JaredFromSubway, one of Ethereum’s most notorious sandwich-trading bots, has become the latest victim of a sophisticated on-chain trap. According to blockchain security firms Blockaid and PeckShield, the visible on-chain loss is around $7.5 million, involving assets such as WETH, USDC, and USDT. The bot’s creator, however, said the full damage may be closer to $15 million when additional losses are included.
A Weeks-Long Setup Using 66 Fake Contracts
The attack did not rely on a smart contract exploit, phishing, or stolen private keys. Instead, Blockaid said the attacker spent weeks deploying 66 fake token contracts designed to closely imitate highly liquid assets including WETH, USDC, and USDT. These contracts were crafted to appear legitimate to JaredFromSubway’s automated MEV strategy, which continuously scans Ethereum’s mempool for profitable trading routes.
Once the bot identified what it believed were real opportunities, it approved token spending permissions to helper contracts controlled by the attacker. Those approvals were later used to drain real assets from the bot’s wallet. In one case, a single approval reportedly exposed more than 92 WETH. The final contract in the sequence then used the accumulated permissions to sweep funds from the wallet.
Its Own Strategy Became the Weakness
Blockaid’s assessment suggests the attack was effective because it turned the bot’s own profit-seeking behavior against it. JaredFromSubway has long depended on speed, automation, and aggressive response times to capture MEV opportunities. In this case, those same strengths became liabilities: the faster the bot reacted, the faster it committed to the trap.
Since becoming active in early 2023, JaredFromSubway has reportedly carried out hundreds of thousands of sandwich attacks. At its peak, gross revenue was estimated at roughly $34 million to $40 million. During the height of Ethereum’s sandwich attack problem, the bot was said to account for around 70% of such attacks on the network in some months. That history has made this reversal especially notable within the crypto community.
Loss Estimates Differ as Bounty Is Offered
While security researchers currently place confirmed losses near $7.5 million, the bot’s creator claims the overall impact is closer to $15 million. Following the incident, a $1 million bounty was reportedly offered in exchange for the return of the funds.
Still, history suggests such recovery efforts face long odds. Similar “MEV bot hunting” incidents have happened before. The report notes that in 2023, a malicious validator used related tactics to extract roughly $25 million from multiple sandwich bots. Compared with that earlier case, this latest exploit appears more elaborate, relying on dozens of fake contracts rather than a single point of attack. The incident underscores how fragile automated MEV systems can become when their assumptions about liquidity, token identity, and execution logic are deliberately manipulated.

