Jaredfromsubway Trading Bot Loses $7.5M in Sandwich Attack Exploit
The well-known Ethereum trading bot jaredfromsubway was exploited on June 22, losing approximately $7.5 million in a sophisticated attack. According to security firm Blockaid, the attacker used fake tokens and fraudulent smart contracts to trick the bot into granting unauthorized spending permissions. Unlike legitimate transactions that revoke permissions after execution, the attacker's crafted transactions left those approvals active, allowing them to drain funds. The bot, famous for performing sandwich attacks—a form of MEV manipulation—was turned against itself. The operator offered a 50% white hat bounty of 2,150 ETH (about $3.7 million) for the return of funds within 48 hours, threatening legal action otherwise. However, a portion of stolen assets has already been sent to Tornado Cash, indicating the attacker's intent to launder funds. The incident highlights vulnerabilities even in sophisticated MEV bots and has drawn mixed reactions from the community, with some seeing it as poetic justice for the bot's past sandwich attacks.
Key facts
- Jaredfromsubway lost $7.5M in an exploit using fake tokens and fraudulent contracts.
- The attack left spender permissions active, allowing fund draining.
- Operator offered 50% white hat bounty of 2,150 ETH.
- Stolen funds partially sent to Tornado Cash.
- Community reaction mixed, some viewing it as retribution for sandwich attacks.