According to MarsBit, the prominent Ethereum MEV sandwich bot jaredfromsubway.eth was recently hacked. The attacker exploited a dangling approval vulnerability in the bot's contract and drained all of its $7.5 million in assets. The bot had been widely known for frequently executing sandwich trades, making it a representative figure in the on-chain MEV landscape.
The incident not only caused a massive financial loss but also highlighted multiple layers of systemic risk within the MEV ecosystem. These include inter-bot attacks, misuse of approval mechanisms, potential validator misconduct, and security issues stemming from mempool transparency. Such risks threaten not only the MEV bots themselves but also the asset security of ordinary users and challenge the finality of Ethereum transactions.
A dangling approval vulnerability occurs when an unrevoked token allowance is exploited by an attacker to transfer assets. The event has reignited community discussions about the security and fairness of the MEV ecosystem.

