Hunter Becomes the Hunted: The Most Profitable MEV Bot Gets Hacked

Odaily星球日报Publicado em 2026-06-21Última atualização em 2026-06-21

Resumo

The prominent Ethereum MEV bot address Jaredfromsubway.eth suffered a targeted on-chain attack, losing over $7.5 million. The incident was identified as a "counter-MEV honeypot attack," where the attacker deployed numerous fake token contracts and liquidity pools over several weeks, mimicking mainstream assets like WETH and USDC to create seemingly profitable arbitrage opportunities. The MEV bot, designed to automatically detect and execute such trades, interacted with the malicious setup. During the process, it granted approvals to attacker-controlled contracts, which were not promptly revoked. The attacker later exploited these persistent permissions in a single transaction, draining the bot's holdings of ETH, USDC, and USDT. Jaredfromsubway.eth is known as one of Ethereum's most active and profitable MEV bots, primarily executing "sandwich attacks" to extract value from user transactions. Its operations have been linked to a majority of such attacks on the network. This event highlights the evolving security threats in crypto, demonstrating that even sophisticated, rule-exploiting systems can become targets of carefully designed behavioral traps. Following the theft, an impersonator account on X falsely claimed to offer a bounty for the return of the funds, prompting warnings from developers.

Original | Odaily Planet Daily (@OdailyChina)

Author | Azuma (@azuma_eth)

The well-known MEV Bot address Jaredfromsubway.eth, long active on the Ethereum network, was targeted in a highly sophisticated on-chain attack on Saturday, resulting in losses exceeding $7.5 million.

According to investigations by Blockaid and several on-chain analytics firms, this incident was not a traditional phishing attack or smart contract exploit. Instead, it was a "counter-MEV honeypot attack" specifically designed to target the operational logic of MEV Bots.

Over the preceding weeks, the attacker had systematically deployed 66 counterfeit token contracts and fake liquidity pools. These assets were meticulously disguised on-chain as mainstream stablecoins like WETH, USDC, and USDT, creating seemingly legitimate arbitrage trading pathways.

The attack chain unfolded step by step — the fake liquidity pools generated signals for "arbitrageable price gaps"; the MEV bot automatically identified the arbitrage opportunity and executed trades; during the transaction, the robot granted authorization to an auxiliary contract controlled by the attacker; this authorization was not promptly revoked, leading to persistent exposure of permissions; Ultimately, in a single transaction, the attacker triggered a pre-embedded backdoor logic, directly draining the ETH, USDC, and USDT held in the MEV bot's address.

On-chain data shows that the total value of assets stolen from Jaredfromsubway.eth in this attack has exceeded $7.5 million. The attacker subsequently split and transferred portions of the funds, further dispersing the flow through mixing tools.

Who is Jaredfromsubway.eth? The Most Notorious MEV Bot Address

The reason this attack is so notable today is that the victim, Jaredfromsubway.eth, is itself one of the most active, profitable, and notorious MEV Bots on the Ethereum network (if not the most).

Essentially, "MEV attacks" are a category of on-chain arbitrage behaviors revolving around "transaction ordering rights." On the Ethereum network, transactions enter the mempool to await block inclusion before being confirmed. Block builders or searchers can extract extra profit by adjusting transaction order, inserting transactions, or rearranging transactions within a block.

The most typical attack type is the "Sandwich Attack" — the attacker inserts buy and sell operations immediately before and after a user's transaction, profiting from the price slippage within a very short time frame. Such behavior is extremely common in high-liquidity DeFi trading pairs and constitutes one of the most fundamental profit models within the MEV ecosystem.

Jaredfromsubway.eth is precisely the most representative automated executor of this mechanism. Unlike traditional "single-point arbitrage bots," this MEV Bot resembles a highly industrialized MEV execution system. It continuously monitors unconfirmed transactions in the mempool, identifies in real-time transaction paths susceptible to being sandwiched, and completes transaction construction, Gas bidding, and order insertion within an extremely short time window, systematically capturing slippage profits.

Data from Cointelegraph Research shows that from November 2024 to October 2025, approximately 60,000 to 90,000 sandwich attacks occurred monthly on the Ethereum network, with about 70% related to the strategic system of Jaredfromsubway.eth.

In May of this year, when Ethereum co-founder Vitalik Buterin exchanged 26,544 DigitalBits (XDB), his transaction was also targeted and sandwiched by Jaredfromsubway.eth.

