Infamous MEV Bot JaredFromSubway Drained For $7.5 Million

bitcoinistPublished on 2026-06-22Last updated on 2026-06-22

Abstract

The notorious Ethereum MEV bot "JaredFromSubway" has been drained of approximately $7.5 million after attackers tricked its automated system. Security firm Blockaid reported that the bot was deceived into approving malicious trading routes by attacker-controlled contracts. These approvals were then used to siphon WETH, USDC, and USDT from the bot's contract. The incident is ironic as MEV bots are designed to exploit minute market advantages, but in this case, its own automation became the vulnerability. The attack specifically targeted the bot's trading logic, not the Ethereum protocol or a broader DeFi application. It underscores a critical risk in automated trading: the pursuit of speed can create fragility, making systems susceptible to carefully crafted traps. While the financial loss is significant, the broader impact is reputational for MEV infrastructure. It serves as a warning that automated systems granting token approvals require stringent safeguards, simulation, and route verification. The event is considered a targeted exploit on a trading bot, not a network-wide security issue.

One of Ethereum’s most notorious MEV bots, known as JaredFromSubway, has reportedly been drained for around $7.5 million after attacker-controlled contracts tricked its automated system into granting token approvals.

TL;DR

  • The JaredFromSubway MEV bot was reportedly drained for about $7.5 million.
  • Security firm Blockaid said the bot was tricked into approving malicious trading routes.
  • The attacker then used those approvals to pull assets from the bot contract.
  • The incident appears to target the bot’s own automation, not Ethereum itself.

CoinDesk reported that Blockaid identified the exploit, saying attacker-controlled contracts tricked the bot into approving fake trading routes. Those approvals were later used to drain WETH, USDC and USDT from the bot’s contract. The incident has drawn attention because JaredFromSubway has long been associated with aggressive sandwich trading on Ethereum.

The irony is hard to miss. MEV bots are built to exploit tiny timing and routing advantages in on-chain markets. In this case, the bot’s own automation appears to have become the weakness. Instead of extracting value from other users, it was manipulated into approving contracts that later drained its balances.

What Happened

The reported exploit was not a hack of Ethereum’s base protocol. It was also not a broad failure of a major DeFi application used by ordinary depositors. The target was a specific MEV bot and the logic it used to interact with contracts during automated trading.

That distinction matters. MEV infrastructure moves quickly and often relies on highly automated decision-making. If that automation can be tricked into approving the wrong contract, the risk can be severe because transactions execute with little human review.

According to reports, the attacker prepared the trap by using fake routes or contracts that the bot interpreted as profitable opportunities. Once approvals were granted, the attacker used them to transfer assets out. In DeFi terms, it was a reminder that approvals are powerful permissions, not harmless signatures.

Why Traders Care

The story is bigger than one bot getting drained. It highlights a risk that applies across automated trading systems: speed can become fragility. Bots competing in MEV markets need to act faster than human traders, but that also means they can be vulnerable to carefully designed traps.

For Ethereum users, the incident may feel like poetic justice because sandwich bots are widely disliked. But the technical lesson is broader. Any system that grants token approvals based on automated contract interactions needs strict safeguards, simulation and route verification.

The market impact is unlikely to come from the dollar amount alone. A $7.5 million drain is meaningful, but not systemic. The bigger impact is reputational for MEV infrastructure and possibly operational for bot operators who now need to review their approval logic more aggressively.

For now, this should be treated as a targeted exploit against a trading bot, not a network-wide security event.

This report is based on information from Blockaid.

This article was written by the News Desk and edited by Samuel Rae.

Trending Cryptos

Related Questions

QWhat is the name of the infamous MEV bot that was drained of $7.5 million?

AThe name of the bot is JaredFromSubway.

QWhat security firm identified the exploit against the JaredFromSubway bot?

AThe security firm that identified the exploit is Blockaid.

QHow was the JaredFromSubway bot tricked into allowing its assets to be drained?

AThe bot was tricked by attacker-controlled contracts into approving fake trading routes. These approvals were then used to drain its assets.

