Hunter Becomes the Hunted: The Most Profitable MEV Bot Gets Hacked

Odaily星球日报2026-06-21 tarihinde yayınlandı2026-06-21 tarihinde güncellendi

Özet

The prominent Ethereum MEV bot address Jaredfromsubway.eth suffered a targeted on-chain attack, losing over $7.5 million. The incident was identified as a "counter-MEV honeypot attack," where the attacker deployed numerous fake token contracts and liquidity pools over several weeks, mimicking mainstream assets like WETH and USDC to create seemingly profitable arbitrage opportunities. The MEV bot, designed to automatically detect and execute such trades, interacted with the malicious setup. During the process, it granted approvals to attacker-controlled contracts, which were not promptly revoked. The attacker later exploited these persistent permissions in a single transaction, draining the bot's holdings of ETH, USDC, and USDT. Jaredfromsubway.eth is known as one of Ethereum's most active and profitable MEV bots, primarily executing "sandwich attacks" to extract value from user transactions. Its operations have been linked to a majority of such attacks on the network. This event highlights the evolving security threats in crypto, demonstrating that even sophisticated, rule-exploiting systems can become targets of carefully designed behavioral traps. Following the theft, an impersonator account on X falsely claimed to offer a bounty for the return of the funds, prompting warnings from developers.

Original | Odaily Planet Daily (@OdailyChina)

Author | Azuma (@azuma_eth)

The well-known MEV Bot address Jaredfromsubway.eth, long active on the Ethereum network, was targeted in a highly sophisticated on-chain attack on Saturday, resulting in losses exceeding $7.5 million.

According to investigations by Blockaid and several on-chain analytics firms, this incident was not a traditional phishing attack or smart contract exploit. Instead, it was a "counter-MEV honeypot attack" specifically designed to target the operational logic of MEV Bots.

Over the preceding weeks, the attacker had systematically deployed 66 counterfeit token contracts and fake liquidity pools. These assets were meticulously disguised on-chain as mainstream stablecoins like WETH, USDC, and USDT, creating seemingly legitimate arbitrage trading pathways.

The attack chain unfolded step by step — the fake liquidity pools generated signals for "arbitrageable price gaps"; the MEV bot automatically identified the arbitrage opportunity and executed trades; during the transaction, the robot granted authorization to an auxiliary contract controlled by the attacker; this authorization was not promptly revoked, leading to persistent exposure of permissions; Ultimately, in a single transaction, the attacker triggered a pre-embedded backdoor logic, directly draining the ETH, USDC, and USDT held in the MEV bot's address.

On-chain data shows that the total value of assets stolen from Jaredfromsubway.eth in this attack has exceeded $7.5 million. The attacker subsequently split and transferred portions of the funds, further dispersing the flow through mixing tools.

Who is Jaredfromsubway.eth? The Most Notorious MEV Bot Address

The reason this attack is so notable today is that the victim, Jaredfromsubway.eth, is itself one of the most active, profitable, and notorious MEV Bots on the Ethereum network (if not the most).

Essentially, "MEV attacks" are a category of on-chain arbitrage behaviors revolving around "transaction ordering rights." On the Ethereum network, transactions enter the mempool to await block inclusion before being confirmed. Block builders or searchers can extract extra profit by adjusting transaction order, inserting transactions, or rearranging transactions within a block.

The most typical attack type is the "Sandwich Attack" — the attacker inserts buy and sell operations immediately before and after a user's transaction, profiting from the price slippage within a very short time frame. Such behavior is extremely common in high-liquidity DeFi trading pairs and constitutes one of the most fundamental profit models within the MEV ecosystem.

Jaredfromsubway.eth is precisely the most representative automated executor of this mechanism. Unlike traditional "single-point arbitrage bots," this MEV Bot resembles a highly industrialized MEV execution system. It continuously monitors unconfirmed transactions in the mempool, identifies in real-time transaction paths susceptible to being sandwiched, and completes transaction construction, Gas bidding, and order insertion within an extremely short time window, systematically capturing slippage profits.

Data from Cointelegraph Research shows that from November 2024 to October 2025, approximately 60,000 to 90,000 sandwich attacks occurred monthly on the Ethereum network, with about 70% related to the strategic system of Jaredfromsubway.eth.

In May of this year, when Ethereum co-founder Vitalik Buterin exchanged 26,544 DigitalBits (XDB), his transaction was also targeted and sandwiched by Jaredfromsubway.eth.

Regarding Jaredfromsubway.eth's historical revenue, there is no official statistic, but conservative estimates suggest that the address has accumulated MEV profits reaching tens of millions of dollars during its active periods. During some peak periods, its daily earnings could reach hundreds of thousands of dollars, and it consistently ranked near the top of Ethereum's MEV leaderboards.

Crypto Security Threats Intensify: Even Top Predators Are Not Spared

While one might muse that "the eagle-hunter finally got pecked," the hacking of Jaredfromsubway.eth has also sounded another alarm regarding risks in the cryptocurrency space.

