Notorious Ethereum MEV Bot JaredFromSubway Exploited, Loses Over $15 Million

Analyst SpecterAnalyst first flagged the incident as potentially tied to JaredFromSubway, describing a possible “$7 million-plus drain” and pointing to a transaction consistent with a dangling-approval pattern. The reporting also cites a specific June 20 transfer cluster where the largest single move was 1,423 ETH (about $2.46 million) sent from 0x3e37f4A10d771Ba9dE44b6d301410b1BEdeA65d0, with additional 1,000 ETH transfers to separate recipients totaling 4,423 ETH across the same cluster.
PeckShieldAlert’s asset-by-asset accounting differs from purely ETH-based estimates: it reported the exploit netted roughly 1,474.58 WETH, 2.87M USDC, and 2M USDT in a single event. The same report says the attacker then converted proceeds into about 4.4K ETH and moved 1K ETH via TornadoCash.
CryptoBriefing provided additional operational context showing why the takedown matters: it said JaredFromSubway had executed “hundreds of thousands” of sandwich attacks since early 2023, with gross revenues reportedly in the $34 million–$40 million range during peak three-month windows, and net profits estimated at more than $6 million after accounting for Ethereum gas costs. It also noted that by mid-2024 the bot’s single-day gas expenditure exceeded 210 ETH.
The same reporting highlighted how the bot evolved—“Jared 2.0” emerged by August 2024, adding advanced multi-hop routing for front-running/back-running efficiency—and said this upgraded version processed over 85,000 transactions and accumulated “hundreds of thousands of ETH.” It also referenced a high-profile example: in May 2026 the bot executed a sandwich against a Vitalik Buterin token swap using over $1.14 million in WETH volume to front-run.
JaredFromSubway, the most notorious sandwich-attack bot on Ethereum, was exploited and drained of more than $15 million on June 20, 2026. The developer behind the bot confirmed the hack, posting: "My MEV bot was hacked and approximately $15 million in assets were drained," according to KuCoin News.
The attacker walked away with 1,474.58 WETH, 2.87 million USDC, and 2 million USDT, per PeckShieldAlert. The proceeds were quickly converted into roughly 4,400 ETH. At least 1,000 ETH was then routed through Tornado Cash to cover the trail.
The attack was not a simple hack. Security firm Blockaid described it as a "targeted exploitation of the bot's automation execution mechanism," according to Crypto Briefing. The attacker deployed a fake "bait contract." The bot interacted with it, granting a token approval. Then the attacker used that leftover approval — a so-called dangling approval — to drain the funds later.
Analyst SpecterAnalyst first flagged the drain on June 20, initially estimating a "$7 million-plus" loss. On-chain data showed a cluster of large transfers at around 23:35 UTC. The biggest single move was 1,423 ETH — about $2.46 million — sent from wallet 0x3e37f4A10d771Ba9dE44b6d301410b1BEdeA65d0, followed by three separate 1,000 ETH transfers, totaling 4,423 ETH, per Crypto Briefing.
JaredFromSubway made its name running sandwich attacks. A sandwich attack works like this: the bot spots a large pending trade, buys the same token first to push the price up, then sells right after the victim's trade goes through. The victim gets a worse price. The bot keeps the difference.
Since early 2023, the bot executed hundreds of thousands of such attacks, according to Crypto Briefing. Gross revenues hit between $34 million and $40 million during peak three-month windows. Net profits topped $6 million after gas costs. By mid-2024, the bot was spending more than 210 ETH — roughly $810,000 — on gas in a single day.
In August 2024, researchers at EigenPhi identified an upgraded version called "Jared 2.0." It used advanced multi-hop routing and processed over 85,000 transactions in its first months, per Crypto Briefing. Between November 2024 and October 2025, this version was responsible for 70% of all sandwich attacks on Ethereum.
Just weeks before the exploit, in May 2026, the bot ran a sandwich attack against a token swap by Ethereum co-founder Vitalik Buterin. It used over $1.14 million in WETH volume to front-run his trade. The exploit on June 20 came shortly after, with Crypto Briefing describing the outcome as "the hunter becoming the hunted."
After confirming the loss, the developer offered a $1 million bounty for the return of funds, promising "complete confidentiality," according to KuCoin News. The offer signals the developer does not expect to recover funds through legal channels. The attacker has shown no sign of responding.
The estimated total varies by source. Crypto Briefing and the developer put it at $15 million-plus. Bitget reported $7.5 million based on specific token receipts. SolanaFloor placed the figure as high as $17 million. All accounts agree the bot was compromised and funds moved fast. The use of Tornado Cash to launder 1,000 ETH adds pressure on regulators already pushing to ban privacy mixers, per Crypto Briefing.
Publishers
10
Articles
2
Reach
12