One of Ethereum's largest sandwich bots, known as jaredfromsubway.eth, has fallen victim to a hacking attack exploiting a lingering approval vulnerability, resulting in the loss of approximately $7.5 million in assets. The bot had long engaged in sandwich attacks—a front-running strategy—to extract MEV (Maximal Extractable Value), but this time it became the target.
The lingering approval vulnerability occurs when users fail to revoke token approvals after interacting with decentralized exchange contracts. Attackers can leverage these leftover approvals to transfer tokens directly. In this case, the hacker bypassed the bot's own defensive mechanisms through such unrevoked permissions.
The incident highlights multiple systemic risks within the MEV ecosystem: bots preying on each other, poor approval management, potential validator manipulation of transaction ordering, and excessive mempool transparency. These issues not only endanger bot operators but also threaten the security of ordinary users' assets and the finality of Ethereum transactions.

