Hunter Becomes the Hunted: The Most Profitable MEV Bot Gets Hacked

Odaily星球日报Published on 2026-06-21Last updated on 2026-06-21

Abstract

The prominent Ethereum MEV bot address Jaredfromsubway.eth suffered a targeted on-chain attack, losing over $7.5 million. The incident was identified as a "counter-MEV honeypot attack," where the attacker deployed numerous fake token contracts and liquidity pools over several weeks, mimicking mainstream assets like WETH and USDC to create seemingly profitable arbitrage opportunities. The MEV bot, designed to automatically detect and execute such trades, interacted with the malicious setup. During the process, it granted approvals to attacker-controlled contracts, which were not promptly revoked. The attacker later exploited these persistent permissions in a single transaction, draining the bot's holdings of ETH, USDC, and USDT. Jaredfromsubway.eth is known as one of Ethereum's most active and profitable MEV bots, primarily executing "sandwich attacks" to extract value from user transactions. Its operations have been linked to a majority of such attacks on the network. This event highlights the evolving security threats in crypto, demonstrating that even sophisticated, rule-exploiting systems can become targets of carefully designed behavioral traps. Following the theft, an impersonator account on X falsely claimed to offer a bounty for the return of the funds, prompting warnings from developers.

Original | Odaily Planet Daily (@OdailyChina)

Author | Azuma (@azuma_eth)

The well-known MEV Bot address Jaredfromsubway.eth, long active on the Ethereum network, was targeted in a highly sophisticated on-chain attack on Saturday, resulting in losses exceeding $7.5 million.

According to investigations by Blockaid and several on-chain analytics firms, this incident was not a traditional phishing attack or smart contract exploit. Instead, it was a "counter-MEV honeypot attack" specifically designed to target the operational logic of MEV Bots.

Over the preceding weeks, the attacker had systematically deployed 66 counterfeit token contracts and fake liquidity pools. These assets were meticulously disguised on-chain as mainstream stablecoins like WETH, USDC, and USDT, creating seemingly legitimate arbitrage trading pathways.

The attack chain unfolded step by step — the fake liquidity pools generated signals for "arbitrageable price gaps"; the MEV bot automatically identified the arbitrage opportunity and executed trades; during the transaction, the robot granted authorization to an auxiliary contract controlled by the attacker; this authorization was not promptly revoked, leading to persistent exposure of permissions; Ultimately, in a single transaction, the attacker triggered a pre-embedded backdoor logic, directly draining the ETH, USDC, and USDT held in the MEV bot's address.

On-chain data shows that the total value of assets stolen from Jaredfromsubway.eth in this attack has exceeded $7.5 million. The attacker subsequently split and transferred portions of the funds, further dispersing the flow through mixing tools.

Who is Jaredfromsubway.eth? The Most Notorious MEV Bot Address

The reason this attack is so notable today is that the victim, Jaredfromsubway.eth, is itself one of the most active, profitable, and notorious MEV Bots on the Ethereum network (if not the most).

Essentially, "MEV attacks" are a category of on-chain arbitrage behaviors revolving around "transaction ordering rights." On the Ethereum network, transactions enter the mempool to await block inclusion before being confirmed. Block builders or searchers can extract extra profit by adjusting transaction order, inserting transactions, or rearranging transactions within a block.

The most typical attack type is the "Sandwich Attack" — the attacker inserts buy and sell operations immediately before and after a user's transaction, profiting from the price slippage within a very short time frame. Such behavior is extremely common in high-liquidity DeFi trading pairs and constitutes one of the most fundamental profit models within the MEV ecosystem.

Jaredfromsubway.eth is precisely the most representative automated executor of this mechanism. Unlike traditional "single-point arbitrage bots," this MEV Bot resembles a highly industrialized MEV execution system. It continuously monitors unconfirmed transactions in the mempool, identifies in real-time transaction paths susceptible to being sandwiched, and completes transaction construction, Gas bidding, and order insertion within an extremely short time window, systematically capturing slippage profits.

Data from Cointelegraph Research shows that from November 2024 to October 2025, approximately 60,000 to 90,000 sandwich attacks occurred monthly on the Ethereum network, with about 70% related to the strategic system of Jaredfromsubway.eth.

In May of this year, when Ethereum co-founder Vitalik Buterin exchanged 26,544 DigitalBits (XDB), his transaction was also targeted and sandwiched by Jaredfromsubway.eth.

Regarding Jaredfromsubway.eth's historical revenue, there is no official statistic, but conservative estimates suggest that the address has accumulated MEV profits reaching tens of millions of dollars during its active periods. During some peak periods, its daily earnings could reach hundreds of thousands of dollars, and it consistently ranked near the top of Ethereum's MEV leaderboards.

