Jaredfromsubway.eth, the MEV bot responsible for 70% of sandwich attacks on Ethereum between November 2024 and October 2025, was exploited for more than $7.5 million on Saturday. According to Blockaid, an attacker tricked the bot's automated execution system into granting token approvals to attacker-controlled contracts, which were then used to drain funds. The attacker created fake wrapper tokens and liquidity pools — including fake Wrapped Ether, fake USDC, and fake USDt routes paired with fake Cap — designed to look like profitable MEV opportunities, triggering the bot to approve helper contracts to spend real WETH, USDC, and USDT. The approvals remained open instead of being consumed in the trade, allowing the attacker to sweep the funds via transferFrom. Blockaid said this is not a phishing attack or a traditional smart-contract vulnerability.
This matters because it confirms a narrow technical risk in MEV execution systems, not a broader DeFi contagion vector. The exploit targets a specific bot's automation, not shared infrastructure. Jaredfromsubway.eth operated independently, and the loss does not appear to cascade to other protocols or drain liquidity pools used by retail traders. Cointelegraph Research previously found that sandwich attacks on Ethereum result in about $60 million in annual losses for traders.
For traders, this suggests background noise in the broader DeFi security narrative, not a catalyst. The market snapshot shows funding at baseline levels (BTC $64,235, funding +0.1bp/8h with 30d avg +0.1bp) and Fear & Greed at 23 Extreme Fear (30d avg 19), indicating risk-off conditions. MEV bots operate in a separate layer from the protocols most traders interact with, and this exploit does not obviously change the risk profile for holding ETH or using major DeFi platforms. The event may generate short-term social media attention — crypto investor David Gokhshtein said that anyone ever sandwiched by the bot is likely not upset — but sentiment does not necessarily translate to a tradable setup when the affected entity is a parasitic bot rather than a retail-facing protocol.
The specific thing to watch next is whether other high-volume MEV bots adjust their approval logic in response to this attack vector. If similar exploits surface across multiple bots in the coming weeks, it would suggest a new category of vulnerability in automated trading systems. For now, this appears to be a one-off event targeting a single operator's automated system.
Source: CoinTelegraph
