Ethereum MEV Bot ‘Jaredfromsubway.eth’ Suffers $7.5M Exploit via Transaction Approval Trap
The prominent Ethereum Maximal Extractable Value (MEV) bot, known as Jaredfromsubway.eth, has reportedly been exploited, leading to a loss of approximately $7.5 million. The incident, detailed in an analysis by on-chain...
Watchlist
Published in the last two hours. A tracked entity is involved.
The prominent Ethereum Maximal Extractable Value (MEV) bot, known as Jaredfromsubway.eth, has reportedly been exploited, leading to a loss of approximately $7.5 million. The incident, detailed in an analysis by on-chain security firm Blockaid, points to a sophisticated transaction approval trap mechanism as the method of attack.
According to the analysis shared on X, the exploit targeted a vulnerability within the bot’s router contract. Jaredfromsubway.eth is recognized as one of the most active and gas-intensive arbitrage bots operating on the Ethereum network. The attacker is reported to have utilized custom smart contracts to manipulate the bot into executing unprofitable sandwich transactions. This maneuver ultimately led to the draining of the bot’s contract balance.
TL;DR:
- Prominent Ethereum MEV bot Jaredfromsubway.eth exploited for $7.5 million.
- Attack utilized a transaction approval trap targeting a router contract vulnerability.
- Sophisticated automated bots remain susceptible to protocol-level smart contract traps, as noted by Blockaid.
Blockaid, which first detected and flagged the exploit on its on-chain monitoring channels, explains that the attack involved forcing the bot into specific, unfavorable transactions. The analyst says this was achieved by leveraging a weakness in how the bot processed transaction approvals. Essentially, the attacker tricked the bot into approving and executing trades that benefited the attacker at the bot’s expense.
The incident serves as a stark reminder that even highly sophisticated automated trading systems and bots, like Jaredfromsubway.eth, are not immune to clever smart contract exploits. The security firm’s commentary, available in full on X, provides further details on the on-chain metrics observed during the exploit. This event suggests that ongoing vigilance and robust smart contract security auditing are crucial, even for established and gas-hungry participants in the Ethereum ecosystem.
The primary source for this analysis can be found at https://x.com/blockaid_/status/2068433798757577198.
Disclaimer: This article discusses market/technical analysis and is for informational purposes only. It does not constitute investment advice, financial advice, or an endorsement by NewsBTC of any analysis or trading setup. This analysis was originally shared by analyst on X @blockaid_ on X at X post.
This article was written by the News Desk and edited by Samuel Rae.
This article is based on commentary shared on X by @blockaid_. at @blockaid_ on X
Why this matters
Ethereum is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on NewsBTCRelated market context
Ethereum’s Jaredfromsubway MEV bot drained after approving its own $7.5M theft
The Jaredfromsubway MEV bot, linked to roughly 70% of Ethereum sandwich attacks, lost more than $7.5 million in an allowance drain...
Aztec Legacy Exploit Shows The Long Tail Risk Of Deprecated Crypto Contracts
Old smart contracts can remain dangerous long after a protocol has moved on. A SlowMist analysis of a $2.19 million theft from Azt...
Why Ethereum Underperforms Despite Wall Street Hype And Spot ETF Approvals
Ethereum (ETH) is facing a curious market dynamic. Despite significant Wall Street interest and the recent approvals of spot Ether...
$2.1M Aztec Exploit Sparks Alarm as Funds Drain From Long-Abandoned Privacy Protocol
Key Takeaways: Around $2.1 million was transferred from Aztec Connect in a suspected exploit. Aztec Connect was terminated 3 years...
Ethereum Foundation Details Clear Signing Wallet Standards to Combat Phishing
The Ethereum Foundation has laid out new security standards for crypto wallets designed to make transaction approvals much clearer...
Ethereum's biggest 'sandwich' bot drained of $7.5 million in ironic exploit
Blockaid said an attacker tricked Jaredfromsubway.eth into approving fake trading routes, then used those approvals to drain WETH,...