On Saturday, Blockaid stated the attack was not a phishing attack, nor was it a vulnerability in the smart contract of Jaredfromsubway.eth. Instead, it was an attack against the automated decision-making system of the MEV bot. That same system is responsible for identifying and executing profitable MEV trades. According to Blockaid's Chief Technology Officer Raz Niv, the incident was a "counter-MEV honeypot attack." This means that the attacker created a honeypot specifically designed for MEV bots. For several weeks leading up to the attack, the attacker reportedly deployed 66 fake token contracts. Each contract mimicked the name and interface of a major crypto asset (i.e., WETH, USDC and USDT). Afterward, the attacker linked these fake tokens to fake liquidity pools that offered seemingly attractive trading opportunities.
The entire setup was structured in a manner that appeared identical to the types of transactions that Jaredfromsubway.eth would typically pursue. When Jaredfromsubway.eth interacted with the fake contracts, it granted authorization to helper contracts controlled by the attacker to transact with its real assets. Put simply, Jaredfromsubway.eth authorized the attacker to access its funds. "In a bizarre twist of fate, the bot gave the attacker millions in its treasury," Niv remarked. Why the Jaredfromsubway.eth MEV Bot Exploit is Important to Ethereum Users.
Earlier coverage: New York Judge Delays Hearing On Aave’s Request To Unfreeze $71M In ETH
Jaredfromsubway.eth has become arguably one of the most recognizable MEV bots on Ethereum due to its involvement in sandwich attacks. Maximal Extractable Value (MEV) is defined as profit that may be obtained by reordering, adding or removing transactions from the blockchain prior to confirmation. In a sandwich attack, a bot executes two trades surrounding a user's trade. The first trade is executed immediately before the user's trade, and the second trade is executed immediately after. Oftentimes, this results in the user receiving a lower price for their asset than what they would have received if the bot did not intervene, and the bot gains from the resulting price fluctuation. For ordinary DeFi users, MEV is often perceived as an additional expense related to executing trades on decentralized exchanges. In a previous study conducted by Cointelegraph Research, it was estimated that sandwich attacks on Ethereum resulted in approximately $60 million in lost revenue for traders annually.
Additionally, between November 2024 and October 2025, there were reportedly between 60,000-90,000 sandwich attacks executed on Ethereum each month. Approximately 70% of those attacks were executed using Jaredfromsubway.eth. Funds Sent to Tornado Cash As indicated by on-chain data, some of the stolen funds have already been deposited into Tornado Cash. Tornado Cash is a crypto mixer that enables users to execute anonymous transactions on the blockchain.
The use of a mixer could potentially complicate efforts to recover the stolen funds; however, investigators and blockchain analytics providers will continue to monitor wallet activity associated with the stolen funds. A Rare Occurrence for a Prominent MEV Bot It is uncommon for MEV bots to experience such exploits since they are typically the parties who exploit or profit from DeFi trading activities. Jaredfromsubway.eth has been operational for years and has reportedly generated millions through its automated MEV strategies. As such, Jaredfromsubway.eth has become synonymous with sandwich attacks on Ethereum, thus making the exploit noteworthy within the broader crypto community. In May, Vitalik Buterin, co-founder of Ethereum, was sandwich-attacked by Jaredfromsubway.eth while exchanging **26,544 DigitalBits**.
Although the value of these DigitalBits was negligible at the time (only a few dollars), Buterin experienced negligible losses.
Nonetheless, the incident exemplified how MEV bots can target even minimal transactions. After the recent exploit occurred, crypto investor and commentator "David Gokhshtein" commented that although people should not rejoice in Jaredfromsubway.eth's misfortune, many users who have been negatively impacted by Jaredfromsubway.eth will probably not be displeased by the news. Quick Takeaway: Jaredfromsubway.eth, one of Ethereum's most prolific sandwich attack bots, was drained for more than $7.5 million. The attacker utilized fake tokens and fake liquidity pools to deceive the bot into authorizing contracts that subsequently stole its funds. The incident exemplifies how even highly profitable MEV bots can be vulnerable to manipulation of their automated systems.
