Ethereum's biggest 'sandwich' bot drained of $7.5 million in ironic exploit

Ethereum's biggest 'sandwich' bot drained of $7.5 million in ironic exploit

Source: CoinDesk

Published:07:12 UTC

BTC Price:$64255.0

#eth #defi #mev

Analysis

Price Impact

Low

The exploit targeted a specific mev bot and not the ethereum network or its native token directly. while it highlights risks within defi, the direct impact on eth price is likely minimal.

Trustworthiness

High

Price Direction

Neutral

The event is an internal defi exploit within the ethereum ecosystem and doesn't directly affect the broader market sentiment or fundamentals of eth.

Time Effect

Short

The exploit happened recently, but its impact on price is expected to be short-lived as it doesn't represent a systemic risk to the ethereum network.

Original Article:

Article Content:

Tech Ethereum's biggest 'sandwich' bot drained of $7.5 million in ironic exploit Blockaid said an attacker tricked Jaredfromsubway.eth into approving fake trading routes, then used those approvals to drain WETH, USDC and USDT. By Shaurya Malwa Jun 21, 2026, 7:12 a.m. 3 min read Make preferred on Share Share this article Copy link X icon X (Twitter) LinkedIn Facebook Email Make preferred on Summary Show An attacker drained more than $7.5 million from the notorious Ethereum MEV bot jaredfromsubway.eth by exploiting its automated trading logic rather than a traditional contract bug or phishing scam. Over several weeks, the attacker lured the bot into approving malicious helper contracts via fake tokens and liquidity pools that mimicked assets like WETH, USDC and USDT, then used those open approvals to pull funds and route some through Tornado Cash. The incident underscores both the scale and risks of industrialized sandwich-bot activity—jaredfromsubway.eth has been responsible for roughly 70% of Ethereum sandwich attacks, which cost traders about $60 million a year—by showing how machine-speed, pattern-based systems can themselves be turned into victims. Jaredfromsubway.eth, one of Ethereum’s most infamous MEV bots, has been drained for more than $7.5 million after an attacker turned the bot’s own automated trading logic against it. The bot is known for sandwich attacks, a form of maximal extractable value, or MEV, in which an automated trader spots a pending transaction, buys ahead of it, lets the victim trade at a worse price, then sells immediately after. The result is a small hidden tax on users that can add up across thousands of trades. Sandwich attackers aren’t typically a form of exploit but are looked upon in crypto circles as a type of predatory behavior, which skims value from users, leads to a spike in gas fees and doesn’t benefit either the network or the user. Security firm Blockaid said Saturday’s incident was not a normal phishing attack and not a simple bug in the victim contract. The attacker instead targeted the bot’s decision-making system. The setup was built over several weeks, where the attacker deployed dozens of fake token contracts and fake liquidity pools - a term for a pile of tokens locked on a decentralized exchange - that looked like profitable trades. Some mimicked familiar assets such as wrapped ether (WETH), and dollar-pegged stablecoins USDC and USDT. That bait did what it was supposed to do. Jaredfromsubway.eth’s bot saw what looked like MEV opportunities and generated approvals for attacker-controlled helper contracts to spend tokens on its behalf. Those approvals were used immediately as part of the trade in earlier tests, but later, the attacker created routes where the approvals stayed open. This left the attacker with standing permission to pull funds. And they used those open approvals to transfer WETH, USDC and USDT out of Jaredfromsubway.eth’s contracts, draining more than $7.5 million. Some of the stolen funds were later sent to Tornado Cash, onchain data reveiwed by CoinDesk showed. The irony was hard to miss, meanwhile. Jaredfromsubway.eth has long been one of the most visible symbols of toxic MEV on Ethereum. Sandwich attacks cost Ethereum traders about $60 million a year, with 60,000 to 90,000 attacks per month between November 2024 and October 2025. Roughly 70% of those attacks were associated with Jaredfromsubway.eth, who has been active since early 2023 . CoinDesk reported in May that the same bot had even sandwiched a small swap by Ethereum co-founder Vitalik Buterin. It put up $1.14 million to frontrun Buterin's trade to make just $4 (after fees, the bot a few dollars money on this particular trade). The trade was worth only a few dollars, and the loss was tiny, but it showed how industrialized the bot had become. It was scanning the mempool for nearly anything it could insert itself around. While Saturday's incident does not make sandwich attacks less harmful, but it does show the risk of running systems that approve transactions at machine speed based on pattern recognition and profit signals. Jaredfromsubway.eth spent years profiting from traders who did not see the bot coming. But on Saturday, the bot did not see the trade coming either. Latest Crypto News 1 Bitcoin holds near $64,000 as a renewed Hormuz threat clouds US-Iran ceasefire talks 26 minutes ago 2 AI is making crypto security cheaper, faster and harder to ignore 16 hours ago 3 How STRC lost its par: The timeline behind Strategy's preferred-stock meltdown 18 hours ago 4 Schwab to join prediction markets race with S&P 500 event-based options: WSJ Jun 19, 2026 5 GoMining challenges Jack Dorsey's Square with payments system designed around bitcoin Jun 19, 2026 6 Franklin Templeton proposes new ETFs that turn corporate dividends into bitcoin Jun 19, 2026 7 Smart-contract and DeFi coins lead losses as bitcoin wilts for 4th straight day Jun 19, 2026 8 Digital credit market hit by huge selloff as Strive CEO blames leverage liquidations Jun 19, 2026 9 Microsoft found malware that hijacks crypto wallets and spreads through USB sticks Jun 19, 2026 10 XRP falls 3% after losing $1.15 support as breakout attempt fades Jun 19, 2026 Latest Research CEX Volumes Drop to Lowest Since September 2024 as RWA Perps Hit Record High CEX Volumes Drop to Lowest Since September 2024 as RWA Perps Hit Record High In May, combined exchange volumes fell 3.45% to $4.41T; the lowest since September 2024. RWA perpetual futures volumes rose 10.4% against the trend, hitting a new all-time high. By CoinDesk Research Jun 15, 2026 In May, combined exchange volumes fell 3.45% to $4.41T; the lowest since September 2024. RWA perpetual futures volumes rose 10.4% against the trend, hitting a new all-time high. Why it matters : In May, combined exchange volumes fell 3.45% to $4.41T; the lowest since September 2024. RWA perpetual futures volumes rose 10.4% against the trend, hitting a new all-time high. View Full Report More From Tech AI is making crypto security cheaper, faster and harder to ignore Microsoft found malware that hijacks crypto wallets and spreads through USB sticks Ethereum Foundation loses another key leader as co-executive director Hsiao-Wei Wang resigns