Crypto Security Threats Intensify: Even Top Predators Are Not Spared

While one might muse that "the eagle-hunter finally got pecked," the hacking of Jaredfromsubway.eth has also sounded another alarm regarding risks in the cryptocurrency space.

In past perceptions, MEV Bots like Jaredfromsubway.eth belonged to the "predator" side of the on-chain ecosystem — they continuously capture slippage and arbitrage opportunities within user transactions through automated strategies, positioning themselves advantageously, arguably representing one of the most iconic types of attackers in the cryptocurrency market.

But this time, it became the one that was designed, lured, and ultimately harvested. Moreover, the attacker did not choose a traditional exploit path. Instead, they constructed a long-running "behavioral trap," allowing the MEV Bot's automated system to make progressively flawed decisions while fully complying with its own rules.

It must be acknowledged that even participants like Jaredfromsubway.eth, once most adept at "gaming the system," are now exposed to a broader attack surface.

Additionally, it is worth noting that after Jaredfromsubway.eth was hacked, an unknown X account with 94,000 followers changed its name to Jaredfromsubway.eth and falsely claimed it would "offer a $1 million bounty for the full return of all funds."

Several developers issued risk warnings, emphasizing that this account is not the official Jaredfromsubway.eth account (the MEV Bot team has no official account). They cautioned that this account might be used for scams subsequently and urged users to remain highly vigilant.

Related Questions

QWhat type of attack did the MEV bot Jaredfromsubway.eth fall victim to, according to the article?

AThe article states that the MEV bot Jaredfromsubway.eth was targeted by a 'counter-MEV honeypot attack.' This was not a traditional phishing or smart contract exploit, but a sophisticated attack specifically designed to exploit the MEV bot's behavioral logic.

QWhat was the estimated total loss suffered by Jaredfromsubway.eth in this incident?

AAccording to on-chain data cited in the article, the total value of assets stolen from Jaredfromsubway.eth exceeded 7.5 million US dollars.

QAccording to the article, what is a 'Sandwich Attack' in the context of MEV?

AA 'Sandwich Attack' is described as a typical type of MEV attack. In this strategy, the attacker inserts buy and sell orders before and after a target user's transaction, respectively, to profit from the price slippage within a very short time window.

QWhat significant event involving Vitalik Buterin is mentioned in relation to Jaredfromsubway.eth?

AThe article mentions that in May of this year (presumably 2025), Ethereum co-founder Vitalik Buterin was targeted by Jaredfromsubway.eth when exchanging 26,544 DigitalBits (XDB) tokens.

QFollowing the hack, what fake action was taken by an unknown X account, and what warning was given?

AAn unknown X account with 94,000 followers changed its name to Jaredfromsubway.eth and falsely announced a '1 million US dollar bounty for the full return of all funds.' Developers issued warnings that this is not the official account (as the MEV bot team has none) and cautioned users to remain vigilant as the account might be used for scams.

Related Reads

Programmers Worldwide Are Wasting Money on Anthropic! The Company Can't Stand It Anymore

Anthropic recently published guidelines to help developers using Claude Code reduce unnecessary token costs. The key recommendations include: 1) Clear (/clear) conversations after completing a task to avoid carrying irrelevant file reads and command outputs into the next task. 2) Set the model and reasoning effort level at the start of a session, as switching mid-session invalidates the prompt cache, requiring a full-price recalculation of the entire dialog history. 3) Attach files using @ references instead of typing paths manually to avoid extra tool calls and searches that bloat the context. 4) Add quiet flags to verbose commands (e.g., in CLAUDE.md) to minimize lengthy output in the dialog history. 5) Use /compact while the session cache is still warm (before breaks) to compress the dialog at one-tenth the cost. 6) Offload large-output tasks to a sub-agent, which runs in an isolated context and only returns conclusions, preventing intermediate outputs from polluting the main dialog. The article explains token pricing: input tokens (prefill) are processed in parallel, while output tokens (decode) are generated serially, making output tokens five times more expensive. Caching is crucial for savings—if a request's prefix (system prompt, CLAUDE.md, dialog history) matches the previous one byte-for-byte, reading it costs only 10% of the standard input price. However, cache invalidation occurs when changing models, effort levels, fast mode, compressing dialogs, after cache expiration, or when resuming old sessions. Dialog history also grows quadratically (O(n²)) as file contents and command outputs accumulate, increasing costs per round. Proactive context management—like isolating noisy tasks, using /rewind to trim unproductive turns, and task-based session clearing—is becoming an essential skill for cost-effective AI-assisted development.