Regarding Jaredfromsubway.eth's historical revenue, there is no official statistic, but conservative estimates suggest that the address has accumulated MEV profits reaching tens of millions of dollars during its active periods. During some peak periods, its daily earnings could reach hundreds of thousands of dollars, and it consistently ranked near the top of Ethereum's MEV leaderboards.

Crypto Security Threats Intensify: Even Top Predators Are Not Spared

While one might muse that "the eagle-hunter finally got pecked," the hacking of Jaredfromsubway.eth has also sounded another alarm regarding risks in the cryptocurrency space.

In past perceptions, MEV Bots like Jaredfromsubway.eth belonged to the "predator" side of the on-chain ecosystem — they continuously capture slippage and arbitrage opportunities within user transactions through automated strategies, positioning themselves advantageously, arguably representing one of the most iconic types of attackers in the cryptocurrency market.

But this time, it became the one that was designed, lured, and ultimately harvested. Moreover, the attacker did not choose a traditional exploit path. Instead, they constructed a long-running "behavioral trap," allowing the MEV Bot's automated system to make progressively flawed decisions while fully complying with its own rules.

It must be acknowledged that even participants like Jaredfromsubway.eth, once most adept at "gaming the system," are now exposed to a broader attack surface.

Additionally, it is worth noting that after Jaredfromsubway.eth was hacked, an unknown X account with 94,000 followers changed its name to Jaredfromsubway.eth and falsely claimed it would "offer a $1 million bounty for the full return of all funds."

Several developers issued risk warnings, emphasizing that this account is not the official Jaredfromsubway.eth account (the MEV Bot team has no official account). They cautioned that this account might be used for scams subsequently and urged users to remain highly vigilant.

Perguntas relacionadas

QWhat type of attack did the MEV bot Jaredfromsubway.eth fall victim to, according to the article?

AThe article states that the MEV bot Jaredfromsubway.eth was targeted by a 'counter-MEV honeypot attack.' This was not a traditional phishing or smart contract exploit, but a sophisticated attack specifically designed to exploit the MEV bot's behavioral logic.

QWhat was the estimated total loss suffered by Jaredfromsubway.eth in this incident?

AAccording to on-chain data cited in the article, the total value of assets stolen from Jaredfromsubway.eth exceeded 7.5 million US dollars.

QAccording to the article, what is a 'Sandwich Attack' in the context of MEV?

AA 'Sandwich Attack' is described as a typical type of MEV attack. In this strategy, the attacker inserts buy and sell orders before and after a target user's transaction, respectively, to profit from the price slippage within a very short time window.

QWhat significant event involving Vitalik Buterin is mentioned in relation to Jaredfromsubway.eth?

AThe article mentions that in May of this year (presumably 2025), Ethereum co-founder Vitalik Buterin was targeted by Jaredfromsubway.eth when exchanging 26,544 DigitalBits (XDB) tokens.

QFollowing the hack, what fake action was taken by an unknown X account, and what warning was given?

AAn unknown X account with 94,000 followers changed its name to Jaredfromsubway.eth and falsely announced a '1 million US dollar bounty for the full return of all funds.' Developers issued warnings that this is not the official account (as the MEV bot team has none) and cautioned users to remain vigilant as the account might be used for scams.

Leituras Relacionadas

a16z Crypto: Marc Andreessen and Chris Dixon Explain Why the 'CLARITY Act' Is Urgently Needed

The CLARITY Act proposes a critical federal regulatory framework for the U.S. crypto market. Currently, a lack of clear rules creates uncertainty, hinders innovation, and leaves consumers exposed. The Act would clearly divide regulatory jurisdiction between the SEC and CFTC, mandate disclosures and insider restrictions for projects, and bring exchanges and other intermediaries under a comprehensive oversight system akin to traditional finance. This clarity is urgently needed as crypto has evolved from a niche interest into a major industry with institutional involvement. Clear, lasting rules would protect consumers by requiring proper audits, custody of client assets, and anti-fraud measures for registered platforms, helping prevent failures like FTX. Regulatory ambiguity currently punishes compliant U.S. firms with high costs while rewarding offshore competitors who bypass rules, creating a race to the bottom. The Act addresses national security by applying existing anti-money laundering rules to crypto intermediaries and distinguishes between legitimate privacy and illicit concealment. It also resolves banking sector concerns by prohibiting interest payments on stablecoin balances while permitting transaction-based rewards. For developers, it establishes liability based on intent and direct assistance to crime, not for unforeseeable downstream misuse of open-source software. Regarding securities law, the Act introduces a risk-based framework. Assets begin under SEC oversight when a network is centralized, transitioning to CFTC commodity regulation if it becomes sufficiently decentralized, with clear definitions to avoid constant litigation. Without the Act, regulatory uncertainty driven by shifting agency interpretations will persist, discouraging long-term investment in the U.S. and pushing development offshore, reducing American oversight and economic leadership. Support for the bipartisan bill comes from lawmakers, law enforcement (like the Fraternal Order of Police), and major financial institutions. Ultimately, the CLARITY Act is essential to establish a stable, sensible regulatory environment that fosters responsible innovation, enhances consumer protection, and ensures U.S. leadership in shaping the future of financial technology.

