The Hunter Becomes the Hunted: The Most Profitable MEV Bot Gets Hacked

marsbit发布于2026-06-21更新于2026-06-21

文章摘要

A well-known and highly profitable Ethereum MEV Bot, Jaredfromsubway.eth, suffered a sophisticated on-chain attack this Saturday, losing over $7.5 million. Analysis by Blockaid and others reveals this was not a conventional phishing or smart contract exploit, but a targeted "counter-MEV honeypot attack." The attacker meticulously laid a trap over several weeks, deploying 66 fake token contracts and liquidity pools disguised as major assets like WETH and USDC. These pools created the illusion of arbitrage opportunities. The MEV Bot's automated system detected these signals, executed trades, and in the process, granted approval permissions to attacker-controlled contracts. These approvals were not revoked, creating a persistent vulnerability. The attacker then exploited this in a single transaction, draining the bot's ETH, USDC, and USDT holdings. Jaredfromsubway.eth is notorious as one of Ethereum's most active and profitable MEV Bots, primarily known for executing "sandwich attacks" to profit from transaction slippage. Estimates suggest it has earned tens of millions in MEV revenue. The incident highlights escalating crypto security threats, demonstrating that even top-tier automated "predators" are vulnerable to novel, logic-based attacks designed to exploit their own operational rules. Following the hack, an unverified X account impersonating Jaredfromsubway.eth emerged, falsely offering a bounty for the return of funds, prompting developer warnings for users to stay vig...

By Azuma(@azuma_eth)

Jaredfromsubway.eth, a well-known MEV Bot address long active on the Ethereum network, was targeted in a highly specific on-chain attack on Saturday, resulting in losses exceeding $7.5 million.

Investigations by Blockaid and several on-chain analytics firms revealed that this incident was not a traditional phishing attack or smart contract exploit, but rather a "counter-MEV honeypot attack" specifically designed to exploit the operational logic of MEV Bots.

Over the preceding weeks, the attacker systematically deployed 66 counterfeit token contracts and fake liquidity pools. These assets were meticulously disguised on-chain as major stable assets like WETH, USDC, and USDT, creating seemingly genuine arbitrage trading pathways.

The attack chain unfolded as follows — fake liquidity pools generated signals of "exploitable price gaps"; the MEV bot automatically identified the arbitrage opportunity and executed a trade; during the transaction, the robot granted authorization to an auxiliary contract controlled by the attacker; this authorization was not revoked promptly, leading to persistent exposure of permissions; finally, the attacker triggered a pre-embedded backdoor logic in a single transaction, directly transferring assets such as ETH, USDC, and USDT held by the MEV bot's address.

On-chain data shows that the total scale of assets stolen from Jaredfromsubway.eth this time has exceeded $7.5 million. The attacker subsequently split and transferred some of the assets, further dispersing the fund flow through mixing tools.

Who is Jaredfromsubway.eth? The Most Notorious MEV Bot Address

The reason this attack is so notable now is that the victim, Jaredfromsubway.eth, is itself the most active, most profitable, and most notorious MEV Bot on the Ethereum network (perhaps without even needing 'one of').

"MEV attacks" are essentially a category of on-chain arbitrage behaviors centered around "transaction ordering rights." In the Ethereum network, transactions wait in the mempool to be included in a block before they are confirmed. Block builders or searchers can adjust transaction order, insert transactions, or rearrange transactions within a block to extract additional profits.

The most typical attack type is the "Sandwich Attack"— the attacker inserts a buy order before and a sell order after a user's transaction, profiting from price slippage within a short timeframe. This behavior is extremely common in high-liquidity DeFi trading pairs and constitutes one of the most fundamental profit models within the MEV ecosystem.

Jaredfromsubway.eth is precisely the most representative automated executor of this mechanism. Unlike traditional "single-point arbitrage bots," this MEV Bot operates more like a highly industrialized MEV execution system. It continuously monitors unconfirmed transactions in the mempool, identifies in real-time transaction paths vulnerable to sandwiching, and within an extremely short time window, completes transaction construction, gas bidding, and order insertion, systematically capturing slippage profits.

Data from Cointelegraph Research shows that between November 2024 and October 2025, approximately 60,000 to 90,000 sandwich attacks occurred monthly on the Ethereum network, with about 70% related to Jaredfromsubway.eth's strategy system.

In May this year, when Ethereum co-founder Vitalik Buterin exchanged 26,544 DigitalBits (XDB), his transaction was also precisely targeted and sandwiched by Jaredfromsubway.eth.

There is no official statistic on Jaredfromsubway.eth's historical revenue, but conservative estimates suggest that the address has accumulated tens of millions of dollars in MEV profits during its active periods. During some peak periods, its single-day profits could reach hundreds of thousands of dollars, and it consistently appeared at the top of Ethereum MEV rankings for a long time.

Crypto Security Threats Escalate: Even Top Predators Are Not Safe

While some may marvel at the "hunter finally getting hunted," the hacking of Jaredfromsubway.eth also rings an alarm bell for cryptocurrency risks once again.

In past perceptions, MEV Bots like Jaredfromsubway.eth belonged to the "predator" side of the on-chain ecosystem — they continuously capture slippage and arbitrage opportunities in user transactions through automated strategies, inherently occupying an advantageous position, and could even be considered a representative class of attackers in the crypto market.

