The Hunter Becomes the Hunted: The Most Profitable MEV Bot Gets Hacked

marsbitPublicado a 2026-06-21Actualizado a 2026-06-21

Resumen

A well-known and highly profitable Ethereum MEV Bot, Jaredfromsubway.eth, suffered a sophisticated on-chain attack this Saturday, losing over $7.5 million. Analysis by Blockaid and others reveals this was not a conventional phishing or smart contract exploit, but a targeted "counter-MEV honeypot attack." The attacker meticulously laid a trap over several weeks, deploying 66 fake token contracts and liquidity pools disguised as major assets like WETH and USDC. These pools created the illusion of arbitrage opportunities. The MEV Bot's automated system detected these signals, executed trades, and in the process, granted approval permissions to attacker-controlled contracts. These approvals were not revoked, creating a persistent vulnerability. The attacker then exploited this in a single transaction, draining the bot's ETH, USDC, and USDT holdings. Jaredfromsubway.eth is notorious as one of Ethereum's most active and profitable MEV Bots, primarily known for executing "sandwich attacks" to profit from transaction slippage. Estimates suggest it has earned tens of millions in MEV revenue. The incident highlights escalating crypto security threats, demonstrating that even top-tier automated "predators" are vulnerable to novel, logic-based attacks designed to exploit their own operational rules. Following the hack, an unverified X account impersonating Jaredfromsubway.eth emerged, falsely offering a bounty for the return of funds, prompting developer warnings for users to stay vig...

By Azuma(@azuma_eth)

Jaredfromsubway.eth, a well-known MEV Bot address long active on the Ethereum network, was targeted in a highly specific on-chain attack on Saturday, resulting in losses exceeding $7.5 million.

Investigations by Blockaid and several on-chain analytics firms revealed that this incident was not a traditional phishing attack or smart contract exploit, but rather a "counter-MEV honeypot attack" specifically designed to exploit the operational logic of MEV Bots.

Over the preceding weeks, the attacker systematically deployed 66 counterfeit token contracts and fake liquidity pools. These assets were meticulously disguised on-chain as major stable assets like WETH, USDC, and USDT, creating seemingly genuine arbitrage trading pathways.

The attack chain unfolded as follows — fake liquidity pools generated signals of "exploitable price gaps"; the MEV bot automatically identified the arbitrage opportunity and executed a trade; during the transaction, the robot granted authorization to an auxiliary contract controlled by the attacker; this authorization was not revoked promptly, leading to persistent exposure of permissions; finally, the attacker triggered a pre-embedded backdoor logic in a single transaction, directly transferring assets such as ETH, USDC, and USDT held by the MEV bot's address.

On-chain data shows that the total scale of assets stolen from Jaredfromsubway.eth this time has exceeded $7.5 million. The attacker subsequently split and transferred some of the assets, further dispersing the fund flow through mixing tools.

Who is Jaredfromsubway.eth? The Most Notorious MEV Bot Address

The reason this attack is so notable now is that the victim, Jaredfromsubway.eth, is itself the most active, most profitable, and most notorious MEV Bot on the Ethereum network (perhaps without even needing 'one of').

"MEV attacks" are essentially a category of on-chain arbitrage behaviors centered around "transaction ordering rights." In the Ethereum network, transactions wait in the mempool to be included in a block before they are confirmed. Block builders or searchers can adjust transaction order, insert transactions, or rearrange transactions within a block to extract additional profits.

The most typical attack type is the "Sandwich Attack"— the attacker inserts a buy order before and a sell order after a user's transaction, profiting from price slippage within a short timeframe. This behavior is extremely common in high-liquidity DeFi trading pairs and constitutes one of the most fundamental profit models within the MEV ecosystem.

Jaredfromsubway.eth is precisely the most representative automated executor of this mechanism. Unlike traditional "single-point arbitrage bots," this MEV Bot operates more like a highly industrialized MEV execution system. It continuously monitors unconfirmed transactions in the mempool, identifies in real-time transaction paths vulnerable to sandwiching, and within an extremely short time window, completes transaction construction, gas bidding, and order insertion, systematically capturing slippage profits.

Data from Cointelegraph Research shows that between November 2024 and October 2025, approximately 60,000 to 90,000 sandwich attacks occurred monthly on the Ethereum network, with about 70% related to Jaredfromsubway.eth's strategy system.

