Ethereum's biggest 'sandwich' bot drained of $7.5 million in ironic exploit
CoinDesk 2026-06-21 07:12:35
Context: An attacker drained over $7.5 million from the Ethereum MEV bot jaredfromsubway.eth by exploiting its automated trading logic. The bot, known for sandwich attacks, had been responsible for roughly 70% of Ethereum sandwich attacks, which cost traders about $60 million a year. The incident highlights the risks of industrialized sandwich-bot activity on Ethereum.
Key Facts
- An attacker tricked jaredfromsubway.eth into approving fake trading routes, then used those approvals to drain WETH, USDC, and USDT, resulting in a loss of over $7.5 million.
- The attacker spent several weeks setting up the exploit, deploying dozens of fake token contracts and fake liquidity pools that mimicked assets like WETH, USDC, and USDT.
- Security firm Blockaid stated that the incident was not a normal phishing attack and not a simple bug in the victim contract, but rather a targeted attack on the bot's decision-making system.
- Jaredfromsubway.eth has been responsible for roughly 70% of Ethereum sandwich attacks, which cost traders about $60 million a year, with 60,000 to 90,000 attacks per month between November 2024 and October 2025.
- Some of the stolen funds were later sent to Tornado Cash, according to on-chain data reviewed by CoinDesk.