But this time, it became the target of design, inducement, and eventual harvesting. Moreover, the attacker did not choose a traditional vulnerability exploitation path. Instead, they constructed a long-running "behavioral trap," allowing the MEV Bot's automated system to proceed step by step towards erroneous decisions while fully complying with its own rules.

It must be admitted that even participants like Jaredfromsubway.eth, who were once most adept at "exploiting the rules," are now exposed to more multidimensional attack surfaces.

It is also worth noting that after the Jaredfromsubway.eth hack, an unknown account on X with 94,000 followers changed its name to Jaredfromsubway.eth and falsely claimed it would "offer a $1 million bounty for the full return of all funds."

Several developers issued risk warnings regarding this, emphasizing that the account is not an official Jaredfromsubway.eth account (the MEV Bot team has no official account) and that it cannot be ruled out that this account might be used for scams in the future. Users are urged to remain highly vigilant.

相关问答

QWhat type of attack was the Jaredfromsubway.eth MEV bot a victim of?

AIt was a victim of a 'counter-MEV honeypot attack', a targeted attack designed to exploit the behavioral logic of MEV bots, not a traditional phishing or smart contract exploit.

QWho is Jaredfromsubway.eth and what is it known for in the Ethereum ecosystem?

AJaredfromsubway.eth is one of the most active, profitable, and notorious MEV bots on the Ethereum network. It is particularly known for executing 'sandwich attacks' to capture slippage profits from user transactions.

QWhat was the estimated total loss for Jaredfromsubway.eth in this attack?

AThe estimated total loss for Jaredfromsubway.eth in this attack was over $7.5 million in assets like ETH, USDC, and USDT.

QWhat specific attack method was used to set up the trap for the MEV bot?

AThe attackers deployed 66 fake token contracts and fake liquidity pools over several weeks. These mimicked mainstream assets like WETH, USDC, and USDT to create seemingly profitable arbitrage opportunities, ultimately tricking the bot into granting permissions that were later exploited.

QWhat did the impersonator account on X (formerly Twitter) falsely claim after the attack?

AAn impersonator account on X, with the name changed to Jaredfromsubway.eth, falsely claimed it would offer a '$1 million bounty for the full return of all funds'.

你可能也喜欢

虚拟资产交易者押注持续上涨,但需求能否突破0.65美元关口?

过去24小时内,虚拟协议(VIRTUAL)价格上涨近5%,未平仓合约增长近17%,交易量也显著增加,表明短期情绪有所改善。其24小时交易量达到7110万美元,较前一日翻倍。这波上涨可能源于周末后的周一市场活动以及比特币试图突破6.52万美元供应区的带动。 尽管有消息称虚拟协议在Robinhood Chain上推出了可定制代币化指数,但该代币价格仍未能突破关键上方供应区。从日线图看,整体摆动结构仍处于下行趋势中。价格需跌破0.459美元才能确认跌势延续,而突破1.19美元才能转为看涨。 近期一周内VIRTUAL虽上涨17%,但目前已接近0.63-0.65美元的局部供应区,该区域曾在6月中旬阻挡上涨。能量潮指标自5月以来持续走低,尽管相对强弱指数高于50,但过去两个月缺乏持续的买盘量能,反弹力度可能不足。 短期来看,价格可能在0.65美元附近遭遇阻力并回落。若成功突破该阻力并将其转为支撑,则可能开启向1.04美元甚至1.19美元的上涨行情。交易员目前可保持看跌倾向,直至0.65美元被攻克;若突破,则可考虑做多,但需注意更高时间框架的趋势仍为看跌。 总结:短期价格与量能飙升可能预示看涨,但长期趋势偏空。若突破0.65美元关键阻力,价格或有望上探1.0-1.2美元区间。

ambcrypto59分钟前

虚拟资产交易者押注持续上涨,但需求能否突破0.65美元关口?

ambcrypto59分钟前

Visa 躬身入局稳定币:不消灭稳定币,而是要向它们「收租」

Visa宣布推出稳定币平台,旨在帮助银行、金融机构和金融科技公司更便捷地发行、管理稳定币,并将其无缝集成到Visa现有的庞大支付生态中。该平台计划覆盖超过2亿商户和1.5万家金融机构。 作为传统支付巨头,Visa此举被视为“躬身入局”,其策略并非消灭现有稳定币,而是拥抱并升级该生态。稳定币市场规模越大,Visa网络处理的交易就越多,从而获得更多收入。这有利于稳定币的进一步采用和整个市场的扩大,但可能导致顶级发行商的市场集中度下降,竞争将转向分发能力、商户接入和合规性。 对主流稳定币的影响方面:USDC短期将受益于通过Visa平台获得直接结算与集成支持,具备先发优势,但中长期将面临更激烈竞争。USDT由于其在新兴市场和加密交易场景的优势,受冲击可能相对更大,在商户支付和机构结算领域的份额或被蚕食。 总体而言,Visa的目标是为稳定币生态“收租”并做大蛋糕,对长期生态发展是利好,但单纯依赖发行赚取利息的模式将面临挑战。 对以太坊的影响为中性偏利好。Visa与以太坊生态合作紧密,其平台有望引导更多传统资金以稳定币形式流入,提升以太坊作为结算层的需求与链上活动。虽然Visa平台会支持多链,但以太坊凭借其成熟度与去中心化程度,在合规稳定币领域仍是机构首选。

marsbit1小时前

Visa 躬身入局稳定币:不消灭稳定币,而是要向它们「收租」

marsbit1小时前

交易

现货
活动图片