Root Cause and Attack Vector
Published 6/21/2026, 7:46:21 AM
The Jaredfromsubway MEV bot (jaredfromsubway.eth), one of Ethereum's most prolific sandwich-attack bots, was exploited for approximately $15 million to $17 million on June 20–21, 2026. The exploit was not a traditional smart contract bug but a sophisticated "anti-MEV honeypot" that turned the bot's automated profit-seeking logic against itself [Source: https://www.kucoin.com/news/jaredfromsubway-mev-bot-exploited-for-15-million].
Root Cause and Attack Vector
The exploitation was a multi-week operation targeting the bot's automated decision-making and approval systems. Security researchers describe the mechanism as a "counter-MEV" setup [Source: https://cryptobriefing.com/jaredfromsubway-mev-bot-exploit-15-million/].
- Adversarial Logic Manipulation: The attacker identified that the bot would automatically interact with any pool or token that appeared to offer a profitable sandwich opportunity, regardless of the token's legitimacy [Source: https://www.coindesk.com/tech/2024/05/07/vitalik-buterin-gets-sandwiched-by-jaredfromsubway/].
- Fake Token Infrastructure: The attacker deployed 66 fake token contracts and malicious liquidity pools designed to mimic legitimate assets like WETH, USDC, and USDT [Source: https://cryptobriefing.com/jaredfromsubway-mev-bot-exploit-15-million/].
- Approval Harvesting: Over several weeks, the bot was lured into executing trades within these fake pools. To facilitate these trades, the bot's automated system granted token approvals to auxiliary contracts controlled by the attacker [Source: https://cryptobriefing.com/jaredfromsubway-mev-bot-exploit-15-million/].
- The Mass Drain: Once sufficient approvals were gathered, the attacker executed a single transaction to invoke these backdoor permissions, sweeping the bot's accumulated holdings of WETH, USDC, and USDT into the attacker's wallet [Source: https://www.kucoin.com/news/jaredfromsubway-mev-bot-exploited-for-15-million].
Key Events and Impact
The bot was historically significant, at one point accounting for 7% of all Ethereum gas fees in a single month [Source: https://tokenmetrics.com/blog/jaredfromsubway-mev-bot-exploit].
| Date | Event | Details |
|---|---|---|
| May 2026 | Vitalik Incident | Bot sandwiched a ~$4 swap by Vitalik Buterin using $1.14M in volume, signaling its aggressive scanning [Source: https://www.coindesk.com/tech/2024/05/07/vitalik-buterin-gets-sandwiched-by-jaredfromsubway/]. |
| June 20, 2026 | Exploitation | Initial reports of a $15M+ drain surface; security firms confirm the "honeypot" method [Source: https://www.kucoin.com/news/jaredfromsubway-mev-bot-exploited-for-15-million]. |
| June 21, 2026 | Bounty Offer | Jaredfromsubway.eth offered a $1 million bounty for the return of the funds [Source: https://www.odaily.news/en/post/5196423]. |
The total loss is widely reported at $15 million, though some social media reports and security trackers estimated the figure as high as $17 million [Source: https://www.kucoin.com/news/jaredfromsubway-mev-bot-exploited-for-15-million]. The event is considered a landmark case of "the hunter becoming the hunted" in the MEV landscape.
Next Steps:
- Would you like a deep dive into the current profitability and gas usage of the new Jaredfromsubway 2.0 contract?
- I can monitor the attacker's wallet for any movement of the $15M in stolen funds. Would you like to set up an alert?