ChainCatcher reported, citing monitoring by an on-chain analyst, that the well-known Ethereum MEV bot JaredFromSubway was attacked and lost about $7.5 million. The incident centered on the bot’s automated execution process. According to the analysis cited in the report, the attack was not a traditional phishing case and was not described as an exploit of a smart contract vulnerability.
The attacker constructed a fake MEV arbitrage path and induced JaredFromSubway to automatically generate token approvals. While those approvals had not been revoked, the attacker used the open authorizations to transfer WETH, USDC and USDT out of the bot contract. The funds eventually flowed to the attacker’s wallet address.
The analysis characterized the incident as a targeted use of the bot’s automation mechanism. MEV bots typically rely on automated strategies to identify and execute on-chain arbitrage routes. In this case, the report said the attacker used a fabricated arbitrage path and existing open approvals to move assets from the robot contract.

