The Hunter Becomes the Hunted: The Most Profitable MEV Bot Gets Hacked

marsbitОпубликовано 2026-06-21Обновлено 2026-06-21

Введение

A well-known and highly profitable Ethereum MEV Bot, Jaredfromsubway.eth, suffered a sophisticated on-chain attack this Saturday, losing over $7.5 million. Analysis by Blockaid and others reveals this was not a conventional phishing or smart contract exploit, but a targeted "counter-MEV honeypot attack." The attacker meticulously laid a trap over several weeks, deploying 66 fake token contracts and liquidity pools disguised as major assets like WETH and USDC. These pools created the illusion of arbitrage opportunities. The MEV Bot's automated system detected these signals, executed trades, and in the process, granted approval permissions to attacker-controlled contracts. These approvals were not revoked, creating a persistent vulnerability. The attacker then exploited this in a single transaction, draining the bot's ETH, USDC, and USDT holdings. Jaredfromsubway.eth is notorious as one of Ethereum's most active and profitable MEV Bots, primarily known for executing "sandwich attacks" to profit from transaction slippage. Estimates suggest it has earned tens of millions in MEV revenue. The incident highlights escalating crypto security threats, demonstrating that even top-tier automated "predators" are vulnerable to novel, logic-based attacks designed to exploit their own operational rules. Following the hack, an unverified X account impersonating Jaredfromsubway.eth emerged, falsely offering a bounty for the return of funds, prompting developer warnings for users to stay vig...

By Azuma(@azuma_eth)

Jaredfromsubway.eth, a well-known MEV Bot address long active on the Ethereum network, was targeted in a highly specific on-chain attack on Saturday, resulting in losses exceeding $7.5 million.

Investigations by Blockaid and several on-chain analytics firms revealed that this incident was not a traditional phishing attack or smart contract exploit, but rather a "counter-MEV honeypot attack" specifically designed to exploit the operational logic of MEV Bots.

Over the preceding weeks, the attacker systematically deployed 66 counterfeit token contracts and fake liquidity pools. These assets were meticulously disguised on-chain as major stable assets like WETH, USDC, and USDT, creating seemingly genuine arbitrage trading pathways.

The attack chain unfolded as follows — fake liquidity pools generated signals of "exploitable price gaps"; the MEV bot automatically identified the arbitrage opportunity and executed a trade; during the transaction, the robot granted authorization to an auxiliary contract controlled by the attacker; this authorization was not revoked promptly, leading to persistent exposure of permissions; finally, the attacker triggered a pre-embedded backdoor logic in a single transaction, directly transferring assets such as ETH, USDC, and USDT held by the MEV bot's address.

On-chain data shows that the total scale of assets stolen from Jaredfromsubway.eth this time has exceeded $7.5 million. The attacker subsequently split and transferred some of the assets, further dispersing the fund flow through mixing tools.

Who is Jaredfromsubway.eth? The Most Notorious MEV Bot Address

The reason this attack is so notable now is that the victim, Jaredfromsubway.eth, is itself the most active, most profitable, and most notorious MEV Bot on the Ethereum network (perhaps without even needing 'one of').

"MEV attacks" are essentially a category of on-chain arbitrage behaviors centered around "transaction ordering rights." In the Ethereum network, transactions wait in the mempool to be included in a block before they are confirmed. Block builders or searchers can adjust transaction order, insert transactions, or rearrange transactions within a block to extract additional profits.

The most typical attack type is the "Sandwich Attack"— the attacker inserts a buy order before and a sell order after a user's transaction, profiting from price slippage within a short timeframe. This behavior is extremely common in high-liquidity DeFi trading pairs and constitutes one of the most fundamental profit models within the MEV ecosystem.

Jaredfromsubway.eth is precisely the most representative automated executor of this mechanism. Unlike traditional "single-point arbitrage bots," this MEV Bot operates more like a highly industrialized MEV execution system. It continuously monitors unconfirmed transactions in the mempool, identifies in real-time transaction paths vulnerable to sandwiching, and within an extremely short time window, completes transaction construction, gas bidding, and order insertion, systematically capturing slippage profits.

Data from Cointelegraph Research shows that between November 2024 and October 2025, approximately 60,000 to 90,000 sandwich attacks occurred monthly on the Ethereum network, with about 70% related to Jaredfromsubway.eth's strategy system.

In May this year, when Ethereum co-founder Vitalik Buterin exchanged 26,544 DigitalBits (XDB), his transaction was also precisely targeted and sandwiched by Jaredfromsubway.eth.

There is no official statistic on Jaredfromsubway.eth's historical revenue, but conservative estimates suggest that the address has accumulated tens of millions of dollars in MEV profits during its active periods. During some peak periods, its single-day profits could reach hundreds of thousands of dollars, and it consistently appeared at the top of Ethereum MEV rankings for a long time.

Crypto Security Threats Escalate: Even Top Predators Are Not Safe

While some may marvel at the "hunter finally getting hunted," the hacking of Jaredfromsubway.eth also rings an alarm bell for cryptocurrency risks once again.

