Jaredfromsubway.eth, Ethereum's most prolific sandwich-attack bot, lost more than $7.5 million after an attacker exploited the bot's own trading logic, according to security firm Blockaid. The bot is designed to detect pending transactions, front-run them with its own swap, force victims into worse prices, then unwind for profit. This time, it became the victim.

The attacker's method was straightforward: create fake token contracts and liquidity pools that looked like MEV opportunities. Over several weeks, Blockaid found that counterfeit versions of fWETH, fUSDC, and fUSDT paired with fake fCAP tokens were presented to the bot as profitable routes. The bot, reading these as legitimate trades, granted spending approvals to attacker-controlled helper contracts.

The trap worked in layers. Early test routes consumed some approvals immediately, but later ones deliberately left token allowances open. That left standing authorization for the attacker to call transferFrom and drain WETH, USDC, and USDT directly from the bot's wallet. Blockaid said the bot granted roughly 92.16 WETH to one helper contract before the final sweep pulled funds across multiple stablecoin routes. CoinDesk reported that part of the proceeds were later routed through Tornado Cash.

Jaredfromsubway.eth has been active since early 2023 and is responsible for roughly 70% of sandwich attacks on Ethereum. Blockaid and other researchers estimate sandwich attacks cost Ethereum traders about $60 million annually. The bot once spent $1.14 million in gas and MEV fees to front-run a Vitalik Buterin swap worth only a few dollars in profit, showing how aggressively it hunts for any edge.

On June 22, the Jaredfromsubway wallet posted an on-chain message offering the attacker a 50% white-hat bounty to return 2,150 ETH within 48 hours, then threatened legal and law-enforcement action. The incident echoes a 2023 attack in which a rogue validator extracted $25 million from sandwich bots using similar social engineering tactics.