In past perceptions, MEV Bots like Jaredfromsubway.eth belonged to the "predator" side of the on-chain ecosystem — they continuously capture slippage and arbitrage opportunities within user transactions through automated strategies, positioning themselves advantageously, arguably representing one of the most iconic types of attackers in the cryptocurrency market.

But this time, it became the one that was designed, lured, and ultimately harvested. Moreover, the attacker did not choose a traditional exploit path. Instead, they constructed a long-running "behavioral trap," allowing the MEV Bot's automated system to make progressively flawed decisions while fully complying with its own rules.

It must be acknowledged that even participants like Jaredfromsubway.eth, once most adept at "gaming the system," are now exposed to a broader attack surface.

Additionally, it is worth noting that after Jaredfromsubway.eth was hacked, an unknown X account with 94,000 followers changed its name to Jaredfromsubway.eth and falsely claimed it would "offer a $1 million bounty for the full return of all funds."

Several developers issued risk warnings, emphasizing that this account is not the official Jaredfromsubway.eth account (the MEV Bot team has no official account). They cautioned that this account might be used for scams subsequently and urged users to remain highly vigilant.

İlgili Sorular

QWhat type of attack did the MEV bot Jaredfromsubway.eth fall victim to, according to the article?

AThe article states that the MEV bot Jaredfromsubway.eth was targeted by a 'counter-MEV honeypot attack.' This was not a traditional phishing or smart contract exploit, but a sophisticated attack specifically designed to exploit the MEV bot's behavioral logic.

QWhat was the estimated total loss suffered by Jaredfromsubway.eth in this incident?

AAccording to on-chain data cited in the article, the total value of assets stolen from Jaredfromsubway.eth exceeded 7.5 million US dollars.

QAccording to the article, what is a 'Sandwich Attack' in the context of MEV?

AA 'Sandwich Attack' is described as a typical type of MEV attack. In this strategy, the attacker inserts buy and sell orders before and after a target user's transaction, respectively, to profit from the price slippage within a very short time window.

QWhat significant event involving Vitalik Buterin is mentioned in relation to Jaredfromsubway.eth?

AThe article mentions that in May of this year (presumably 2025), Ethereum co-founder Vitalik Buterin was targeted by Jaredfromsubway.eth when exchanging 26,544 DigitalBits (XDB) tokens.

QFollowing the hack, what fake action was taken by an unknown X account, and what warning was given?

AAn unknown X account with 94,000 followers changed its name to Jaredfromsubway.eth and falsely announced a '1 million US dollar bounty for the full return of all funds.' Developers issued warnings that this is not the official account (as the MEV bot team has none) and cautioned users to remain vigilant as the account might be used for scams.

İlgili Okumalar

Base Under Pressure

**Title: The Pressure Mounts for Base** Base, the Ethereum Layer 2 scaling solution backed by Coinbase, is facing significant pressure and public scrutiny from its leadership following the launch of Robinhood Chain. Base co-founder Jesse Pollak recently acknowledged strategic missteps, admitting that the chain's past focus on social and creator tokens (e.g., through Farcaster, Zora) failed to deliver sustainable adoption. He has refocused on core infrastructure, handing leadership of the Base App back to Coinbase's Cobie. While Base remains a top L2 contender alongside OP Mainnet and Arbitrum, and boasts the highest TVL (nearly $12B), its weaknesses are being highlighted by the new competitor. Key criticisms include its slow progress on decentralization. Base has faced issues with its single sequencer causing block production halts, and L2BEAT is reportedly considering downgrading its decentralization rating from Stage 1 to Stage 0. This contrasts sharply with the rapid initial success of Robinhood Chain, whose DEX quickly entered the top five by volume. The leadership styles of the parent companies are also being compared: Robinhood's CEO actively engages with new projects, while a recent incident where Coinbase's Brian Armstrong briefly changed his profile picture—sparking and then crashing a related meme token—drew community ire and mockery. Pollak stated Base is working with Coinbase on tokenized stocks backed 1:1 by real equity, differentiating it from Robinhood's derivatives model. However, the article argues that Base's most urgent task is to address its long-standing technical and trust issues. With more traditional finance players likely to emulate Robinhood's path, Base must use this competitive pressure to solidify its position as long-term financial infrastructure.

Foresight News7 dk önce

Base Under Pressure

Foresight News7 dk önce

White House Concession Removes Ethical Hurdle, Clarity Act Races Against Final Window Before Recess?

