Crypto & Web3·Jun 22, 2026

Ethereum MEV Bot JaredFromSubway Threatens Legal Action After $7.5 Million Loss

In brief Jaredfromsubway, a well-known trading bot, fell victim to a series of transactions that left its logic exposed to malicious behavior. The trading bot has developed a reputation for so-called sandwich attacks, but it was abused by f

Decrypt3 min readVerified
Ethereum MEV Bot JaredFromSubway Threatens Legal Action After $7.5 Million Loss
Image · Decrypt
The gist
5-point summary · 1 min

In brief Jaredfromsubway, a well-known trading bot, fell victim to a series of transactions that left its logic exposed to malicious behavior. The trading bot has developed a reputation for so-called sandwich attacks, but it was abused by f

  • In brief Jaredfromsubway, a well-known trading bot, fell victim to a series of transactions that left its logic exposed to malicious behavior.
  • The trading bot has developed a reputation for so-called sandwich attacks, but it was abused by fake tokens and fraudulent smart contracts.
  • Jaredfromsubway’s operator offered the attacker a bounty, yet a portion of the stolen funds had been transferred to Tornado Cash.
  • In an on-chain message, they offered a “50% white hat bounty” for the return of 2,150 Ethereum, currently valued at roughly $3.7 million, within the next 48 hours.
  • You can't make this up 💀 The wallet that owns metamask.eth had something to say to JaredFromSubway regarding his recent onchain bounty request.
$7.5 Million$3.7 million50%
In this article

In brief Jaredfromsubway, a well-known trading bot, fell victim to a series of transactions that left its logic exposed to malicious behavior. The trading bot has developed a reputation for so-called sandwich attacks, but it was abused by fake tokens and fraudulent smart contracts. Jaredfromsubway’s operator offered the attacker a bounty, yet a portion of the stolen funds had been transferred to Tornado Cash. A well-known trading bot took a notable hit this weekend after it fell victim to a series of transactions that left its logic exposed to malicious behavior.The $7.5 million attack, which took place on Saturday, marked a sudden setback for “jaredfromsubway” and the formula it has used to quietly notch profits on Ethereum for years.The trading bot has been credited with perfecting the so-called sandwich attack. The strategy is widely viewed as a form of market manipulation on decentralized exchanges, involving trades that are placed around pending transactions and hurt price execution.Essentially, an attacker presented jaredfromsubway with misleading opportunities that later allowed the bad actor to drain legitimate funds, according to security firm Blockaid. The scheme boiled down to fake tokens and fraudulent smart contracts, Blockaid added in an X post.Jaredfromsubway is designed to continuously scan for profitable trades, and in order to act on them, it occasionally needs to provide entities with permission to move funds on its behalf.Some transactions that jaredfromsubway engaged in revoked those powers as soon as they were completed, while the ones that were crafted later by the attacker didn’t. “That left attacker-controlled spenders armed,” Blockaid explained.Although the crypto industry has developed several services to prevent sandwich attacks, entities like jaredfromsubway are viewed, in some ways, as unavoidable. However, Saturday’s attack showed that the trading bot’s logic is far from infallible.The trading bot’s operator appeared to recognize this. In an on-chain message, they offered a “50% white hat bounty” for the return of 2,150 Ethereum, currently valued at roughly $3.7 million, within the next 48 hours. Otherwise, the individual behind the bot threatened to pursue legal remedies and involve law enforcement. You can't make this up 💀 The wallet that owns metamask.eth had something to say to JaredFromSubway regarding his recent onchain bounty request. There's virtually no chance the person or group behind the exploit takes the bounty, and there's also no chance Jared pursues legal… https://t.co/bSDkGZJ4Ik pic.twitter.com/3Xhx0YKH2T — zubic (@ ) June 22, 2026“Finally, someone punished the infamous sandwich attacker,” an onlooker remarked on X. “People don't die without experiencing what they've inflicted on others.”Sandwich attacks fall under the umbrella of Maximal Extractable Value (MEV). Coined in 2019, the term refers to validators and other participants who are able to generate profits by reordering transactions before they are finalized.Following the exploit on Saturday, the attacker appeared to begin covering their tracks.Security firm PeckShield noted in an X post that—after stealing wrapped Ethereum and stablecoins—a portion of the funds was swapped and partially deposited in Tornado Cash, a common resource for attackers trying to obscure the flow of ill-gotten gains.Daily Debrief NewsletterStart every day with the top news stories right now, plus original features, a podcast, videos and more.

Integrity note  ·  Xela does not rewrite or paraphrase article content. The excerpt above is the source publication's own words, sanitized for display. For the full piece — including any quotes, charts, or images — read it at Decrypt. Xela's rewritten version is off for this story, so there's no editorial angle attached — you're getting the source's reporting unfiltered. When the rewrite is on, we add a What this means block underneath with the operator/trader takeaway.

What people are saying

Discussion

Hot takes

0/280

Loading takes…

Comments

Discussion · 0

Sign in to comment, like, and save articles.

Sign in

Loading comments…

Newsletter

Track crypto & web3 every morning.

Daily digest tuned to this beat. The 5 stories most worth your time. Unsubscribe anytime.