
A major Ethereum-based MEV bot known as Jaredfromsubway.eth has suffered losses exceeding $7.5 million after falling victim to a carefully planned attack that exploited weaknesses in its automated trading logic.
Details released on June 21 revealed that the incident was not caused by phishing, wallet theft, or a smart contract exploit but by a highly specialised strategy designed to manipulate the bot’s decision-making process.
Blockchain security firm Blockaid described the event as a reverse MEV honeypot attack aimed specifically at exploiting how MEV bots identify and execute profitable opportunities.
The attacker reportedly spent several weeks preparing the operation by deploying 66 counterfeit token contracts and fraudulent liquidity pools across the network.
These fake pools were structured to resemble widely used digital assets, including WETH, USDC and USDT, creating the appearance of legitimate and lucrative trading opportunities.
By presenting transactions that appeared highly profitable, the attacker successfully encouraged the bot to interact with malicious infrastructure under the adversary’s control.
The deceptive setup ultimately convinced the automated system to approve a harmful auxiliary contract without detecting the hidden risks embedded within the transaction flow.
After securing the necessary permissions, the attacker initiated a final transaction that activated concealed mechanisms built into the malicious contracts.
Those mechanisms enabled the transfer of assets from the bot’s wallet, resulting in the theft of Ethereum and multiple stablecoin holdings.
The breach highlights growing concerns about the risks associated with highly automated trading systems operating in decentralised finance environments.
Historical network data shows sandwich attacks remained a significant feature of Ethereum trading activity between November 2024 and October 2025.
During that period, the Ethereum blockchain recorded an estimated 60,000 to 90,000 sandwich attacks each month on average.
Data from the organisation indicated that roughly 70% of those attacks were linked to activity associated with Jaredfromsubway.eth.
The bot gained notoriety for consistently dominating Ethereum sandwich trading strategies and became one of the most recognisable participants in the MEV ecosystem.
Its influence extended across a large portion of network activity, making the latest exploit one of the most notable incidents involving an MEV operator in recent months.
The development also follows an earlier incident involving Ethereum co-founder Vitalik Buterin, who was reportedly affected by the same bot’s sandwich trading activity during a DigitalBits transaction completed in May.
The attack demonstrates how sophisticated adversaries are increasingly turning advanced automation against the very systems designed to exploit market inefficiencies.
Security researchers said the incident serves as a reminder that even dominant automated trading operations can become vulnerable when attackers successfully manipulate the assumptions built into their execution models.
At the time of reporting, Ethereum price was $1,735.08.