Odaily, citing Cointelegraph, reported that Jaredfromsubway.eth, a well-known MEV bot that has long been active on the Ethereum network, was attacked and lost more than $7.5 million. Security company Blockaid said the incident was not a traditional phishing attack and was not a typical smart contract vulnerability. Instead, it described the case as an “anti-MEV honeypot attack” specifically designed to target the decision-making logic of an MEV bot.
Attack Focused on the Bot’s Automated Execution Logic
Jaredfromsubway.eth has been closely associated with MEV activity on Ethereum. In this incident, the attackers did not rely on tricking ordinary users into clicking a link or signing a standard phishing approval. According to Blockaid’s description, the attack took aim at weaknesses in the bot’s automated execution system, causing the bot to treat the attackers’ setup as a profitable trading opportunity.
Over a period of several weeks, the attackers deployed 66 fake token contracts and fraudulent liquidity pools. These contracts and pools were disguised as environments connected to assets such as WETH, USDC and USDT. The structure was intended to lure Jaredfromsubway.eth into executing trades that appeared profitable while also authorizing auxiliary contracts controlled by the attackers.
Backdoor Permissions Used in a Single Transaction
The attack ultimately culminated in one transaction. The attackers called all of the accumulated backdoor permissions and transferred assets held by the bot address, including ETH, USDC and USDT. The total loss exceeded $7.5 million. Blockaid’s description places the focus on the bot’s strategy evaluation and execution flow, rather than on a single vulnerable contract.
Data cited in the report showed that from November 2024 to October 2025, the Ethereum network saw roughly 60,000 to 90,000 sandwich attacks per month. Around 70% of those attacks were associated with Jaredfromsubway.eth. In this case, a bot long linked to MEV execution became the target of a reverse attack, with Blockaid characterizing the method as an anti-MEV honeypot attack aimed at bot logic.

