The Hunter Becomes the Hunted: The Most Profitable MEV Bot Gets Hacked

marsbitОпубліковано о 2026-06-21Востаннє оновлено о 2026-06-21

Анотація

A well-known and highly profitable Ethereum MEV Bot, Jaredfromsubway.eth, suffered a sophisticated on-chain attack this Saturday, losing over $7.5 million. Analysis by Blockaid and others reveals this was not a conventional phishing or smart contract exploit, but a targeted "counter-MEV honeypot attack." The attacker meticulously laid a trap over several weeks, deploying 66 fake token contracts and liquidity pools disguised as major assets like WETH and USDC. These pools created the illusion of arbitrage opportunities. The MEV Bot's automated system detected these signals, executed trades, and in the process, granted approval permissions to attacker-controlled contracts. These approvals were not revoked, creating a persistent vulnerability. The attacker then exploited this in a single transaction, draining the bot's ETH, USDC, and USDT holdings. Jaredfromsubway.eth is notorious as one of Ethereum's most active and profitable MEV Bots, primarily known for executing "sandwich attacks" to profit from transaction slippage. Estimates suggest it has earned tens of millions in MEV revenue. The incident highlights escalating crypto security threats, demonstrating that even top-tier automated "predators" are vulnerable to novel, logic-based attacks designed to exploit their own operational rules. Following the hack, an unverified X account impersonating Jaredfromsubway.eth emerged, falsely offering a bounty for the return of funds, prompting developer warnings for users to stay vig...

By Azuma(@azuma_eth)

Jaredfromsubway.eth, a well-known MEV Bot address long active on the Ethereum network, was targeted in a highly specific on-chain attack on Saturday, resulting in losses exceeding $7.5 million.

Investigations by Blockaid and several on-chain analytics firms revealed that this incident was not a traditional phishing attack or smart contract exploit, but rather a "counter-MEV honeypot attack" specifically designed to exploit the operational logic of MEV Bots.

Over the preceding weeks, the attacker systematically deployed 66 counterfeit token contracts and fake liquidity pools. These assets were meticulously disguised on-chain as major stable assets like WETH, USDC, and USDT, creating seemingly genuine arbitrage trading pathways.

The attack chain unfolded as follows — fake liquidity pools generated signals of "exploitable price gaps"; the MEV bot automatically identified the arbitrage opportunity and executed a trade; during the transaction, the robot granted authorization to an auxiliary contract controlled by the attacker; this authorization was not revoked promptly, leading to persistent exposure of permissions; finally, the attacker triggered a pre-embedded backdoor logic in a single transaction, directly transferring assets such as ETH, USDC, and USDT held by the MEV bot's address.

On-chain data shows that the total scale of assets stolen from Jaredfromsubway.eth this time has exceeded $7.5 million. The attacker subsequently split and transferred some of the assets, further dispersing the fund flow through mixing tools.

Who is Jaredfromsubway.eth? The Most Notorious MEV Bot Address

The reason this attack is so notable now is that the victim, Jaredfromsubway.eth, is itself the most active, most profitable, and most notorious MEV Bot on the Ethereum network (perhaps without even needing 'one of').

"MEV attacks" are essentially a category of on-chain arbitrage behaviors centered around "transaction ordering rights." In the Ethereum network, transactions wait in the mempool to be included in a block before they are confirmed. Block builders or searchers can adjust transaction order, insert transactions, or rearrange transactions within a block to extract additional profits.

The most typical attack type is the "Sandwich Attack"— the attacker inserts a buy order before and a sell order after a user's transaction, profiting from price slippage within a short timeframe. This behavior is extremely common in high-liquidity DeFi trading pairs and constitutes one of the most fundamental profit models within the MEV ecosystem.

Jaredfromsubway.eth is precisely the most representative automated executor of this mechanism. Unlike traditional "single-point arbitrage bots," this MEV Bot operates more like a highly industrialized MEV execution system. It continuously monitors unconfirmed transactions in the mempool, identifies in real-time transaction paths vulnerable to sandwiching, and within an extremely short time window, completes transaction construction, gas bidding, and order insertion, systematically capturing slippage profits.

Data from Cointelegraph Research shows that between November 2024 and October 2025, approximately 60,000 to 90,000 sandwich attacks occurred monthly on the Ethereum network, with about 70% related to Jaredfromsubway.eth's strategy system.

In May this year, when Ethereum co-founder Vitalik Buterin exchanged 26,544 DigitalBits (XDB), his transaction was also precisely targeted and sandwiched by Jaredfromsubway.eth.

There is no official statistic on Jaredfromsubway.eth's historical revenue, but conservative estimates suggest that the address has accumulated tens of millions of dollars in MEV profits during its active periods. During some peak periods, its single-day profits could reach hundreds of thousands of dollars, and it consistently appeared at the top of Ethereum MEV rankings for a long time.

Crypto Security Threats Escalate: Even Top Predators Are Not Safe

While some may marvel at the "hunter finally getting hunted," the hacking of Jaredfromsubway.eth also rings an alarm bell for cryptocurrency risks once again.

