More than $7.5 million disappeared from addresses linked to Jaredfromsubway.eth after one of the most well-known sandwich bots on the Ethereum network became the victim of an attack. The perpetrators lured the automated system into a fake transaction specifically designed as a trap.
According to preliminary data, the funds were withdrawn using a complex counter-MEV scheme. It was developed to use the bot’s own trading logic against it.
Blockchain cybersecurity company Blockaid reported:
“The Blockaid Exploit Detection system recorded an attack on an MEV bot in the Ethereum network. The attackers used contracts under their control to trick the automated system into granting token approvals. These approvals were later used to withdraw funds.”
This incident was a rare setback for JaredFromSubway. The bot gained notoriety for its front-running and back-running strategies, which allowed it to profit at the expense of traders on decentralized exchanges.
According to Blockaid, Attackers Used Fake Tokens and Liquidity Pools
In a separate statement, Blockaid noted that this attack differed from classic phishing schemes and was likely not related to a smart contract vulnerability. Instead, the attackers targeted the bot’s trading logic. They made the system perceive fake opportunities as profitable trades and grant approvals to contracts controlled by the attackers.
To implement the scheme, an entire ecosystem of 66 fake tokens and liquidity pools was created. Among them were counterfeit versions of Wrapped ETH (WETH), USD Coin (USDC), and Tether (USDT), which were then linked to CAP tokens.
The fake assets mimicked the signals the MEV bot was tuned to. As a result, the system automatically granted approvals to the attackers’ contracts.
Blockaid CTO Raz Niv commented on the situation:
“Ironically, it was at this moment that the bot effectively handed over the keys to millions of dollars from its own vault to the attackers.”
According to Etherscan, the damage amounted to about $7.5 million.
Blockchain data shows that part of the stolen funds has already been sent through the Tornado Cash service.
Crypto investor and commentator David Gokhshtein urged people not to celebrate the incident:
“I don’t think this is something to celebrate. No one should be celebrating this. But if this bot ever ran a sandwich attack against you, you probably won’t be too upset by this news.”
Why Jaredfromsubway.eth Is Considered One of the Most Aggressive Sandwich Bots
Earlier analysis showed that Ethereum traders lose about $60 million per year due to sandwich attacks. According to Ethereum network telemetry, from November 2024 to October 2025, the network saw an average of 60,000 to 90,000 such attacks per month. Jaredfromsubway.eth accounted for about 70% of this volume.
See also: Microsoft Discovers USB Worm for Stealing Cryptocurrency
In May, Jaredfromsubway.eth attacked a transaction by Vitalik Buterin involving 26,544 DigitalBits. The loss was small, but the case showed that MEV bots are willing to hunt even for minimal profit. According to Etherscan, the Ethereum founder was hit by a sandwich attack in block 24993038.
Before Buterin’s swap went through, the bot ran about $1.14 million in WETH through SushiSwap and Uniswap V2 to influence the price of XDB in both liquidity pools.
Previously, EigenPhi warned that slippage in crypto transactions gives Jared the opportunity to push the price up. As a result, traders pay more and the bot takes the difference.
MEV tracker described the scheme as follows:
“Jared 2.0 uses adding liquidity as the front or central part of the attack, and removing liquidity as the back part. The combinations can vary: several transactions are inserted between them, which become the victims of the sandwich attack.”
By May, the volume of MEV extraction in Ethereum exceeded $1.2 billion. Sandwich attacks accounted for about 51% of the total volume.
In recent months, Buterin has been promoting the idea of encrypted mempools. This is one way to reduce the harm from aggressive MEV practices in the future roadmap of Ethereum.