Ethereum MEV Bot JaredFromSubway Falls Into Honeypot, Losses May Reach $15 Million

Ethereum MEV Bot JaredFromSubway Falls Into Honeypot, Losses May Reach $15 Million

N
News Editor 01
2026-07-22 05:52:13
Ethereum sandwich bot JaredFromSubway was trapped by 66 fake token contracts in a carefully staged honeypot attack. On-chain losses are estimated at about $7.5 million, while the bot’s creator claims total damage may be close to $15 million.
EthereumMEVsandwich-attacksonchain-securityJaredFromSubway

JaredFromSubway, one of Ethereum’s most notorious sandwich-trading bots, has become the latest victim of a sophisticated on-chain trap. According to blockchain security firms Blockaid and PeckShield, the visible on-chain loss is around $7.5 million, involving assets such as WETH, USDC, and USDT. The bot’s creator, however, said the full damage may be closer to $15 million when additional losses are included.

A Weeks-Long Setup Using 66 Fake Contracts

The attack did not rely on a smart contract exploit, phishing, or stolen private keys. Instead, Blockaid said the attacker spent weeks deploying 66 fake token contracts designed to closely imitate highly liquid assets including WETH, USDC, and USDT. These contracts were crafted to appear legitimate to JaredFromSubway’s automated MEV strategy, which continuously scans Ethereum’s mempool for profitable trading routes.

Once the bot identified what it believed were real opportunities, it approved token spending permissions to helper contracts controlled by the attacker. Those approvals were later used to drain real assets from the bot’s wallet. In one case, a single approval reportedly exposed more than 92 WETH. The final contract in the sequence then used the accumulated permissions to sweep funds from the wallet.

Its Own Strategy Became the Weakness

Blockaid’s assessment suggests the attack was effective because it turned the bot’s own profit-seeking behavior against it. JaredFromSubway has long depended on speed, automation, and aggressive response times to capture MEV opportunities. In this case, those same strengths became liabilities: the faster the bot reacted, the faster it committed to the trap.

Since becoming active in early 2023, JaredFromSubway has reportedly carried out hundreds of thousands of sandwich attacks. At its peak, gross revenue was estimated at roughly $34 million to $40 million. During the height of Ethereum’s sandwich attack problem, the bot was said to account for around 70% of such attacks on the network in some months. That history has made this reversal especially notable within the crypto community.

Loss Estimates Differ as Bounty Is Offered

While security researchers currently place confirmed losses near $7.5 million, the bot’s creator claims the overall impact is closer to $15 million. Following the incident, a $1 million bounty was reportedly offered in exchange for the return of the funds.

Still, history suggests such recovery efforts face long odds. Similar “MEV bot hunting” incidents have happened before. The report notes that in 2023, a malicious validator used related tactics to extract roughly $25 million from multiple sandwich bots. Compared with that earlier case, this latest exploit appears more elaborate, relying on dozens of fake contracts rather than a single point of attack. The incident underscores how fragile automated MEV systems can become when their assumptions about liquidity, token identity, and execution logic are deliberately manipulated.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.