$7.5 Million Reversal: Ethereum's Largest Sandwich Bot Drained

$7.5 Million Reversal: Ethereum's Largest Sandwich Bot Drained

N
News Editor
2026-06-23 06:01:51
Ethereum's prominent sandwich bot jaredfromsubway.eth was exploited via a lingering approval vulnerability, losing $7.5 million in assets and exposing systemic risks in the MEV ecosystem.
EthereumMEVsandwich attacksecurity vulnerability

One of Ethereum's largest sandwich bots, known as jaredfromsubway.eth, has fallen victim to a hacking attack exploiting a lingering approval vulnerability, resulting in the loss of approximately $7.5 million in assets. The bot had long engaged in sandwich attacks—a front-running strategy—to extract MEV (Maximal Extractable Value), but this time it became the target.

The lingering approval vulnerability occurs when users fail to revoke token approvals after interacting with decentralized exchange contracts. Attackers can leverage these leftover approvals to transfer tokens directly. In this case, the hacker bypassed the bot's own defensive mechanisms through such unrevoked permissions.

The incident highlights multiple systemic risks within the MEV ecosystem: bots preying on each other, poor approval management, potential validator manipulation of transaction ordering, and excessive mempool transparency. These issues not only endanger bot operators but also threaten the security of ordinary users' assets and the finality of Ethereum transactions.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.