ChainCatcher reported that, according to monitoring by on-chain analysts, the well-known Ethereum MEV bot JaredFromSubway suffered an attack that resulted in a loss of about $7.5 million. JaredFromSubway is associated with automated MEV-related execution on Ethereum, and the reported incident centered on the way the bot handled execution rather than on a conventional user phishing flow.
Fake MEV Arbitrage Routes Led to Token Approvals
The attackers constructed false MEV arbitrage paths and used them to induce the bot to automatically generate token approvals. Because those approvals were not revoked, the attackers were able to make use of the open authorization and transfer WETH, USDC and USDT from the bot contract. The funds ultimately flowed to a wallet address controlled by the attacker.
The analysis cited in the report stated that this incident was not a traditional phishing attack and was not a standard smart contract vulnerability. Instead, it was a targeted exploitation of the bot’s automated execution mechanism. The case focuses attention on how token authorization, route validation and automated contract execution interact in on-chain MEV operations.

