# Пов'язані статті щодо Bot

Центр новин HTX надає останні статті та поглиблений аналіз на тему "Bot", що охоплює ринкові тренди, оновлення проєктів, технологічні розробки та регуляторну політику в криптоіндустрії.

Top-Tier MEV Bot Loses $7.5 Million: Is 'Approval' the Most Overlooked Fatal Risk On-Chain?

The article discusses a sophisticated attack on a prominent Ethereum MEV (Miner Extractable Value) bot, Jaredfromsubway.eth, resulting in a loss exceeding $7.5 million. Unlike typical exploits involving key leaks or smart contract bugs, this attack was a carefully orchestrated "reverse hunt." The attacker spent weeks deploying fake tokens and liquidity pools that mimicked legitimate assets like WETH and USDC. These pools were designed to appear as profitable arbitrage opportunities, tricking the automated bot's trading logic. During its normal operation, the bot was induced to grant ERC-20 token approvals to the malicious contracts. Once sufficient permissions were accumulated, the attacker drained the bot's funds by calling these pre-approved allowances. This incident highlights the often-underestimated risks associated with token approvals in Web3. The article explains that approvals are a fundamental mechanism, allowing smart contracts (like DEXs) to move a user's tokens on their behalf. However, risks arise from practices like granting infinite approvals, the persistence of approvals even after disconnecting from a dApp, and the potential for a once-trusted contract to become compromised later. The piece concludes with advice for managing approval risks: users should adopt the principle of least privilege (approving only the needed amount), use separate wallets for storage versus interactions, and regularly audit and revoke unnecessary approvals using tools like Revoke.cash. It also emphasizes the role of wallets like imToken in providing proactive defenses, such as risk warnings and clear, readable transaction signing interfaces, to help users make informed decisions. Ultimately, wallet security must extend beyond private key protection to include active management of token approvals.

marsbit06/24 05:28

Top-Tier MEV Bot Loses $7.5 Million: Is 'Approval' the Most Overlooked Fatal Risk On-Chain?

marsbit06/24 05:28

The Hunter Becomes the Hunted: The Most Profitable MEV Bot Gets Hacked

A well-known and highly profitable Ethereum MEV Bot, Jaredfromsubway.eth, suffered a sophisticated on-chain attack this Saturday, losing over $7.5 million. Analysis by Blockaid and others reveals this was not a conventional phishing or smart contract exploit, but a targeted "counter-MEV honeypot attack." The attacker meticulously laid a trap over several weeks, deploying 66 fake token contracts and liquidity pools disguised as major assets like WETH and USDC. These pools created the illusion of arbitrage opportunities. The MEV Bot's automated system detected these signals, executed trades, and in the process, granted approval permissions to attacker-controlled contracts. These approvals were not revoked, creating a persistent vulnerability. The attacker then exploited this in a single transaction, draining the bot's ETH, USDC, and USDT holdings. Jaredfromsubway.eth is notorious as one of Ethereum's most active and profitable MEV Bots, primarily known for executing "sandwich attacks" to profit from transaction slippage. Estimates suggest it has earned tens of millions in MEV revenue. The incident highlights escalating crypto security threats, demonstrating that even top-tier automated "predators" are vulnerable to novel, logic-based attacks designed to exploit their own operational rules. Following the hack, an unverified X account impersonating Jaredfromsubway.eth emerged, falsely offering a bounty for the return of funds, prompting developer warnings for users to stay vigilant.

marsbit06/21 09:22

The Hunter Becomes the Hunted: The Most Profitable MEV Bot Gets Hacked

marsbit06/21 09:22

When Depth Becomes an Illusion: Polymarket Faces 'Order Attack' Stress Test

A sophisticated "order attack" is exploiting a critical vulnerability in Polymarket's hybrid off-chain matching/on-chain settlement system. For less than $0.10 in gas fees on Polygon, an attacker can initiate a trade and then, in the brief window before on-chain execution, drain their wallet via a high-gas transfer. This causes the initial trade to fail on-chain due to insufficient funds. However, Polymarket's off-chain system responds by forcibly removing all the legitimate market maker orders that were matched with the failed transaction. This attack has two primary profit methods. First, attackers clear the order book of competitors, create a liquidity vacuum, and then place their own orders with artificially wide spreads to monopolize trading. Second, they "hunt" automated trading bots: after a trade is matched off-chain, a bot hedges its new position, but the attacker then forces the original trade to fail on-chain. This leaves the bot with an unhedged, risky position, which the attacker exploits for profit. One identified attacker address, created in February 2026, reportedly profited over $16,000 in a single day by targeting just 7 markets. The attack severely undermines market maker confidence, threatens the platform's liquidity, and exposes a fundamental design flaw. While the community has developed monitoring tools, Polymarket team has not yet issued an official fix.

比推02/26 04:52

When Depth Becomes an Illusion: Polymarket Faces 'Order Attack' Stress Test

比推02/26 04:52

High-Frequency Trading, $100K Annual Income: The Most 'Boring' Profit Myth on Polymarket

A user known as planktonXD (0x4ffe49ba2a4cae123536a8af4fda48faeb609f71) has generated over $106,000 in profit on Polymarket within a year by executing more than 61,000 predictions—averaging around 170 trades per day. This high-frequency, automated strategy focuses on exploiting small, certain opportunities rather than betting on high-risk, high-reward outcomes. The approach is characterized by market-making and micro-arbitrage: placing orders on both sides of the order book to capture spreads or profiting from mispriced options in low-liquidity markets. The largest single win was only $2,527, illustrating a disciplined, risk-managed method that avoids large drawdowns. The bot operates across diverse categories—sports, weather, crypto prices, politics—constantly scanning for pricing inefficiencies. Notable examples include buying heavily undervalued options in niche markets, such as esports matches or extreme crypto price movements, where probability is mispriced due to emotional trading or thin order books. For instance, a $16 bet on SOL falling to $130 (priced at 0.7¢, implying <1% chance) returned $1,574 during a volatile period. Key takeaways: The strategy highlights the power of compounding small gains, the necessity of automation and API tools, and the superiority of high-probability opportunities over high-risk bets. In prediction markets, the most advanced approach isn’t forecasting—it’s managing probability and liquidity.

marsbit02/11 13:06

High-Frequency Trading, $100K Annual Income: The Most 'Boring' Profit Myth on Polymarket

marsbit02/11 13:06

活动图片