
Ethereum's well-known MEV bot JaredFromSubway was drained after an attacker used contracts that made its automated trading system grant token approvals, according to Blockaid. The security firm reported that the incident was not a normal phishing case and not a direct bug in the victim contract. The attacker first tested routes where approvals were used at once, leaving no open allowance, before changing the route design so the bot gave approvals that were not spent or revoked. As per Cointelegraph, this represents a reverse attack that exploited MEV bot decision logic rather than traditional vulnerabilities. The attacker exploited the bot's mechanism: its automated system detected what looked like profitable MEV opportunities and generated approvals to attacker-controlled helper contracts.
According to AMBCrypto, the attacker has now begun actively laundering the stolen funds through multiple channels. Out of the $7.5 million stolen, approximately $5.1 million has been transferred to Tornado Cash using sophisticated laundering techniques. The attacker used 20 different transactions, each worth 100 ETH, to deposit 2,000 ETH into Tornado Cash in batches to obscure the trail. To reduce ETH price volatility exposure and facilitate future transfers, the remaining 1,422 ETH were exchanged for roughly $2.44 million worth of DAI - a dollar-pegged stablecoin. The exploit itself brought in 1,583 ETH, $2.87 million in USDC, and $2.09 million in USDT, with the attacker combining these assets and exchanging them for 4,427 ETH to reduce fragmentation and ease the laundering process.
The attack appears to have targeted the bot's own trading workflow, as reported by Blockaid. MEV bots watch Ethereum activity and act on transactions that look profitable. In this case, attacker-controlled contracts made the route look useful enough for the bot to approve spending rights. The attacker used 66 fake token contracts that copied the look and function of WETH, USDC and USDT, paired with fake liquidity pools. One example cited by Blockaid involved an approval of about 92.16 WETH to an attacker helper contract. While in normal cases, the bot would use up the approval during the trade, in this case, the attacker crafted routes that allowed the approvals to stay open. Once enough approvals were in place, the attacker conducted a "final sweep" to pull WETH, USDC and USDT from the JaredFromSubway MEV bot contract via transferFrom. The setup was built over several weeks, where the attacker deployed dozens of fake token contracts and fake liquidity pools that looked like profitable trades.
The attack highlights the scale of MEV activity on Ethereum, with data showing that between November 2024 and October 2025, approximately 60,000 to 90,000 sandwich attacks occurred monthly on the Ethereum network, according to Cointelegraph. Notably, about 70% of these attacks were linked to JaredFromSubway.eth, demonstrating the bot's significant market presence. JaredFromSubway has been active since early 2023 and is one of Ethereum's most watched sandwich bots, as previously reported by crypto.news. In a sandwich attack, a bot places trades before and after a user's swap, potentially giving the user a worse price while the bot captures the spread. Sandwich attacks cost Ethereum traders about $60 million a year, with the exploit showing how machine-speed, pattern-based systems can themselves be turned into victims. The bounty-plus-legal-threat approach makes practical sense with permanent on-chain evidence, and if the attacker tries to cash out on centralized exchanges, KYC could eventually link identities. The incident underscores both the scale and risks of industrialized sandwich-bot activity by demonstrating how automated trading systems can be vulnerable to the same adversarial tactics they use against other traders.