In past perceptions, MEV Bots like Jaredfromsubway.eth belonged to the "predator" side of the on-chain ecosystem — they continuously capture slippage and arbitrage opportunities in user transactions through automated strategies, inherently occupying an advantageous position, and could even be considered a representative class of attackers in the crypto market.

But this time, it became the target of design, inducement, and eventual harvesting. Moreover, the attacker did not choose a traditional vulnerability exploitation path. Instead, they constructed a long-running "behavioral trap," allowing the MEV Bot's automated system to proceed step by step towards erroneous decisions while fully complying with its own rules.

It must be admitted that even participants like Jaredfromsubway.eth, who were once most adept at "exploiting the rules," are now exposed to more multidimensional attack surfaces.

It is also worth noting that after the Jaredfromsubway.eth hack, an unknown account on X with 94,000 followers changed its name to Jaredfromsubway.eth and falsely claimed it would "offer a $1 million bounty for the full return of all funds."

Several developers issued risk warnings regarding this, emphasizing that the account is not an official Jaredfromsubway.eth account (the MEV Bot team has no official account) and that it cannot be ruled out that this account might be used for scams in the future. Users are urged to remain highly vigilant.

Связанные с этим вопросы

QWhat type of attack was the Jaredfromsubway.eth MEV bot a victim of?

AIt was a victim of a 'counter-MEV honeypot attack', a targeted attack designed to exploit the behavioral logic of MEV bots, not a traditional phishing or smart contract exploit.

QWho is Jaredfromsubway.eth and what is it known for in the Ethereum ecosystem?

AJaredfromsubway.eth is one of the most active, profitable, and notorious MEV bots on the Ethereum network. It is particularly known for executing 'sandwich attacks' to capture slippage profits from user transactions.

QWhat was the estimated total loss for Jaredfromsubway.eth in this attack?

AThe estimated total loss for Jaredfromsubway.eth in this attack was over $7.5 million in assets like ETH, USDC, and USDT.

QWhat specific attack method was used to set up the trap for the MEV bot?

AThe attackers deployed 66 fake token contracts and fake liquidity pools over several weeks. These mimicked mainstream assets like WETH, USDC, and USDT to create seemingly profitable arbitrage opportunities, ultimately tricking the bot into granting permissions that were later exploited.

QWhat did the impersonator account on X (formerly Twitter) falsely claim after the attack?

AAn impersonator account on X, with the name changed to Jaredfromsubway.eth, falsely claimed it would offer a '$1 million bounty for the full return of all funds'.

Похожее

Strategy привлекла $730 млн за 2 недели и купила 0 биткойнов – рынок спрашивает, почему

Компания Strategy привлекла 730 миллионов долларов за две недели, но не купила ни одного биткойна, увеличив свои денежные резервы до 3,2 миллиарда долларов. Это отступление от привычной стратегии компании, которая годами привлекала капитал для немедленной покупки BTC. Рынок задается вопросом о причинах такого шага. Одна из версий — компания укрепляет баланс и ликвидность, поскольку ее индекс STRC торгуется ниже ключевого уровня в 100 долларов, что ограничивает возможности для привлечения нового капитала через программу ATM для покупки биткойнов. Некоторые инвесторы рассматривают это как стратегическую паузу в ожидании лучших условий, в то время как другие выражают озабоченность в связи с размыванием доли акционеров при отсутствии наращивания стека BTC. Данное решение усиливает неопределенность вокруг будущих действий Strategy в условиях доминирующих настроений избегания риска на рынке.

ambcrypto18 мин. назад

Strategy привлекла $730 млн за 2 недели и купила 0 биткойнов – рынок спрашивает, почему

ambcrypto18 мин. назад

Американский банк незаметно готовится: $6 трлн банковских вкладов могут уйти в стейблкоины?

В статье обсуждаются недавние кадровые перестановки в Bank of America, направленные на развитие цифровых активов, включая стейблкоины, токенизированные депозиты и услуги кастоди. Эти шаги вызвали обсуждение в криптосообществе, особенно на фоне заявления гендиректора банка о потенциальном перемещении до $6 трлн банковских депозитов в стейблкоины — при условии, что последним будет разрешено выплачивать проценты. Этот прогноз основан на более раннем отчете Казначейства США. Несмотря на задержки в окончательном утверждении правил закона GENIUS Act (сейчас крайний срок — 18 января 2027 года), крупные банки, такие как JPMorgan Chase и Citigroup, уже активно внедряют связанные с токенизацией решения. По данным аналитиков, объем расчетов в стейблкоинах в 2025 году достиг $33 трлн. Однако некоторые эксперты скептически относятся к значимости этих назначений, отмечая, что банки давно анонсируют блокчейн-проекты, а рынок стейблкоинов в последнее время демонстрирует спад. Тем не менее, оптимисты прогнозируют рост рынка стейблкоинов до более $1 трлн к концу 2026 года. Действия Bank of America рассматриваются как часть более широкой тенденции слияния традиционных финансов и криптоиндустрии, где ключевые изменения ожидаются после вступления закона GENIUS Act в силу.

Foresight News19 мин. назад

Американский банк незаметно готовится: $6 трлн банковских вкладов могут уйти в стейблкоины?

