JaredFromSubway—one of Ethereum’s most recognizable MEV bots—was caught in an unusual exploit that drained roughly $7.5 million in WETH, $USDC, and $USDT. Blockchain security firm Blockaid detailed the incident in a security report covered by WuBlockchain, framing it as a novel attack on the bot’s decision-making logic rather than a traditional smart contract vulnerability. The loss reshapes how automated trading infrastructure on Ethereum will need to defend itself.
The attacker deployed contracts that tricked JaredFromSubway’s automated systems into granting token approvals. Once those allowances were in place, the exploiter siphoned off the bot’s WETH, $USDC, and $USDT holdings. There was no phishing attack and no flaw in the deployed smart contracts. Blockaid clarified that the incident exploited “the bot’s automated MEV opportunity detection and approval mechanism,” a category of risk that has received far less attention than code audits.
That distinction matters a lot. The bot’s own logic—the part that evaluates pending transactions and decides whether to frontrun, backrun, or sandwich a trade—made a sequence of decisions that gave the attacker a foothold. Because the approvals were granted inside the bot’s normal workflow, the standard safeguards that wallets and protocols use against human users simply did not apply. JaredFromSubway had been running successfully for years on Ethereum, where MEV has become a specialized and highly competitive business. The network remains the dominant chain for DeFi, as recent data on developer activity across top blockchains confirms, which means bots like this one are handling enormous volumes of value daily.
blockchainreporter.net