Newsroom
22 June, 2026 / News / AI / 635 reads / Tags: mev, jaredfromsubway, weth, attacker, sandwich

A sophisticated multi-week exploit targeted the Ethereum sandwich bot, resulting in the loss of millions in WETH, USDC, and USDT. The operator has offered a bounty and signaled plans for legal action
On June 20, 2026, the Ethereum address tied to the well-known MEV bot jaredfromsubway.eth suffered a significant drain estimated at $7.5 million. Security researchers from Blockaid and on-chain analysts tracked the incident, confirming the transfer of substantial holdings in wrapped Ether, USD Coin, and Tether to attacker-controlled addresses.
The bot, active since early 2023, specializes in sandwich attacks on decentralized exchanges. This strategy involves placing trades around user transactions to extract value, a common but controversial MEV practice. The attacker essentially turned the bot's own approval mechanisms against it through careful preparation over several weeks.
According to detailed forensic analysis, the attacker created contracts that behaved differently based on transaction size. Small interactions performed as expected, delivering minor profits to the bot and encouraging continued engagement. However, the malicious contracts were designed to maintain open approvals rather than revoking them after use.
On-chain data showed the final large withdrawal occurring around 6:49 PM UTC. The attacker then moved portions of the funds through Tornado Cash to obscure the trail.
The operator of jaredfromsubway.eth posted an on-chain message offering a 50% white hat bounty for the return of 2,150 ETH within 48 hours. They warned of pursuing legal remedies and involving law enforcement if the deadline passed without recovery. Some observers noted the irony given the bot's history of profiting from user transactions.
Community reactions mixed amusement with recognition of the sophisticated counter-MEV tactic. While one X account associated with the bot claimed a higher loss figure and offered a bounty, analysts confirmed the verified amount at approximately $7.5 million.
This incident highlights vulnerabilities in automated trading systems that rely heavily on token approvals. Even experienced MEV operators can fall victim to targeted social engineering through smart contract interactions. The event underscores ongoing risks in decentralized finance, where participants on both sides employ advanced tactics.
MEV activities, including sandwiching, remain a point of discussion in the Ethereum ecosystem. While they provide liquidity and arbitrage opportunities, they can also increase costs for regular users. The jaredfromsubway.eth bot had built a reputation as one of the most active in this space.
| Asset | Approximate Amount Drained |
|---|---|
| WETH | 1,474 |
| USDC | 2.87 million |
| USDT | 2 million |
| Total Value | $7.5M+ |