Foresight News19 мин. назад

Министр финансов США Бенсонт заявил, что США скоро будут контролировать 80% вычислительной мощности в мире

Министр финансов США Джанет Йеллен заявила, что Соединенные Штаты вскоре будут контролировать 80% мировых вычислительных мощностей, назвав это ключевым столпом экономической стратегии страны. По ее словам, в настоящее время на США приходится около 50-60% мировых мощностей, и этот показатель скоро вырастет. Она охарактеризовала гонку вычислений как стратегическую игру, которую США «не могут проиграть», поскольку лидерство соперников даст им «неприемлемые» стратегические преимущества. Йеллен отнесла ИИ, полупроводники и квантовые вычисления к трем основным компонентам национальной экономической мощи и безопасности. Она утверждает, что ИИ создаст больше возможностей и позволит малым компаниям конкурировать с крупными, не приводя к чистым потерям рабочих мест. Это заявление рассматривается как сильная политическая поддержка для долгосрочных капиталовложений в инфраструктуру ИИ в США, что благоприятно для таких компаний, как NVIDIA, и крупных облачных провайдеров. Однако аналитики призывают к осторожности, отмечая, что показатель в 80% является прогнозом, а не проверенными данными. Ключевыми для проверки этого прогноза будут фактические данные о расширении производственных мощностей, энергетической инфраструктуре и отчеты отраслевых исследователей.

marsbit31 мин. назад

Министр финансов США Бенсонт заявил, что США скоро будут контролировать 80% вычислительной мощности в мире

marsbit31 мин. назад

Matrixdock два года подряд проходит независимую проверку резервов, продолжая совершенствовать систему прозрачности резервов

Недавно платформа токенизации RWA Matrixdock, входящая в состав BIT (бывший Matrixport), завершила свой четвертый последовательный полугодовой независимый аудит резервов. Проверку, как и в прошлый раз, провела международная инспекционно-сертификационная компания Bureau Veritas, расширив аудиторский охват, включив в него продукт токенизированного серебра XAGm. Этот аудит подтверждает соответствие физических запасов золота и серебра, лежащих в основе XAUm и XAGm, данным в записях. Проверка охватила 574 слитка из аффинажных заводов, сертифицированных LBMA, хранящихся в трех институциональных хранилищах: Malca-Amit Singapore, Brink's Hong Kong и Brink's Singapore. По состоянию на дату аудита резервы XAUm (16 331,179 унций золота) и XAGm (65 934 унции серебра) полностью соответствовали количеству токенов в обращении. Matrixdock проводит независимую проверку резервов дважды в год в течение двух лет подряд с помощью одного и того же аудитора, что создает стабильную и последовательную систему. Компания называет этот подход «резервной прозрачностью» (Reserve Transparency Stack). Помимо регулярных аудитов, платформа ежемесячно публикует отчеты о резервах, предоставляет доказательства резервов в блокчейне (Proof of Reserves) и инструмент для проверки привязки токенов к конкретным слиткам (Gold Allocation Lookup). Такая постоянная проверяемость базовых активов формирует основу для интеграции токенизированных активов в более широкие финансовые сценарии, такие как управление капиталом и кредитование. Непрерывная верификация становится ключевым элементом инфраструктуры цепочки поставок в цифровых финансах.

marsbit42 мин. назад

Matrixdock два года подряд проходит независимую проверку резервов, продолжая совершенствовать систему прозрачности резервов

marsbit42 мин. назад

Hyperliquid открывает развертывание рынков предсказаний: стейкинг токенов HYPE на $30 млн с возможностью получать до 50% комиссий

Hyperliquid открывает развертывание прогнозных рынков для всех: стейкинг на $30 млн в токенах HYPE с возможностью получения до 50% комиссий. После обновления HIP-4, которое ввело на платформе функции торговли на исход событий, Hyperliquid планирует позволить любому пользователю запускать собственные прогнозные рынки. В настоящее время такие рынки контролируются валидаторами, но в будущем их количество сократится до менее 10 в год, а остальные станут общедоступными. Для запуска рынка необходимо застейкать 500 000 токенов HYPE (около $30 млн). Эти средства выступают гарантией и могут быть изъяты, если валидаторы сочтут определение рынка неясным или его расчеты ошибочными. Взамен создатель рынка может получать до 50% торговых комиссий с него. Эта модель, аналогичная используемой для бессрочных контрактов, кардинально отличается от централизованного подхода таких платформ, как Polymarket и Kalshi. Этот шаг следует за рекордным летом для индустрии прогнозных рынков, объем торгов которой достиг $50 млрд в июне, в основном благодаря ставкам на Чемпионат мира. Несмотря на то, что доля Hyperliquid пока невелика ($176 млн), платформа, уже демонстрирующая рекордные объемы на DEX, надеется за счет децентрализованной модели занять более существенную позицию в этом растущем сегменте.

marsbit44 мин. назад

Hyperliquid открывает развертывание рынков предсказаний: стейкинг токенов HYPE на $30 млн с возможностью получать до 50% комиссий

marsbit44 мин. назад

Торговля

Спот
活动图片