Thread about the JaredFromSubway MEV bot exploit
1/ Insane exploit on one of Ethereum’s most notorious MEV bots.
JaredFromSubway.eth — the sandwich attack bot that has extracted tens of millions from traders since 2023 — just got drained for ~$7.5M+ in one of the cleanest and most sophisticated attacks I’ve seen.
No contract vulnerability. No phishing. The bot essentially approved its own robbery.
2/ Here’s exactly how it happened:
The attacker didn’t hack the bot’s code. Instead, they weaponized the bot’s own logic against it.
They deployed:
* Fake wrapper tokens (fWETH, fUSDC, fUSDT)
* Fake liquidity pools on DEXes that looked highly profitable for arbitrage/sandwich opportunities
3/ The bot, constantly scanning for MEV opportunities, spotted these fake pools and thought it had found a juicy trade.
As part of its normal automated process, it granted approval to attacker-controlled helper contracts to spend its tokens.
In early test transactions, these approvals were actually used (small amounts), so nothing looked suspicious.
4/ Then came the critical part:
In later transactions, the bot granted large approvals that were never consumed or revoked.
This gave the attacker unlimited spending power over the bot’s funds through those helper contracts.
5/ Once enough approvals were in place, the attacker executed the final drain using transferFrom.
They pulled large amounts of WETH, USDC, and USDT directly from the JaredFromSubway contract.
Example from on-chain data:
* Multiple transfers of ~92 WETH
* Multiple transfers of ~143k USDC
* Multiple transfers of ~149k USDT
All going to the attacker’s helper address: 0x3e37f4A10d771Ba9dE44b6d301410b1BEdeA65d0
6/ The bot’s address (for verification):
jaredfromsubway.eth → 0xae2fc483527b8ef99eb5d9b44875f005ba1fae13
Arkham Intelligence tracked the hit across 95 addresses. The bot’s balance reportedly dropped from ~$25M to ~$4.4M.
Some funds were later moved through Tornado Cash.
7/ Why this attack was so effective:
MEV bots are designed to act fast and trust opportunities that look profitable. This attacker created a fake opportunity that perfectly matched what the bot was programmed to chase.
The exploit turned the bot’s automation and lack of strict approval management into a liability.
8/ Key takeaway:
Even sophisticated MEV bots (and their operators) must be extremely careful with token approvals.
Always revoke unused approvals.
This applies to regular users and automated bots alike.
This attack is a masterclass in social engineering on-chain — no code was broken, only trust and automation were exploited.
The hunter became the hunted.
What are your thoughts on this exploit? Have you seen similar approval-based attacks before?
@MartyDiclemente@CarterDillonNFL@tr_walsh You literally missed the point of the OP. If the refs wanted to 'give the broncos the game', they would have called holding in the end zone which would have resulted in a safety and the Broncos the win. At that point none of the stuff you mentioned even happens.
@jayjaymarinn @HighIQSportsGuy @Its_Strez You mean the one where Cook stutter steps back into the Moss and takes himself out of the he play instead of continuing to smoke him and running through the catch?
@DeniseRiedel4@AnnieAgar If they wanted to rig the game, the could have easily just called holding in the end zone on Buffalo in OT and ended the game with a safety. Weird that they wouldnt if they wanted to rig the game, would have been much less controversy.
@EthanBrady5346@jadenking9@BUFonWECK@harryplopper__ If he keeps running Moss is already smoked at that point. Again he took himself out of the play but not running through. Crying on the Internet about it ain't gonna change Cooks decision.
@MUTheadTy@EpicNormie__ After all the annoying shit Packers fans have been saying all week? Sit down in the corner and cry to yourself. Try to keep it down though, we got stuff going on.
My favorite part of AI is that you can ask it to do something, and it can say that it doesn't have the resources to do what you are asking.
Then you just tweak the prompt and it ends up giving you what you want.
Turns out you did have the resources.