Ethereum · CoinDesk
Ethereum's biggest 'sandwich' bot drained of $7.5 million in ironic exploit
Compiled by KHAO Editorial — aggregated from 4 sources. See llms.txt for citation guidance.
✓ KHAO Verified
Jaredfromsubway.eth, one of Ethereum’s most infamous MEV bots, has been drained for more than $7.5 million after an attacker turned the bot’s own automated trading logic against it.
Key facts
- In May, combined exchange volumes fell 3.45% to $4.41T; the lowest since September 2024
- Roughly 70% of those attacks were associated with Jaredfromsubway.eth, who has been active since early 2023
- Jaredfromsubway.eth, one of Ethereum’s most infamous MEV bots, has been drained for more than $7.5 million after an attacker turned the bot’s own automated trading logic against it
- In May that the same bot had even sandwiched a small swap by Ethereum co-founder Vitalik Buterin
Summary
An attacker drained more than $7.5 million from the notorious Ethereum MEV bot jaredfromsubway.eth by exploiting its automated trading logic rather than a traditional contract bug or phishing scam. Over several weeks, the attacker lured the bot into approving malicious helper contracts via fake tokens and liquidity pools that mimicked assets like WETH, USDC and USDT, then used those open approvals to pull funds and route some through Tornado Cash. The incident underscores both the scale and risks of industrialized sandwich-bot activity—jaredfromsubway.eth has been responsible for roughly 70% of Ethereum sandwich attacks, which cost traders about $60 million a year—by showing how machine-speed, pattern-based systems can themselves be turned into victims.