marsbit1h ago

Programmers Worldwide Are Wasting Money on Anthropic! The Company Can't Stand It Anymore

marsbit1h ago

Pax Silica vs. WAICO: The US Wants to Prohibit Europe from Using Chinese Artificial Intelligence

The United States is preparing to demand that European and other partners abandon Chinese artificial intelligence initiatives, threatening exclusion from the American-led "Pax Silica" coalition, according to a leaked U.S. State Department document. This ultimatum forces signatories of the "AI Opportunity Statement" to choose between the Western technological ecosystem and alternative frameworks, with China not explicitly named but clearly targeted. Pax Silica is a U.S. strategy for AI and semiconductor hegemony, launched in late 2025. Its European presence expanded significantly in mid-2026. Concurrently, China, Russia, and 27 other nations established the World AI Cooperation Organization (WAICO) in July 2026 as an independent intergovernmental platform promoting AI governance based on UN principles. This situation creates a difficult choice, especially for European nations balancing strategic autonomy with dependence on U.S. tech and security. It also pressures Global South countries with pragmatic ties to both Washington and Beijing. The formation of competing blocks risks fragmenting the global tech landscape, forcing companies to split supply chains, increasing costs, and potentially leading to incompatible standards and protocols. The era of open globalization in AI may be ending, replaced by geopolitical confrontation where technological sovereignty trumps economic efficiency. The decisions made will shape the global digital economy for decades.

cryptonews.ru3h ago

Pax Silica vs. WAICO: The US Wants to Prohibit Europe from Using Chinese Artificial Intelligence

cryptonews.ru3h ago

Robert Kiyosaki Shares His Mentor's Predictions About the Emergence of Bitcoin and AI

American entrepreneur and author of "Rich Dad Poor Dad," Robert Kiyosaki, discussed the influence of futurist R. Buckminster Fuller on his worldview, linking Fuller's past technological predictions to the emergence of Bitcoin and the development of artificial intelligence. In an X post, Kiyosaki also reflected on personal purpose, sharing his journey from the music business—where he worked with bands like The Police and Iron Maiden—to creating the "Cashflow" board game and writing his famous book. He described feeling an inner emptiness despite his success, a turning point that came after meeting Fuller, whom he studied with for three summers. Kiyosaki described Fuller as a "friendly genius" who foresaw world-changing developments like Bitcoin and AI. However, the core of his post focused on Fuller's philosophical impact, particularly a quote about belonging to the universe and finding purpose by dedicating one's life to the maximum benefit of others. The entrepreneur remains a vocal advocate for cryptocurrencies. He regularly advises buying Bitcoin during market panics, viewing it and assets like Ethereum, gold, and silver as hedges against traditional financial system failures. Kiyosaki has predicted a major market crash by 2026, seeing it as an opportunity for prepared investors, with long-term price targets including $750,000 for Bitcoin and $95,000 for Ethereum.

cryptonews.ru5h ago

Robert Kiyosaki Shares His Mentor's Predictions About the Emergence of Bitcoin and AI

cryptonews.ru5h ago

Etherealize CEO Calls Wall Street's Private Blockchains a 'Race to the Bottom'

Etherealize co-founder and CEO Vivek Raman criticized Wall Street's growing interest in private, permissioned blockchains, calling them a "race to the bottom." In an interview with CoinDesk, Raman argued that consortium networks fragment liquidity and return the industry to the siloed systems that blockchain technology was meant to overcome. He stated that closed networks do not interoperate, undermining two key advantages of the technology: system compatibility and liquidity concentration. Etherealize promotes Ethereum as an open, foundational layer for institutional players. Raman insists that privacy and access restrictions should be built on top of public infrastructure—at the application or L2 level—rather than creating separate, closed networks. He compared Ethereum to HTTP as a base layer, with additional permissioned and private layers akin to HTTPS. Examples of this new wave of "closed" solutions mentioned include Canton Network from Digital Asset, Circle's Arc project, and Stripe's Tempo. Raman termed this trend "consortium chains 2.0," recalling earlier initiatives like the R3 interbank consortium and the Hyperledger corporate ecosystem from 2016 that failed to gain significant traction. He reiterated his firm belief that a global, open, permissionless infrastructure is necessary as a foundational base layer. Raman previously noted in June that traditional financial institutions had begun implementing Ethereum-based solutions into real business processes.

cryptonews.ru5h ago

Etherealize CEO Calls Wall Street's Private Blockchains a 'Race to the Bottom'

cryptonews.ru5h ago

Trading

Spot
活动图片