K

KeyAudit

· ·defi-exploit·private-key-leak·phishing

JaredfromSubway.eth Loses $7.5M in Reverse Honeypot Exploit

JaredfromSubway.eth, the most prolific sandwich-attack bot on Ethereum, was drained of at least $7.5 million in a reverse honeypot exploit on June 20–21, 2026. An unknown attacker deployed 66 fake token contracts to trick the bot into granting token-spending approvals, then swept its real assets in a single coordinated transaction. The stolen funds — ETH and stablecoins — were converted to ETH and sent to Tornado Cash. No funds have been recovered. The exploit underscores the importance of revoking unused approvals and vetting smart contracts before interacting with them on-chain. This incident serves as a cautionary tale for all DeFi users, highlighting that even sophisticated automated traders can fall victim to well-crafted traps.

Key facts

  • Attacker deployed 66 fake token contracts mimicking WETH, USDC, USDT.
  • JaredfromSubway.eth bot granted approvals to malicious contracts without vetting.
  • Stolen funds converted to ETH and laundered through Tornado Cash.
  • Exploit highlights dangers of unrevoked token approvals in DeFi.
  • No funds recovered; incident occurred June 20-21, 2026.

KeyAudit data perspective

📊 KeyAudit data: Ethereum historical leak records: 1846029

← Back to list