marsbitHá 50m

a16z Crypto: Marc Andreessen and Chris Dixon Explain Why the 'CLARITY Act' Is Urgently Needed

marsbitHá 50m

Citi's Interpretation: Why Does Citi Still Give SanDisk a Target Price of $2500 After Earnings Report Despite a Significant Stock Price Drop?

Citi maintains a "Buy" rating on SanDisk with a $2500 price target despite a post-earnings stock drop. This target, implying an 85.1% upside from the August 5th close of $1350.50, hinges on the firm's view that SanDisk merits a higher valuation than traditional NAND cyclical stocks. Although SanDisk reported strong Q4 FY26 results with revenue up 51% sequentially and robust full-year data center growth (+437%), its stock fell sharply on August 6th. Investors are concerned about potential NAND price growth moderation and guidance that failed to meet elevated market expectations. Citi's bullish thesis centers on SanDisk's new long-term "New Business Model" (NBM) agreements. These contracts, covering a significant portion of its NAND bit output for FY27 and FY28, represent minimum revenue commitments of approximately $94 billion backed by financial guarantees. This structure aims to increase revenue and cash flow predictability. The report links this visibility to AI data center demand, driven by the expansion of inference workloads requiring more storage. Citi estimates data center storage capacity demand will grow about 35% in CY27. However, the analysis notes long-term contracts cannot eliminate the NAND cycle. Risks include potential oversupply from industry capacity expansion, competition, and macroeconomic headwinds. The $2500 target essentially bets that AI demand and these contracts can reduce earnings volatility enough to support a premium valuation (~11x CY27E EPS). Key factors to watch are the execution of the $94B commitments, pricing mechanisms, actual data center demand, and industry supply dynamics.

marsbitHá 1h

Citi's Interpretation: Why Does Citi Still Give SanDisk a Target Price of $2500 After Earnings Report Despite a Significant Stock Price Drop?

marsbitHá 1h

Dark Pools Prevail, Whales Vanish: How Credible Are Public Market Signals?

Institutional cryptocurrency trading is increasingly shifting towards dark pools and over-the-counter (OTC) desks, with data from sFOX showing such venues accounted for 15% of total monthly volume by June, up from negligible levels in April. In July, 77.7% of institutional capital on sFOX's platform was routed through OTC desks, while only 18.4% went to public exchanges. A key driver is institutions' need to conceal large orders to avoid revealing trading patterns, preventing front-running and minimizing price impact. Firms like Jane Street and Citadel use dark pools and order-splitting across multiple venues to execute trades discreetly. This structural shift mirrors earlier developments in equities and forex markets. As a result, public order books now reflect only a fraction of actual market activity, eroding the once-significant advantage retail traders had in tracking large wallets and exchange flows. The proliferation of prime brokers and aggregation platforms is also rapidly closing simple arbitrage opportunities. The market may evolve toward a brokerage model for retail, similar to traditional stocks. Two scenarios emerge: an optimistic one where retail gains from narrower spreads and better order routing, and a pessimistic one where transparency declines faster than benefits trickle down, leaving smaller investors in the dark. Regardless, traders must adapt by not relying solely on exchange volume, comparing total execution costs, and using limit orders in thin markets. While reduced volatility from hidden large trades may seem positive, it comes at the cost of obscured market signals and institutional intent.

marsbitHá 1h

Dark Pools Prevail, Whales Vanish: How Credible Are Public Market Signals?

marsbitHá 1h

Trading

Spot
活动图片