QWhat types of assets were drained from the MEV bot's contract?

AThe assets drained from the bot's contract were WETH, USDC, and USDT.

QWhat is the core vulnerability or weakness that this exploit highlighted for automated trading systems like MEV bots?

AThe exploit highlighted that the automation and speed required for MEV trading can become a fragility, making bots vulnerable to carefully designed traps that trick their automated approval logic.

Related Reads

1.65 Billion Yuan: Sichuan Power Semiconductor Company Sells Itself

Sichuan-based power semiconductor company Jingyi Semiconductor is being acquired by its customer, Jiangsu-listed power semiconductor firm Suzhou Kaiweite Semiconductor Co., Ltd. ("Kaiweite"), for 1.65 billion yuan. Following the transaction, Jingyi Semiconductor will become a wholly-owned subsidiary of Kaiweite. Kaiweite will pay for the acquisition partly with new shares (approximately 901 million yuan worth) and partly in cash (approximately 749 million yuan). The deal is considered a major asset restructuring as Jingyi Semiconductor's assets and revenue in 2025 were 176.34% and 137.38% of Kaiweite's, respectively. Financially, Kaiweite has reported losses for 2024 and 2025. In contrast, Jingyi Semiconductor has remained profitable. The acquisition is expected to significantly improve Kaiweite's profitability. Jingyi Semiconductor's controlling shareholder and chairman, Yi Kun, along with employee持股 platforms, will hold a 13.28% stake in Kaiweite post-transaction. Founded in 2015 and listed on Shanghai's STAR Market in 2023, Kaiweite is a national-level "Little Giant" specializing in intelligent power semiconductor devices and power integrated chips. Established in 2019, Jingyi Semiconductor is a fabless power semiconductor company and a national-level专精特新重点"Little Giant." Its products, including Intelligent Power Modules (IPM), are supplied to major domestic appliance makers like Midea, Xiaomi, Gree, TCL, and Hisense-Hitachi. The company holds a leading 53.5% market share in China's IPM半桥 module segment for white goods. The strategic acquisition aims to repair Kaiweite's profitability and expand its power semiconductor product portfolio through integration in technology, products, and customer channels.

marsbit1h ago

1.65 Billion Yuan: Sichuan Power Semiconductor Company Sells Itself

marsbit1h ago

Launch Event Turned into a Make-up Ceremony? Why Hasn't Pools.trade Produced a High-Market-Cap Meme Coin Yet?

The article discusses the launch of Pools.trade, Uniswap's new token launch platform on Robinhood Chain, designed as a Meme coin launchpad. Despite generating high initial trading volumes (over $1.5 billion before the official frontend launch), the platform has yet to produce a high-market-cap Meme coin. The piece highlights two primary reasons for this. First, it outlines Pools.trade's features: it offers Instant and Crowd Launch modes, locks liquidity permanently in Uniswap v4 pools, and charges a low 0.25% transaction fee (compared to 1% on competitors like Pons and Flap), with most fees reinvested into liquidity. Second, it identifies a key problem: a lack of perceived fairness. The two most notable coins on the platform, FRONG (a "frog mascot" coin) and POOLS (a platform namesake), were both minted days before Uniswap's official countdown began. This "pre-minting" or "insider" controversy has dampened community FOMO (Fear Of Missing Out) and trust, causing their market caps to fall from peaks of $18 million and $4 million, respectively. The article argues that fairness is foundational for Meme coin success, and its absence has hindered viral growth. In conclusion, while Pools.trade benefits from Uniswap's existing user base and Robinhood Chain's popularity, its current lack of a fair-launch, high-engagement narrative has prevented a breakout hit. However, the author suggests that with its inherent traffic, such a success might not be far off.

Odaily星球日报2h ago

Launch Event Turned into a Make-up Ceremony? Why Hasn't Pools.trade Produced a High-Market-Cap Meme Coin Yet?

Odaily星球日报2h ago

Trading

Spot

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of ETH (ETH) are presented below.

活动图片