Skip to main content
Important: We do not provide financial advice or custody funds. All transactions occur on third-party platforms.
Back to news
securityhigh impact

Infamous Ethereum MEV Bot 'Jaredfromsubway' Just Got Drained of $7.5M — Here's the Ironic Twist

52d ago · 1 source

Jaredfromsubway, one of Ethereum's most notorious MEV (Maximal Extractable Value) bots known for profiting by front-running other users' transactions, was drained of $7.5 million after a vulnerability in its own smart contract allowed an attacker to exploit it. The bot essentially approved its own theft by granting token approvals that were later used against it. The incident highlights the risks inherent even in sophisticated automated trading systems operating on-chain.

WHY IT MATTERS

Imagine a pickpocket who works a crowded subway, stealing wallets from unsuspecting passengers every day. Now imagine that same pickpocket accidentally left their own wallet wide open, and someone else stole everything from them. That's essentially what happened here. On Ethereum, there are automated programs called MEV bots that make money by cutting in line on other people's transactions — buying tokens right before you do to drive the price up, then selling right after for a profit. Jaredfromsubway was one of the most successful of these bots. But its own code had a security flaw — specifically in how it gave permission for tokens to be moved — and an attacker used that flaw to drain $7.5 million. The lesson? In crypto, even the predators can become prey if their code isn't airtight. It also shows why "token approvals" (permissions you give to smart contracts to move your money) are one of the most important security concepts to understand in DeFi.

Read the full analysis with a CryptoBipto membership

Create a free account and subscribe to unlock deep-dive analysis on every story.

Get started

SOURCES

RELATED

ETHMEVSmart Contract VulnerabilityDeFi SecurityToken ApprovalsEthereum

Educational only — not financial advice.