Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Ethereum’s Staking War Why EIP-8361 Has DeFi Leaders Fighting Back
    Ethereum’s Staking War: Why EIP-8361 Has DeFi Leaders Fighting Back
    Nothing Is 100% Safe in Crypto Bitcoin’s Coldcard Exploit and Growing Security Crisis 
    Nothing Is 100% Safe in Crypto: Bitcoin’s Coldcard Exploit and Growing Security Crisis 
    From BitMEX to Leap Wallet 100+ Crypto Projects Have Shut Down in H1 2026
    From BitMEX to Leap Wallet: 100+ Crypto Projects Have Shut Down in H1 2026
    July Crypto Stock Breakdown Why MSTR, BMNR Held Gains as IREN, WULF, RIOT, ABTC Dropped
    July Crypto Stock Breakdown: Why MSTR, BMNR Held Gains as IREN, WULF, RIOT, ABTC Dropped
    What Happens If the CLARITY Act Does Not Pass?
    What Happens If the CLARITY Act Does Not Pass?
  • Opinion
    OpinionShow More
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Ethereum MEV Bot JaredFromSubway Drained in $15M Honeypot Attack

Security researchers reveal how a web of fake token contracts tricked the network's most notorious front-running operation into approving its own multi-million dollar robbery.

Written By Kenrodgers Fabian
Fact Checked by Divya Mistry
Published 2026-06-22·Updated 2 months ago
Make The Crypto Times preferred on GoogleGoogle
Ethereum MEV Bot JaredFromSubway Drained in $15M Honeypot Attack
Show AI Summary
Attackers exploited JaredFromSubway’s MEV bot using fake tokens, granting unauthorized access to its funds
Automated trading logic was weaponized against the bot, highlighting risks of extensive token permissions
Vulnerabilities arose from broader token approvals, allowing attackers to drain millions in crypto assets

An attacker has successfully drained millions of dollars from the wallet of JaredFromSubway, Ethereum’s most visible and notorious Maximal Extractable Value (MEV) bot operator. Blockchain security researchers confirm the attack weaponized the bot’s own automated trading logic against it, using a specialized token approval trap. 

Blockchain security firm PeckShield reported that attackers stole about $7.5 million in crypto assets before converting the funds into Ether. According to the firm, roughly 1,000 ETH was later transferred through the privacy protocol Tornado Cash. JaredFromSubway subsequently claimed the total losses were closer to $15 million.

#PeckShieldAlert Specter has reported that #MEV bot #JaredFromSubway appears to have been drained of ~$7.5M in crypto, including 1,474.58 $WETH, 2.87M $USDC, & 2M $USDT.

The attacker swapped the stolen funds for 4.4K ETH and has already deposited 1K ETH into #TornadoCash pic.twitter.com/qY6IVDdnGJ

— PeckShieldAlert (@PeckShieldAlert) June 20, 2026

The incident, first flagged by security researcher Specter, highlights the risks associated with automated trading operations on Ethereum, where extensive token permissions can create vulnerabilities even when underlying smart contracts remain secure.

Fake tokens turned the hunter into the target

The attack did not involve a flaw in JaredFromSubway’s trading software, according to analyst RaFi. Instead, the hackers allegedly created fake wrapper tokens and liquidity pools that appeared to offer profitable arbitrage opportunities. When the bot interacted with the fraudulent contracts, it unknowingly granted permissions that later allowed the attackers to access its funds.

“The bot essentially approved its own robbery,” RaFi said, noting that the initial transactions appeared legitimate. Over time, however, broader token approvals remained in place, giving the attackers unrestricted access through a network of helper contracts.

Thread about the JaredFromSubway MEV bot exploit

1/ Insane exploit on one of Ethereum’s most notorious MEV bots.

JaredFromSubway.eth — the sandwich attack bot that has extracted tens of millions from traders since 2023 — just got drained for ~$7.5M+ in one of the cleanest and… pic.twitter.com/Cg6NWScmvw

— RaFi (@RoanRafi) June 21, 2026

Blockchain data shows the exploit drained more than 4,400 wrapped Ether (WETH) from the bot’s wallets. The stolen funds were subsequently distributed across multiple addresses, making them more difficult to trace. Etherscan has identified one of the primary wallets involved in the operation as “JaredFromSubway Exploiter 1.”

Operator offers bounty after attack

JaredFromSubway confirmed the exploit in a series of posts on X, claiming the losses were significantly higher than early estimates from blockchain security firms. “I just woke up to a call from my friend. Yeah, I got fucking drained for $15M.”

The operator later appeared to open negotiations with the attacker, offering a reward in exchange for the return of stolen funds. “Well played. We are willing to offer a 50% white hat bounty.” He also warned that legal action could follow if the attacker failed to cooperate.

Well played. We are willing to offer a 50% white hat bounty if you return the ETH to us in the next 48 hours, otherwise we will pursue all available legal and law-enforcement options.​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​

Jaredfromsubway.eth pic.twitter.com/2eXYrH7X5b

— Jaredfromsubway.eth (@jaredsmev) June 22, 2026

The exploit has triggered widespread discussion across the decentralized finance (DeFi) ecosystem. While some security analysts view the incident as an important case study on the hidden risks of machine-speed token approvals, many everyday traders greeted the news with a sense of irony. Since early 2023, JaredFromSubway has extracted tens of millions of dollars from retail users, reportedly accounting for up to 70% of all sandwich attacks on Ethereum during peak periods.

The fallout is expected to drive intensive scrutiny toward automated trading infrastructure and the standard allowance models that keep Web3’s most aggressive searchers exposed.

Also Read: Taiko Urges Bridge Withdrawals After $1.7M Chain Verification Breach

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

The Architecture of Trust Same Routes, New Risks in Global Tokenisation
The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
Bybit Sues North Korea Over $1.5B Hack; Freezes Assets
Bybit Sues North Korea Over $1.5B Hack, Secures Court-Ordered Asset Freeze
U.S. Senate Moves CLARITY Act Forward as September Vote Comes Into View
U.S. Senate Moves CLARITY Act Forward as September Vote Comes Into View
From Trusted Vendor to Insider Job Coinkite CTO Now Linked to $110M Coldcard Hack Code
From Trusted Vendor to Insider Job? Coinkite CTO Now Linked to $110M Coldcard Hack Code
The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation

Find Us on Socials

You may also like

Panther Protocol Hit by Governance Attack, 5.12M ZKP Drained on Base

Panther Protocol Hit by Governance Attack, 5.12M ZKP Drained on Base

Privacy-First Coldcard Maker Suspends Data Deletion as Legal Proceedings Loom

Privacy-First Coldcard Maker Suspends Data Deletion as Legal Proceedings Loom

BONK Crashes to 3-Year Low as Upbit Delists Solana Memecoin Over $20M Hack

BONK Crashes to 3-Year Low as Upbit Delists Solana Memecoin Over $20M Hack

Hyperliquid Active Traders Hit ATH While Volume Declines

Hyperliquid Active Traders Hit ATH While Volume Declines

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information