An attacker stole between $7.5 million and $15 million from jaredfromsubway.eth, the Ethereum address associated with one of the network’s most active sandwich-attack bots, by exploiting the bot’s automated trading logic rather than a flaw in Ethereum itself. Researchers said the attacker spent weeks preparing the operation, deploying 66 fake token contracts and sham liquidity pools designed to resemble assets such as WETH, USDC, and USDT, then feeding the bot false trading opportunities that caused it to approve attacker-controlled helper contracts.
After testing the setup with earlier benign transactions, the attacker used the preserved token allowances to execute a sweep transaction and drain real assets with transferFrom, routing at least some of the proceeds through Tornado Cash while retaining the rest in attacker-controlled wallets. The incident has been described as a targeted operational failure of the bot, which had been linked to a large share of Ethereum sandwich attacks, and the operator reportedly responded by offering a bounty that rose from $3 million to $7.5 million in exchange for the partial or full return of the stolen funds while also pursuing talks with a white-hat group.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
JaredFromSubway later increased the offer to $7.5 million in exchange for the return of half of the stolen amount, and was also reportedly negotiating with a white-hat hacking group.
Following the theft, JaredFromSubway reportedly offered the attacker a $3 million bounty in exchange for the full return of the stolen funds.
After the theft, some of the stolen cryptocurrency was reportedly sent through Tornado Cash, while the remainder stayed in attacker-controlled addresses.
Over the weekend, the attacker used previously obtained approvals to execute a sweep transaction that drained real WETH, USDC, and USDT from contracts controlled by the JaredFromSubway MEV bot. The reported loss was described as more than $7.5 million by one source and about $15 million by another.
According to Blockaid, the attacker spent several weeks deploying 66 fake token contracts and sham liquidity pools designed to mimic assets such as WETH, USDC, and USDT in order to manipulate the JaredFromSubway bot's automated approval logic.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
chainalysis.com
Open sourcexakep.ru
Open sourcescworld.com
Open sourcethedefiant.io
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.