Ethereum's well-known mezzanine bot was exploited, resulting in a $7.5 million loss.
CoinDesk
7h ago
Ai Focus
The well-known Ethereum MEV bot jaredfromsubway.eth was found to have over $7.5 million stolen after approving a fake transaction path; some of the funds subsequently flowed into Tornado Cash.
Helpful
No.Help

The well-known Ethereum MEV bot jaredfromsubway.eth was recently compromised by attackers who exploited its automated trading logic, resulting in a loss of over $7.5 million. Security firm Blockaid stated that this incident was neither a traditional contract vulnerability nor a common phishing attack; rather, attackers used counterfeit tokens and liquidity pools to trick the bot into granting token authorization to a malicious auxiliary contract.

The attack was planned over several weeks.

According to Blockaid, the attackers deployed dozens of fake token contracts and fake liquidity pools over several weeks. These objects were packaged as seemingly profitable trading opportunities, and some even mimicked common assets such as WETH, USDC, and USDT.

Once the bot on jaredfromsubway.eth identifies these "opportunities," it automatically generates authorizations that allow related auxiliary contracts to use funds on its behalf. In early tests, these authorizations were used instantly during the transaction process; however, in a later design, attackers constructed paths where the authorizations remained valid.

Open licensing was used to transfer assets.

Once the authorizations persisted, the attackers gained continuous access to the funds. They then used these open authorizations to transfer WETH, USDC, and USDT from contracts controlled by jaredfromsubway.eth, totaling over $7.5 million.

On-chain data reviewed by CoinDesk shows that some of the stolen funds were subsequently transferred to Tornado Cash. The report did not mention whether the funds have been frozen or recovered.

  • Assets involved: WETH, USDC, USDT
  • Losses: Over $7.5 million
  • Partial destination of funds: Tornado Cash

MEV robots are hit by automation logic.

jaredfromsubway.eth is one of the most well-known mezzanine attack bots on Ethereum. A mezzanine attack involves a bot buying a stock before the user completes their transaction, then quickly selling it at a lower price to profit from the difference. While the loss per transaction may be small, it can create a hidden cost for the user in the long run.

The report cited data showing that between November 2024 and October 2025, Ethereum experienced approximately 60,000 to 90,000 mezzanine attacks per month, resulting in annualized losses of approximately $60 million for traders. About 70% of these attacks were related to jaredfromsubway.eth.

CoinDesk previously reported that this bot even performed a mezzanine operation on a small exchange by Ethereum co-founder Vitalik Buterin. At the time, it invested approximately $1.14 million in the frontrunner trade, ultimately only gaining about $4. This reflects the system's high level of automation, involving a wide-ranging scan of the mempool for insertable transactions.

This incident did not change the harm that mezzanine attacks cause to users, but it revealed another layer of risk: when a trading system relies on machine speed, pattern recognition, and automatic authorization of profit signals, this mechanism itself can also be exploited in reverse.

Tip
$0
Like
0
Save
0
Views 766
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Aztec Network's overpass was exploited, resulting in a loss of approximately $2.16 million.
Aztec Network's Private Rollup Bridge was exploited, with on-chain data showing a loss of approximately $2.16 million, involving ETH, DAI, and renBTC.
U.Today
·2026-06-18 20:21:15
916
A liquidity pool on BNB Chain was exploited, resulting in a loss of approximately $1.11 million.
The OLPC/LABUBU pool on the BNB Chain was exploited, with attackers using distorted reserves to withdraw LABUBU at a low price, resulting in a loss of approximately $1.11 million.
AMBCrypto
·2026-06-21 20:24:18
545
Jared from Subway MEV robot attacked, resulting in approximately $7.5 million in losses.
AMBCrypto reports that the Jaredfromsubway.eth-related MEV bot was attacked, resulting in a loss of approximately $7.5 million, exposing permission security risks in DeFi automated trading.
AMBCrypto
·2026-06-21 19:23:58
129
Aztec's old contract suffered two attacks within three days, resulting in losses exceeding $4 million.
Aztec's two deactivated old contracts were attacked twice within three days, resulting in a total loss of over $4 million. The current network and AZTEC tokens are unaffected.
CoinJournal
·2026-06-18 20:30:00
455
Axelar suspended its connection with Secret, resulting in the theft of $4.67 million in assets.
Axelar shut down its connection with Secret Network due to a security incident, resulting in the loss of approximately $4.67 million in bridging assets. The investigation points to the ICS-20 contract on the Secret side.
AMBCrypto
·2026-06-20 01:22:08
888