Infamous Ethereum MEV Bot 'Jaredfromsubway' Just Got Drained of $7.5M — Here's the Ironic Twist
52d ago · 1 source
Jaredfromsubway, one of Ethereum's most notorious MEV (Maximal Extractable Value) bots known for profiting by front-running other users' transactions, was drained of $7.5 million after a vulnerability in its own smart contract allowed an attacker to exploit it. The bot essentially approved its own theft by granting token approvals that were later used against it. The incident highlights the risks inherent even in sophisticated automated trading systems operating on-chain.
WHY IT MATTERS
Imagine a pickpocket who works a crowded subway, stealing wallets from unsuspecting passengers every day. Now imagine that same pickpocket accidentally left their own wallet wide open, and someone else stole everything from them. That's essentially what happened here. On Ethereum, there are automated programs called MEV bots that make money by cutting in line on other people's transactions — buying tokens right before you do to drive the price up, then selling right after for a profit. Jaredfromsubway was one of the most successful of these bots. But its own code had a security flaw — specifically in how it gave permission for tokens to be moved — and an attacker used that flaw to drain $7.5 million. The lesson? In crypto, even the predators can become prey if their code isn't airtight. It also shows why "token approvals" (permissions you give to smart contracts to move your money) are one of the most important security concepts to understand in DeFi.
Read the full analysis with a CryptoBipto membership
Create a free account and subscribe to unlock deep-dive analysis on every story.
Get startedSOURCES
RELATED
Educational only — not financial advice.
