JaredFromSubway MEV Bot Loses $15M in Phishing Attack
The JaredFromSubway Ethereum MEV bot suffered a $15 million loss after an attacker manipulated its opportunity-detection logic by creating fake cryptocurrency trading opportunities. The drain was detected on Saturday by blockchain security firm Blockaid, and JaredFromSubway confirmed that the attacker used fake pools and tokens to trick the bot into approving helper contracts. According to Blockaid, the attacker deployed contracts designed to appear as profitable MEV opportunities to the bot's automated execution system. The bot automatically analyzed routes and trade opportunities, granting ERC-20 token approvals to attacker-controlled contracts. The attacker planned carefully, with early transactions serving as harmless tests. Later, the route was changed so that allowances were not consumed. The attacker accumulated up to 92.1614 WETH in approvals, then used them to withdraw WETH, USDC, and USDT via transferFrom. JaredFromSubway is a private MEV bot known for sandwich attacks. Initially, it offered a $3 million bounty, later increased to $7.5 million for 50% return. It is also negotiating with a white-hat hacking group, with no deal confirmed yet.
Key facts
- Attacker used fake pools and tokens to trick JaredFromSubway MEV bot.
- Bot granted ERC-20 approvals to attacker-controlled contracts.
- Attacker accumulated 92.1614 WETH approvals before draining funds.
- Stolen funds include WETH, USDC, and USDT via transferFrom.
- JaredFromSubway increased bounty from $3M to $7.5M for 50% return.