funds resided in the bot’s operational wallets rather than a shared protocol. However, it underscores ongoing challenges for automated systems that interact at high speed with unverified contracts and liquidity pools.

MEV activity remains a contentious part of Ethereum’s ecosystem. While it provides liquidity and arbitrage that can tighten spreads, sandwich attacks extract value directly from retail traders, often increasing effective slippage and gas costs. The operator has pursued recovery efforts, including the recent bounty offer. As of the latest updates, the attacker had not publicly responded, and funds remain unrecovered.

This case adds to a series of incidents where sophisticated actors target MEV infrastructure, highlighting the need for stricter approval management and simulation safeguards in high-stakes automated trading.

The exploit also adds to the growing list of major cryptocurrency thefts recorded in 2026, a year that has already seen billions of dollars lost to hacks, exploits, and protocol compromises. The continued rise in high-profile security incidents serves as another reminder that even advanced automated trading systems remain vulnerable to carefully engineered attacks and social manipulation techniques embedded within on-chain activity.

Disclaimer: Cryip is an independent media and research outlet providing news, data, and analysis on the cryptocurrency industry. Content is for informational and research purposes only and does not constitute financial, legal, tax, or investment advice. Cryptocurrency markets are volatile and past performance is not indicative of future results. References to specific assets, platforms, or incidents are for journalistic purposes only and do not imply endorsement, and readers assume full responsibility for their decisions.
Tags: Crypto HacksETHEthereum

Related Posts

TrustedVolumes Attacker Returns 1,122 ETH
Security & Hacks

TrustedVolumes Attacker Returns 1,122 ETH, Retains Funds After Settlement

by Saravana Kumar Mahendran
July 18, 2026

The party responsible for the TrustedVolumes exploit has returned 1,122 ETH, worth roughly $2 million at current prices. On-chain monitoring...

Read moreDetails
Airbnb CEO Brian Chesky Confirms X Account Hack After Fake Crypto Thread

Airbnb CEO Brian Chesky Confirms X Account Hack After Fake Crypto Thread

July 17, 2026
Summer.fi to Wind Down After $6.04 Million Vault Exploit

Summer.fi to Wind Down After $6.04 Million Vault Exploit

July 16, 2026
Arthur Hayes Buys 1,293 ETH Worth $2.48M After Recent Ethereum Sell-Off

Arthur Hayes Accumulates 1,293 ETH Through Two On-Chain Transfers

July 16, 2026
Ostium Keeps Trading Paused After $18 Million Oracle Exploit

Ostium Keeps Trading Paused After $18 Million Oracle Exploit

July 16, 2026
Cascade CLS Vault Incident Triggers Trading and Withdrawal Freeze

Polychain Backed Cascade CLS Vault Exploit Drains $1.34M in USDC

July 16, 2026
LayerZero-Linked Executor Wallets Suspected of Losing $2.4 Million Across Multiple Chains

LayerZero-Linked Executor Wallets Suspected of Losing $2.4 Million Across Multiple Chains

July 15, 2026 - Updated on July 16, 2026
Next Post
Token Unlock

Upcoming Crypto Token Unlocks: $129.67M in Supply Across Key Projects (June 22–28, 2026)

How to Add a Custom RPC to MetaMask: The Ultimate Guide

How to Add a Custom RPC to MetaMask: The Ultimate Guide

Recommended

  • All
  • News
TrustedVolumes Attacker Returns 1,122 ETH

TrustedVolumes Attacker Returns 1,122 ETH, Retains Funds After Settlement

July 18, 2026
Consensys Removed North Korea-Linked MetaMask Consultant After Month-Long Code Access

Consensys Hired Suspected North Korean Hacker for MetaMask Wallet: Tyler Knapp Case Revealed

July 18, 2026
FTX to Distribute $900M to Creditors in Fifth Repayment Round on July 31

FTX to Distribute $900M to Creditors in Fifth Repayment Round on July 31

July 18, 2026
France Blocks Polymarket as Global Crackdown on Prediction Markets Expands

France Blocks Polymarket as Global Crackdown on Prediction Markets Expands

July 18, 2026
SBI Holdings Acquire Coinhako

SBI Holdings Completes Majority Acquisition of Singapore Crypto Platform Coinhako

July 17, 2026
ESMA Adds 14 Crypto Firms to MiCA Register, Total Licensed CASPs Reach 294

ESMA Adds 14 Crypto Firms to MiCA Register, Total Licensed CASPs Reach 294

July 17, 2026
Argentina Traces LIBRA Funds Across Exchanges as Wallet Freeze Remains Unconfirmed

Argentina Traces LIBRA Funds Across Exchanges as Wallet Freeze Remains Unconfirmed

July 17, 2026
Bitcoin $DOG Mode Aims to Remove Bitcoin Core Relay Policy Limits

Bitcoin $DOG Mode Aims to Remove Bitcoin Core Relay Policy Limits

July 17, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Cathie Wood Buys SpaceX Dip as Stock Falls Below IPO Price
  • TrustedVolumes Attacker Returns 1,122 ETH, Retains Funds After Settlement
  • Consensys Hired Suspected North Korean Hacker for MetaMask Wallet: Tyler Knapp Case Revealed

Categories

  • AI × Crypto
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.