In May this year, when Ethereum co-founder Vitalik Buterin exchanged 26,544 DigitalBits (XDB), his transaction was also precisely targeted and sandwiched by Jaredfromsubway.eth.

There is no official statistic on Jaredfromsubway.eth's historical revenue, but conservative estimates suggest that the address has accumulated tens of millions of dollars in MEV profits during its active periods. During some peak periods, its single-day profits could reach hundreds of thousands of dollars, and it consistently appeared at the top of Ethereum MEV rankings for a long time.

Crypto Security Threats Escalate: Even Top Predators Are Not Safe

While some may marvel at the "hunter finally getting hunted," the hacking of Jaredfromsubway.eth also rings an alarm bell for cryptocurrency risks once again.

In past perceptions, MEV Bots like Jaredfromsubway.eth belonged to the "predator" side of the on-chain ecosystem — they continuously capture slippage and arbitrage opportunities in user transactions through automated strategies, inherently occupying an advantageous position, and could even be considered a representative class of attackers in the crypto market.

But this time, it became the target of design, inducement, and eventual harvesting. Moreover, the attacker did not choose a traditional vulnerability exploitation path. Instead, they constructed a long-running "behavioral trap," allowing the MEV Bot's automated system to proceed step by step towards erroneous decisions while fully complying with its own rules.

It must be admitted that even participants like Jaredfromsubway.eth, who were once most adept at "exploiting the rules," are now exposed to more multidimensional attack surfaces.

It is also worth noting that after the Jaredfromsubway.eth hack, an unknown account on X with 94,000 followers changed its name to Jaredfromsubway.eth and falsely claimed it would "offer a $1 million bounty for the full return of all funds."

Several developers issued risk warnings regarding this, emphasizing that the account is not an official Jaredfromsubway.eth account (the MEV Bot team has no official account) and that it cannot be ruled out that this account might be used for scams in the future. Users are urged to remain highly vigilant.

Preguntas relacionadas

QWhat type of attack was the Jaredfromsubway.eth MEV bot a victim of?

AIt was a victim of a 'counter-MEV honeypot attack', a targeted attack designed to exploit the behavioral logic of MEV bots, not a traditional phishing or smart contract exploit.

QWho is Jaredfromsubway.eth and what is it known for in the Ethereum ecosystem?

AJaredfromsubway.eth is one of the most active, profitable, and notorious MEV bots on the Ethereum network. It is particularly known for executing 'sandwich attacks' to capture slippage profits from user transactions.

QWhat was the estimated total loss for Jaredfromsubway.eth in this attack?

AThe estimated total loss for Jaredfromsubway.eth in this attack was over $7.5 million in assets like ETH, USDC, and USDT.

QWhat specific attack method was used to set up the trap for the MEV bot?

AThe attackers deployed 66 fake token contracts and fake liquidity pools over several weeks. These mimicked mainstream assets like WETH, USDC, and USDT to create seemingly profitable arbitrage opportunities, ultimately tricking the bot into granting permissions that were later exploited.

QWhat did the impersonator account on X (formerly Twitter) falsely claim after the attack?

AAn impersonator account on X, with the name changed to Jaredfromsubway.eth, falsely claimed it would offer a '$1 million bounty for the full return of all funds'.

Lecturas Relacionadas

a16z Crypto: Marc Andreessen and Chris Dixon Explain Why the 'CLARITY Act' Is Urgently Needed

The CLARITY Act proposes a critical federal regulatory framework for the U.S. crypto market. Currently, a lack of clear rules creates uncertainty, hinders innovation, and leaves consumers exposed. The Act would clearly divide regulatory jurisdiction between the SEC and CFTC, mandate disclosures and insider restrictions for projects, and bring exchanges and other intermediaries under a comprehensive oversight system akin to traditional finance. This clarity is urgently needed as crypto has evolved from a niche interest into a major industry with institutional involvement. Clear, lasting rules would protect consumers by requiring proper audits, custody of client assets, and anti-fraud measures for registered platforms, helping prevent failures like FTX. Regulatory ambiguity currently punishes compliant U.S. firms with high costs while rewarding offshore competitors who bypass rules, creating a race to the bottom. The Act addresses national security by applying existing anti-money laundering rules to crypto intermediaries and distinguishes between legitimate privacy and illicit concealment. It also resolves banking sector concerns by prohibiting interest payments on stablecoin balances while permitting transaction-based rewards. For developers, it establishes liability based on intent and direct assistance to crime, not for unforeseeable downstream misuse of open-source software. Regarding securities law, the Act introduces a risk-based framework. Assets begin under SEC oversight when a network is centralized, transitioning to CFTC commodity regulation if it becomes sufficiently decentralized, with clear definitions to avoid constant litigation. Without the Act, regulatory uncertainty driven by shifting agency interpretations will persist, discouraging long-term investment in the U.S. and pushing development offshore, reducing American oversight and economic leadership. Support for the bipartisan bill comes from lawmakers, law enforcement (like the Fraternal Order of Police), and major financial institutions. Ultimately, the CLARITY Act is essential to establish a stable, sensible regulatory environment that fosters responsible innovation, enhances consumer protection, and ensures U.S. leadership in shaping the future of financial technology.