On July 21st, industry sources reported that the Trump administration has agreed to include an ethics provision in the "Clarity Act" (Digital Asset Market Clarity Act of 2025). This concession addresses the long-standing conflict-of-interest concerns regarding government officials and the crypto industry, potentially removing the final major obstacle to the bill's progress. Additionally, Patrick Witt, the executive director of the White House's Digital Asset Advisory Committee, confirmed he will remain in his role to help finalize the bill, alleviating previous concerns about his potential departure. The Clarity Act aims to establish a unified federal regulatory framework for the U.S. digital asset market. Its core objective is to resolve regulatory ambiguity by defining different types of digital assets (digital commodities, investment contract assets, and permitted payment stablecoins) and clarifying the respective oversight roles of the SEC and CFTC. This would end the long-running jurisdictional dispute between the two agencies and provide clearer compliance paths for the industry. With the ethics issue moving toward resolution, the most urgent challenge now is time. The U.S. Congress is set to begin its August recess in mid-August, leaving only a few working weeks to finalize the text and advance the bill through the Senate. Industry advocates, like the Blockchain Association's Kristin Smith, stress that this is a critical moment. If negotiations conclude successfully in the coming weeks, the Clarity Act could pass a key hurdle before the recess; otherwise, it may face significant delays. If enacted, the Clarity Act could mark a historic turning point in crypto regulation. By providing a clearer and more predictable legal framework, it aims to reduce uncertainty for businesses, developers, and traditional financial institutions looking to enter the digital asset space, potentially setting a global benchmark for market structure regulation.

Odaily星球日报12 dk önce

White House Concession Removes Ethical Hurdle, Clarity Act Races Against Final Window Before Recess?

Odaily星球日报12 dk önce

AI Era, Industrial Revolution, and Future Civilization Interview — Zhang Dingwen: The Future Does Not Belong to Chasers

"AI Era, Industrial Revolution and Future Civilization: An Interview with Zhang Dingwen – The Future Does Not Belong to Those Who Chase" In this interview, entrepreneur Zhang Dingwen reflects on his entrepreneurial journey and philosophy, moving beyond discussions of financing or success to emphasize understanding the "era" itself. He argues that true entrepreneurs should not chase short-term trends ("winds"), but position themselves in the direction of long-term technological and societal evolution. Zhang shares key lessons from his early days, including the realization that user value does not automatically translate to commercial value. For him, the core of entrepreneurship is not building a company but constantly upgrading one's own "cognition" – the ability to interpret information, ask the right questions, and understand the underlying "causes" behind business outcomes, not just the effects. His thinking has evolved from a focus on creating good products to a strategic focus on building "entrances" – platforms that naturally connect users to digital services. He sees smart wearables, like watches, not merely as hardware but as potential future gateways combining technological, financial, social, and even fashion attributes to create sustained user relationships and ecosystems. Ultimately, Zhang's vision transcends individual products or companies. He discusses business competition in three stages: product, platform, and finally, "civilization" – where the greatest companies influence how society operates by defining new rules and ways of life. He believes the mission of a truly great enterprise is to solve problems of its time, build enduring trust, and contribute lasting value, leaving behind not just wealth but a positive impact on how the world works. The future, he concludes, belongs not to the fastest, but to those with the correct long-term direction and a commitment to continuous learning and evolution.

marsbit24 dk önce

AI Era, Industrial Revolution, and Future Civilization Interview — Zhang Dingwen: The Future Does Not Belong to Chasers

marsbit24 dk önce

Cryptocurrency & Stock Market Barometer丨Strategy Cash Reserves Increase to $3.23 Billion, Halting BTC Purchases; Vanguard and Other Asset Managers Increase Holdings in Strategy Stock (July 21)

Market Overview & Warnings: The article warns of high volatility in South Korean stocks and continued dependence on U.S. stocks on geopolitics. Chinese A-shares remain under pressure. It advises against using leverage in current equity markets. For crypto-linked stocks, most have limited growth except Robinhood, with caution advised. U.S. Stock Market: Bearish bets on U.S. stocks, particularly targeting AI-related companies, have reached record highs since 2010, signaling deep skepticism about the sustainability of the AI-driven rally. Tech and chip stocks led a market decline, with the Philadelphia Semiconductor Index potentially entering a bear market. Increased expectations for Federal Reserve interest rate hikes and geopolitical tensions contributed to the negative sentiment. Bitcoin Treasury Company Updates: * Strategy: Increased its cash reserves to $3.23 billion and paused Bitcoin purchases. Several major asset managers, including Vanguard Group and Capital Group, increased their holdings of Strategy (MSTR) stock. * Global corporate Bitcoin buying slowed significantly to just $1.33 million last week. * Other notable activity: Strive purchased 21 BTC; ORANGE JUICE raised $40 million for Bitcoin acquisitions; Bitcoin Japan Corp. raised $60 million, allocating $4.08 million for its first BTC purchase. Other Crypto Treasury Holdings: * Ethereum: BitMine increased its ETH holdings to 5.78 million, nearing its 5% of supply goal. Its total crypto assets, cash, and securities are valued at $11.5 billion. * Solana: No significant corporate treasury activity reported. * Altcoins: HypeStrat made no adjustments to its treasury; its mNAV ratio fell to a long-term low. (Note: This summary is for informational purposes only and does not constitute investment advice.)

marsbit24 dk önce

Cryptocurrency & Stock Market Barometer丨Strategy Cash Reserves Increase to $3.23 Billion, Halting BTC Purchases; Vanguard and Other Asset Managers Increase Holdings in Strategy Stock (July 21)

marsbit24 dk önce

İşlemler

Spot
活动图片