The Exploit Mechanism: The "Approval Trap"
Published 6/22/2026, 9:46:02 AM
The JaredFromSubway MEV bot, one of Ethereum's most dominant sandwich attack operators, lost an estimated $7.5 million to $15 million in a sophisticated honeypot attack. The exploit was not a private key compromise but a "logic trap" that manipulated the bot's automated ERC-20 approval system, causing it to authorize the theft of its own assets.
The Exploit Mechanism: The "Approval Trap"
The attack was a multi-week operation designed to exploit the bot's automated profit-seeking logic. Unlike typical honeypots that trap a user's buy order, this attack targeted the bot's spending permissions.
- Pattern Establishment: The attacker deployed fake tokens and liquidity pools (mimicking WETH, USDC, and USDT) to lure the bot. For weeks, the attacker allowed the bot to successfully "sandwich" small trades, establishing these malicious contracts as "profitable" and "trusted" within the bot's algorithm.
- The Approval Vulnerability: To interact with these new tokens, the bot's system granted ERC-20 approvals to the attacker's malicious contracts. MEV bots often provide "infinite" or large approvals to save on gas for future high-frequency trades.
- The Drain: Once the bot granted the attacker-controlled contracts permission to spend its real assets (actual WETH, USDC, and USDT), the attacker triggered the
transferFromfunction. This allowed the attacker to pull assets directly out of the bot's wallet using the permissions the bot had voluntarily granted.
Loss Summary and Impact
While some estimates place the total loss as high as $15 million, documented on-chain data confirms a significant portion of the drain across major assets.
| Metric | Detail |
|---|---|
| Target Address | 0xae2fc483527b8ef99eb5d9b44875f005ba1fae13 |
| Attacker Address | 0x6b75d8af000000e20b7a7ddf000ba900b4009a80 |
| Estimated Total Loss | $7.5M – $15M |
| Confirmed Drained Assets | ~92 WETH, ~$143,000 USDC, ~$149,000 USDT |
| Bot Market Share | ~70% of Ethereum sandwich attacks at peak |
| Network Impact | Responsible for ~7% of total Ethereum gas usage at peak |
Timeline of Events
- Preparation: The attacker spent weeks deploying infrastructure and "training" the bot's algorithms to recognize the malicious pools as safe and profitable.
- Execution: The final drain occurred once the bot had granted sufficient approvals. Security firms like Blockaid confirmed the root cause was the bot's internal rules for identifying trades rather than a protocol-level bug.
- Aftermath: The event is cited as one of the most significant "predator-turned-prey" incidents in MEV history, highlighting that even highly sophisticated automated systems are vulnerable to social engineering at the smart contract level.
The exact total loss remains difficult to pin down to a single dollar amount due to the complexity of the bot's various sub-accounts and the fluctuating value of the assets at the time of the drain, but the $7.5M floor is widely accepted by on-chain analysts.
Next Steps:
- Would you like to perform a deep dive into the current holdings and recent activity of the JaredFromSubway wallet?
- I can set up a monitor to alert you if the attacker's address moves the stolen funds to an exchange or mixer.