marsbitHace 51 min(s)

a16z Crypto: Marc Andreessen and Chris Dixon Explain Why the 'CLARITY Act' Is Urgently Needed

marsbitHace 51 min(s)

Citi's Interpretation: Why Does Citi Still Give SanDisk a Target Price of $2500 After Earnings Report Despite a Significant Stock Price Drop?

Citi maintains a "Buy" rating on SanDisk with a $2500 price target despite a post-earnings stock drop. This target, implying an 85.1% upside from the August 5th close of $1350.50, hinges on the firm's view that SanDisk merits a higher valuation than traditional NAND cyclical stocks. Although SanDisk reported strong Q4 FY26 results with revenue up 51% sequentially and robust full-year data center growth (+437%), its stock fell sharply on August 6th. Investors are concerned about potential NAND price growth moderation and guidance that failed to meet elevated market expectations. Citi's bullish thesis centers on SanDisk's new long-term "New Business Model" (NBM) agreements. These contracts, covering a significant portion of its NAND bit output for FY27 and FY28, represent minimum revenue commitments of approximately $94 billion backed by financial guarantees. This structure aims to increase revenue and cash flow predictability. The report links this visibility to AI data center demand, driven by the expansion of inference workloads requiring more storage. Citi estimates data center storage capacity demand will grow about 35% in CY27. However, the analysis notes long-term contracts cannot eliminate the NAND cycle. Risks include potential oversupply from industry capacity expansion, competition, and macroeconomic headwinds. The $2500 target essentially bets that AI demand and these contracts can reduce earnings volatility enough to support a premium valuation (~11x CY27E EPS). Key factors to watch are the execution of the $94B commitments, pricing mechanisms, actual data center demand, and industry supply dynamics.

marsbitHace 1 hora(s)

Citi's Interpretation: Why Does Citi Still Give SanDisk a Target Price of $2500 After Earnings Report Despite a Significant Stock Price Drop?

marsbitHace 1 hora(s)

Dark Pools Prevail, Whales Vanish: How Credible Are Public Market Signals?

Institutional cryptocurrency trading is increasingly shifting towards dark pools and over-the-counter (OTC) desks, with data from sFOX showing such venues accounted for 15% of total monthly volume by June, up from negligible levels in April. In July, 77.7% of institutional capital on sFOX's platform was routed through OTC desks, while only 18.4% went to public exchanges. A key driver is institutions' need to conceal large orders to avoid revealing trading patterns, preventing front-running and minimizing price impact. Firms like Jane Street and Citadel use dark pools and order-splitting across multiple venues to execute trades discreetly. This structural shift mirrors earlier developments in equities and forex markets. As a result, public order books now reflect only a fraction of actual market activity, eroding the once-significant advantage retail traders had in tracking large wallets and exchange flows. The proliferation of prime brokers and aggregation platforms is also rapidly closing simple arbitrage opportunities. The market may evolve toward a brokerage model for retail, similar to traditional stocks. Two scenarios emerge: an optimistic one where retail gains from narrower spreads and better order routing, and a pessimistic one where transparency declines faster than benefits trickle down, leaving smaller investors in the dark. Regardless, traders must adapt by not relying solely on exchange volume, comparing total execution costs, and using limit orders in thin markets. While reduced volatility from hidden large trades may seem positive, it comes at the cost of obscured market signals and institutional intent.

marsbitHace 1 hora(s)

Dark Pools Prevail, Whales Vanish: How Credible Are Public Market Signals?

marsbitHace 1 hora(s)

Trading

Spot
活动图片