TLDR
A major Ethereum MEV bot known as jaredfromsubway.eth was tricked by a sophisticated on-chain trap, losing an estimated $7.5 million to possibly $15 million in assets.
- An attacker spent weeks deploying fake tokens and pools so the MEV bot would grant token approvals that were later used to drain WETH, USDC, and USDT.
- Security firms estimate on-chain losses around $7.5 million, while the operator claims about $15 million and has offered a large bounty to recover funds.
- The exploit targets MEV infrastructure, not Ethereum itself, but it highlights growing risks for bots, DeFi routing, and users in a highly adversarial trading environment.
Deep Dive
1. How The Exploit Worked
The victim was a prominent MEV (maximal extractable value) sandwich bot on Ethereum called jaredfromsubway.eth.
According to security firm Blockaid, the attacker deployed roughly 66 counterfeit token contracts and fake liquidity pools that mimicked assets like WETH, USDC, and USDT, luring the bot into treating them as profitable routes and granting token approvals to attacker-controlled contracts. Once large approvals were in place, the attacker used those open allowances to sweep real WETH, USDC, and USDT from the bots contracts, draining about $7.5 million worth of assets in a single sequence of transactions.
Reports describe this as a counter-MEV or reverse honeypot attack: instead of exploiting a protocol bug or stealing keys, the attacker turned the bots own routing and profit logic into the vulnerability.
Even sophisticated bots that profit from others transactions can be trapped if they blindly trust on-chain routes and leave token approvals too flexible.
2. Loss Size And Recovery Efforts
Blockchain forensics firms including Blockaid and PeckShield place the on-chain drain at roughly $7.5 million, based on the value of WETH, USDC, and USDT moved out of the bots control.
The bots operator, however, has publicly claimed total losses closer to $15 million and offered a large white-hat style bounty to the attacker if a significant portion of funds is returned, with some reports citing a 50% recovery deal and tight deadline for cooperation. Crypto.news notes this discrepancy between the operators claim and the security firms lower on-chain estimate, which remains unresolved.
Funds have reportedly been partially swapped into ETH and some sent through Tornado Cash, complicating recovery efforts.
3. Broader Impact On Ethereum And MEV
This incident does not indicate a flaw in Ethereum (ETH) itself or a generic wallet vulnerability. Blockaid explicitly said it was not a classic phishing case and not a traditional smart contract bug in the victim contract.
Instead, it exposes structural risk in industrial-scale MEV: highly automated systems that chase tiny edges at machine speed can be profiled and trapped by patient adversaries. The same bot has been linked to around 70% of Ethereum sandwich attacks between late 2024 and late 2025, which Cointelegraph Research estimates cost traders about $60 million per year, so its compromise is symbolically significant for the MEV ecosystem.
For most users, day-to-day Ethereum usage is unaffected, but MEV operators, DeFi protocols, and advanced traders need to harden routing logic, token approval management, and detection of fake liquidity routes.
Conclusion
A sophisticated attacker turned one of Ethereums most aggressive MEV bots into the victim, draining millions of dollars by abusing its approval logic rather than any core protocol bug. The incident highlights how adversarial and complex the MEV landscape has become, and suggests that the next layer of defense on Ethereum will be about safer routing, stricter approval patterns, and more robust MEV-aware infrastructure rather than just traditional contract audits.
