Ethereum’s Most Feared MEV Bot Loses $15M After Approving Its Own Exploit in Trap
Key Takeaways: The Jaredfromsubway.eth MEV bot lost about $15 million in an advanced exploit. Attackers manipulated the bot’s automated trading logic using fake tokens and liquidity routes. The incident exposed a critica...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Key Takeaways:
- The Jaredfromsubway.eth MEV bot lost about $15 million in an advanced exploit.
- Attackers manipulated the bot’s automated trading logic using fake tokens and liquidity routes.
- The incident exposed a critical risk in MEV automation rather than a flaw in Ethereum itself.
User Score
8.7
Follow us on Google NewsOne of Ethereum’s most notorious MEV operators has become the victim of a highly unusual attack. The Jaredfromsubway.eth MEV bot was emptied of approximately $15 million after a special attack against the bot to bypass the automated execution system and gain approvals on tokens.
You guys seriously think $15 million is a big deal for me? 😂
I will keep front running you all 👊 https://t.co/gkAbJaf8wz
— Jaredfromsubway.eth (@jaredsmev) June 21, 2026
It quickly gained traction in the cryptocurrency community, and this weakness was not in the private keys or phishing techniques, or even a standard smart contract vulnerability.
Attackers Turned the Bot’s Logic Against ItBlockaid described the incident as an exploit of an automated MEV execution system. Instead of directly compromising the bot, the attacker spent time constructing fake trading environments designed to appear profitable. These are all fake wrapper tokens along with liquidity pools that appear to be real trading routes with WETH, USDC and USDT.
The bot’s algorithms recognized the interactions on the routes as potential arbitrage or MEV opportunities and automatically interacted with these routes. In the context of that decision, the system granted helpful contracts that the attacker controlled permission to purchase tokens for the system.
Fake Routes Created a Hidden Attack SurfaceThe exploit wasn’t a one-and-done operation. In the beginning, both fake routes responded as they should, and approvals would be used when executing. This gave the appearance of authenticity, and built trust into the bots automation process.
Read More: $2.1M Aztec Exploit Sparks Alarm as Funds Drain From Long-Abandoned Privacy Protocol
Critical Token Approvals Remained ActiveLater the attacker added routes that were approved for the operation, but not used. Those permissions were still active and the attacker enabled supply permissions to assets owned by the MEV bot.
The attacker then utilised the ERC-20 transferFrom function to transfer WETH, USDC and USDT from the bot’s wallet to an attacker address they controlled.
Not a Smart Contract Hack or Phishing ScamSecurity researchers stressed that this exploit was not the same as a lot of the prevalent, high-profile crypto exploits. There has not been any vulnerability found in Ethereum, nor has there been any private keys stolen. Similarly, the attack did not use any retail-users common phishing attack method.
The second way was not with the automatic earning of the bot, but by taking advantage of its weakness. The attacker now offers up the seemingly lucrative opportunities and makes the system grant permission for its own ante.
This situation illustrates the level to which trading bots can present individual security concerns if the very benefit of automation is to rush through the initiation of trade processes without adequate validation of counterparties and approvals.
Read More: $50M Exploit Finally Forces Radiant Capital Shutdown After 18 Months of Recovery Efforts
The post Ethereum’s Most Feared MEV Bot Loses $15M After Approving Its Own Exploit in Trap appeared first on CryptoNinjas.
Why this matters
Ethereum is showing up inside the Stablecoins theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on CryptoNinjasRelated market context
HIFI Raises $37M To Build Stablecoin And Tokenized Market Infrastructure
HIFI has raised a $37 million Series A led by Left Lane Capital. The company says the funding will expand stablecoin payments, car...
Visa cuts reported stablecoin volume but there’s no proof payments fell
Visa’s September 18 data refresh lowered its adjusted stablecoin volume measure, while its adjusted transaction count fell by less...
Crypto Hacks: Three Projects Hacked in One Day as Losses Hit Over $11M
Three crypto projects were attacked on September 24, suffering combined losses of more than $11M. Attackers drained around $1.8M f...
Ethereum is not instant, but collateral could make it feel that way
When a payment app tells you a transfer is complete, you start making decisions. You hand over whatever you've sold, spend the mon...
Binance deal gives Circle a boost in stablecoin race with Tether, analysts say
The five-year deal could strengthen USDC’s reach in emerging markets, though Tether’s liquidity advantage remains hard to dislodge...
Bitget hacker withdraws $1.23M from Binance, funnels funds to attacker-controlled wallet
The Bitget hack highlights vulnerabilities in crypto exchanges, prompting urgent calls for enhanced security measures and internat...