In past perceptions, MEV Bots like Jaredfromsubway.eth belonged to the "predator" side of the on-chain ecosystem — they continuously capture slippage and arbitrage opportunities in user transactions through automated strategies, inherently occupying an advantageous position, and could even be considered a representative class of attackers in the crypto market.

But this time, it became the target of design, inducement, and eventual harvesting. Moreover, the attacker did not choose a traditional vulnerability exploitation path. Instead, they constructed a long-running "behavioral trap," allowing the MEV Bot's automated system to proceed step by step towards erroneous decisions while fully complying with its own rules.

It must be admitted that even participants like Jaredfromsubway.eth, who were once most adept at "exploiting the rules," are now exposed to more multidimensional attack surfaces.

It is also worth noting that after the Jaredfromsubway.eth hack, an unknown account on X with 94,000 followers changed its name to Jaredfromsubway.eth and falsely claimed it would "offer a $1 million bounty for the full return of all funds."

Several developers issued risk warnings regarding this, emphasizing that the account is not an official Jaredfromsubway.eth account (the MEV Bot team has no official account) and that it cannot be ruled out that this account might be used for scams in the future. Users are urged to remain highly vigilant.

Пов'язані питання

QWhat type of attack was the Jaredfromsubway.eth MEV bot a victim of?

AIt was a victim of a 'counter-MEV honeypot attack', a targeted attack designed to exploit the behavioral logic of MEV bots, not a traditional phishing or smart contract exploit.

QWho is Jaredfromsubway.eth and what is it known for in the Ethereum ecosystem?

AJaredfromsubway.eth is one of the most active, profitable, and notorious MEV bots on the Ethereum network. It is particularly known for executing 'sandwich attacks' to capture slippage profits from user transactions.

QWhat was the estimated total loss for Jaredfromsubway.eth in this attack?

AThe estimated total loss for Jaredfromsubway.eth in this attack was over $7.5 million in assets like ETH, USDC, and USDT.

QWhat specific attack method was used to set up the trap for the MEV bot?

AThe attackers deployed 66 fake token contracts and fake liquidity pools over several weeks. These mimicked mainstream assets like WETH, USDC, and USDT to create seemingly profitable arbitrage opportunities, ultimately tricking the bot into granting permissions that were later exploited.

QWhat did the impersonator account on X (formerly Twitter) falsely claim after the attack?

AAn impersonator account on X, with the name changed to Jaredfromsubway.eth, falsely claimed it would offer a '$1 million bounty for the full return of all funds'.

Пов'язані матеріали

After Investing in Changxin, Hefei State Capital Makes Another Move

Two events unfolded within the same week. On July 13th, the Hefei Industrial Investment Xinzhi Xinyu Equity Investment Partnership with a pledged scale of 5 billion RMB was established. Three days later, ChangXin Technology launched its online and offline public offering at a price of 8.66 RMB per share, aiming to raise approximately 57.9 billion RMB. The link between these events is the Hefei Industrial Investment Group (Hefei ChanTou). Hefei ChanTou directly holds shares in ChangXin Technology through its wholly-owned subsidiary, ChangXin Integration, and is also behind the newly established 5 billion RMB fund. This highlights a strategic move: as ChangXin approaches its IPO, Hefei ChanTou establishes a new fund to prepare for the next round of industrial investment. Founded in 2015, Hefei ChanTou is a state-owned capital investment platform focused on industrial financing and innovation. Beyond direct equity holdings in major projects like ChangXin's 12-inch memory wafer manufacturing base, it manages various provincial and municipal government-guided funds. Its self-managed fund scale exceeds 100 billion RMB. ChangXin Technology, now China's leading DRAM manufacturer, exemplifies the classic "Hefei model." A decade ago, when founder Zhu Yiming sought entry into the capital-intensive DRAM sector, Hefei's state capital provided the crucial long-term support. Pre-IPO, entities within the Hefei ChanTou system hold significant direct and indirect stakes, with a theoretical combined value of roughly 116.2 billion RMB based on the IPO price. However, this long-cycle, concentrated investment model brings financial pressure. Hefei ChanTou's financials show significant liabilities, net outflows from investing activities, and reliance on investment income. The focus is now shifting alongside Hefei's broader "654X" industrial system, which encompasses six dominant industries, five emerging industries (like AI and biopharma), and four future industries (including quantum tech and nuclear fusion). The narrative is one of transition. As the ChangXin project reaches a major milestone with its IPO, the new 5 billion RMB fund symbolizes the beginning of the next investment chapter—targeting a more diverse and early-stage array of sectors within Hefei's expanded industrial vision.

marsbit2 хв тому

After Investing in Changxin, Hefei State Capital Makes Another Move

marsbit2 хв тому

Should Developers Build on Corporate Blockchains Like Base and Robinhood?

