Ethereum’s well-known MEV bot address Jaredfromsubway.eth has suffered a targeted “anti-MEV honeypot attack,” with losses exceeding $7.5 million. The case has been described as a hunter being hunted: a bot designed to automatically capture on-chain trading opportunities was instead trapped through a setup built around its own execution behavior.
Sixty-Six Fake Contracts and Pools Used to Lure the Bot
According to the report, the attacker deployed 66 fake contracts and liquidity pools that were disguised as mainstream assets. These contracts and pools were used to induce Jaredfromsubway.eth to automatically execute transactions and grant permissions. MEV, or maximal extractable value, generally refers to value extracted through transaction ordering, price differences, or liquidity changes on-chain. In this incident, the attacker targeted the bot’s automated recognition and execution process.
After the bot completed the trades and authorizations, the attacker used a backdoor to steal the assets, resulting in losses of more than $7.5 million. The incident shows that even a highly prominent and profitable MEV bot can face security threats at the behavioral-logic level. The risk in this case was not limited to smart contract code; it also involved how an automated strategy makes decisions and grants permissions in a complex on-chain environment.

