An attacker drained more than $7.5 million from jaredfromsubway.eth, one of Ethereum's most infamous MEV bots, by tricking the automated system into approving malicious helper contracts over several weeks. According to security firm Blockaid, the attacker deployed fake tokens and liquidity pools designed to mimic assets such as wrapped ether (WETH) and dollar-pegged stablecoins USDC and USDT. The bot's automated logic treated these as MEV opportunities and granted approvals to attacker-controlled helper contracts, which were later used to pull WETH, USDC and USDT directly from the bot's contracts. Some of the stolen funds were later sent to Tornado Cash, per onchain data reviewed by CoinDesk.

This matters because it exposes the limits of machine-speed trading systems that rely on pattern recognition without deeper validation. Jaredfromsubway.eth has been responsible for roughly 70 percent of Ethereum sandwich attacks, with 60,000 to 90,000 attacks per month between November 2024 and October 2025. Sandwich attacks cost Ethereum traders about $60 million a year. The bot has been active since early 2023. The incident suggests that even dominant MEV extractors can be vulnerable when their decision-making is entirely mechanical—the attacker exploited the bot's own automated approval logic rather than a contract vulnerability or phishing vector.

For traders, this is a DeFi operational failure contained to one sophisticated actor, not a network-level vulnerability. The exploit did not involve Ethereum base-layer contracts, shared bridges, or cross-protocol collateral systems. Sandwich bots like jaredfromsubway.eth operate outside the core DeFi protocols that underpin liquidity provisioning and lending markets, suggesting the $7.5 million loss does not cascade into liquidations or affect protocol solvency elsewhere. Funding on BTC perpetuals sits at +0.3 basis points per eight hours, just above the 30-day average of +0.1 basis points, and the Fear and Greed Index reads 23 (extreme fear), marginally above the 30-day average of 19. Market conditions reflect broader macro caution, not a DeFi-specific flight to safety.

Watch for any secondary disclosures around whether other MEV bots used similar approval structures. If multiple bots surface with the same open-approval vulnerability, that would widen the risk surface and potentially trigger a broader retreat from automated MEV strategies. For now, this remains a single-operator failure with no clear read-through to ETH or BTC spot positioning.

Source: CoinDesk