Should developers build on enterprise-backed public chains like Base, Robinhood, or Stripe's Tempo? While these chains offer enticing benefits—primarily access to the platform's existing user base for accelerated growth—they come with significant, well-documented risks stemming from the inherent conflict of interest when a company controls both the underlying chain and major on-chain applications. The core promise is traffic distribution: projects gain exposure through platforms like the Coinbase wallet or app. However, this model creates five major risks: 1. **Direct Competition**: The platform can leverage its data and position to launch and prioritize its own competing products, similar to Amazon creating private-label goods or Microsoft bundling Internet Explorer. 2. **Wallet Agnosticism**: Companion wallets (e.g., Coinbase Wallet) must support multiple chains and integrate top applications across the ecosystem to remain competitive, diluting the promised exclusive traffic advantage for the enterprise chain. 3. **Competitor Exclusion**: Rival platforms (e.g., Coinbase vs. Robinhood) have no incentive to promote applications built on a competitor's chain. 4. **Profit Extraction**: The party controlling end-users holds disproportionate bargaining power and can capture most of the value, squeezing protocol profits down to marginal cost. 5. **Unfulfilled Promises**: Promised traffic support can be deprioritized or withdrawn based on shifting corporate strategies. In contrast, neutral chains like Ethereum or Solana avoid these platform risks entirely. For developers considering enterprise chains, risk mitigation strategies include: evaluating substantial onboarding grants, seeking (though often weak) contractual guarantees, and, most crucially, pursuing a multi-chain strategy while building independent user acquisition channels. Enterprise chains may be useful for initial cold-start growth, but the ultimate goal should be cultivating a dedicated user base rather than long-term dependence on a single, conflicted platform.

marsbit3 хв тому

Should Developers Build on Corporate Blockchains Like Base and Robinhood?

marsbit3 хв тому

The Jacobian Conjecture that plagued Yitang Zhang for 7 years was overturned and disproven by Fable 5 overnight

**Summary:** The mathematical community was shocked when the longstanding **Jacobi Conjecture**—a core problem in polynomial mapping that had remained open for 87 years—was reportedly **disproven** by **Fable 5** (an AI model from Anthropic). The conjecture, first posed in 1939, asks whether a polynomial map with a constant, non-zero Jacobian determinant must have a polynomial inverse. Despite seeming intuitive, it had resisted numerous proof attempts by leading mathematicians. The breakthrough came when a researcher, Levent Alpoge, shared a succinct counterexample generated by Fable 5: a specific polynomial map from ℂ³ to ℂ³ whose Jacobian is the constant -2, yet which is not injective (mapping three distinct points to the same image). This elegantly falsifies the conjecture in its general form for dimensions ≥3. The counterexample is simple enough to be verified by hand or with tools like Wolfram Alpha. The event sparked intense discussion, with other AI models like GPT-5.6 quickly analyzing the result and even proposing a refined conjecture. It demonstrated AI's emerging capacity for genuine mathematical creativity, not just pattern matching. The story carries a poignant human dimension: renowned mathematician **Yitang Zhang** had devoted seven years of his early career to this problem under his PhD advisor, using a flawed lemma provided by the advisor. This setback contributed to Zhang leaving academia for years, including a period working at Subway, before his later breakthrough on the Twin Prime Conjecture. The AI's swift resolution underscores the tragic waste of his early effort on a conjecture now shown to be false in higher dimensions. It's important to note the disproof specifically targets the generalized (n-dimensional, n≥3) conjecture. The 2-dimensional case, which Zhang worked on, remains open and is considered mathematically distinct and even more challenging. Nonetheless, the event marks a significant moment, prompting reflections on AI's future role in mathematical discovery.

marsbit28 хв тому

The Jacobian Conjecture that plagued Yitang Zhang for 7 years was overturned and disproven by Fable 5 overnight

marsbit28 хв тому

Bought Bitcoin at $117,000, Sold at $62,000 in Tears: This Company’s Faith Only Lasted a Year

Wall Street's once-hot trend of corporate "Bitcoin hoarding" has hit a painful reality check. Empery Digital, formerly an electric motorcycle company, pivoted to Bitcoin in July 2025, accumulating over 4,000 BTC at an average cost of approximately $117,600 each. As Bitcoin's price plummeted, the company faced massive paper losses exceeding its total market value by early 2026, triggering internal conflict with a major shareholder demanding a sale. In a stark reversal from its earlier refusal to sell, Empery Digital recently sold 1,400 BTC at an average price of $62,000, locking in a significant loss of roughly $77 million on just those coins. The proceeds were used to pay down $10 million in debt, prepare for legal fees related to shareholder lawsuits, and, most notably, fund a new strategic shift: a $65 million investment for a 25% stake in an AI data center facility. This move completes a cycle of chasing market trends—from electric vehicles to Bitcoin treasury and now to AI infrastructure. Empery's case exposes the leveraged nature of the corporate "treasury model," where buying Bitcoin with borrowed money works only while prices rise. Once the asset fell below its cost basis, the company was forced to sell at a loss to service debt and pivot to the next opportunity. The company's remaining assets are 1,514 BTC and its ambitions in AI, demonstrating that its stated "long-term belief" in Bitcoin had a clear price tag: a 50% discount.

marsbit38 хв тому

Bought Bitcoin at $117,000, Sold at $62,000 in Tears: This Company’s Faith Only Lasted a Year

marsbit38 хв тому

Торгівля

Спот
活动图片