Odaily reported that Jaredfromsubway.eth, a well-known MEV bot long active on the Ethereum network, has suffered a reverse attack that resulted in losses of more than $7.5 million. Security firm Blockaid said the incident was not a traditional phishing attack and was not a standard smart contract exploit. Instead, it described the case as an “anti-MEV honeypot attack” specifically designed to target the decision-making logic of an MEV bot.
Fake contracts and liquidity pools built over several weeks
According to the disclosed information, the attackers deployed 66 fake token contracts and false liquidity pools over a period of several weeks. These contracts and pools were presented as environments involving assets such as WETH, USDC and USDT. They were structured to make the bot identify trades that appeared profitable, leading Jaredfromsubway.eth to interact with them through its automated execution system.
During that process, the bot granted permissions to auxiliary contracts controlled by the attackers. Blockaid characterized the strategy as a reverse trap aimed at MEV logic: rather than stealing keys, impersonating a user interface, or exploiting a conventional code flaw, the attackers targeted how the bot evaluated on-chain prices, liquidity and execution opportunities. The authorizations created during those interactions later gave the attackers a path to use the backdoor permissions together.
Assets moved in a single transaction
In the final stage, the attackers called all of the backdoor permissions in a single transaction and transferred assets held by the bot address, including ETH, USDC and USDT. The total loss exceeded $7.5 million, turning a long-running MEV actor on Ethereum into the target of a strategy built around its own automated trading behavior.
The report also cited data showing that between November 2024 and October 2025, the Ethereum network saw roughly 60,000 to 90,000 sandwich attacks each month. About 70% of those attacks were related to Jaredfromsubway.eth. The incident was reported by Cointelegraph and centers on how automated MEV systems can be exposed when adversaries design on-chain environments around their execution logic.

