Ethereum’s biggest ‘sandwich’ bot drained of $7.5 million in ironic exploit
Blockaid said an attacker tricked Jaredfromsubway.eth into approving fake trading routes, then used those approvals to drain WETH, USDC and USDT.
Make preferred on
Share this article
Summary
- An attacker drained more than $7.5 million from the notorious Ethereum MEV bot jaredfromsubway.eth by exploiting its automated trading logic rather than a traditional contract bug or phishing scam.
- Over several weeks, the attacker lured the bot into approving malicious helper contracts via fake tokens and liquidity pools that mimicked assets like WETH, USDC and USDT, then used those open approvals to pull funds and route some through Tornado Cash.
- The incident underscores both the scale and risks of industrialized sandwich-bot activity—jaredfromsubway.eth has been responsible for roughly 70% of Ethereum sandwich attacks, which cost traders about $60 million a year—by showing how machine-speed, pattern-based systems can themselves be turned into victims.

