Home / News / Ethereum / jaredfromsubway.eth Sandwich Bot Drained of $7.5 Million

Written By

jaredfromsubway.eth Sandwich Bot Drained of $7.5 Million

jaredfromsubway.eth Sandwich Bot Drained of $7.5 Million
jaredfromsubway.eth Sandwich Bot Drained of $7.5 Million

What to Know

  • $7.5 million was drained from jaredfromsubway.eth, Ethereum’s most prolific sandwich bot, on June 21, 2026
  • The attacker spent weeks deploying dozens of fake token contracts to trick the bot into granting open token approvals
  • Stolen funds including WETH, USDC, and USDT were later traced moving toward Tornado Cash
  • Sandwich attacks linked to jaredfromsubway.eth cost Ethereum traders roughly $60 million per year, per on-chain data

The most infamous sandwich bot on Ethereum just got a taste of its own medicine. jaredfromsubway.eth, a maximal extractable value (MEV) trading bot that built a fortune by preying on ordinary Ethereum users, was drained of more than $7.5 million on Saturday after an attacker spent weeks engineering the perfect trap, turning the bot’s own automated approval logic into an open vault that anyone with the right permissions could empty at will.

How the Attacker Flipped the Sandwich Bot’s Logic

This was not a standard phishing attack, and it was not a simple contract bug. Security firm Blockaid said the attacker targeted something more fundamental: the bot’s decision-making system. The whole operation was months in the making, built layer by layer through patient, methodical deception.

Over several weeks, the attacker deployed dozens of fake token contracts and fake liquidity pools designed to look like profitable jaredfromsubway.eth sandwich bot $7.5 million drained opportunities. Some mimicked WETH (wrapped ether). Others copied familiar stablecoins like USDC and USDT. The bait was sophisticated enough to fool automated pattern recognition built to scan for profit signals, not authenticate token origins.

At first, the attacker ran test trades. The bot would see what it thought was a MEV opportunity and generate token approvals for attacker-controlled helper contracts. In the early rounds, those approvals got used immediately during the trade itself. But the attacker was learning, iterating, watching how the bot responded. Gradually, routes were restructured so that approvals stayed open after each transaction completed. The bot had handed over standing permission to move its funds without realizing it.

Then came the withdrawal. Using those open approvals, the attacker pulled WETH, USDC, and USDT directly out of jaredfromsubway.eth’s contracts. The whole thing unraveled in a matter of minutes once the attacker decided to collect. More than $7.5 million was gone.

The incident was not a normal phishing attack and not a simple bug in the victim contract. The attacker targeted the bot’s decision-making system.

— Blockaid, blockchain security firm

What Is a Sandwich Bot and Why Should You Care?

A sandwich bot is an automated trader that exploits Ethereum’s public mempool. When a user submits a swap, the bot spots it, buys the same asset ahead to push the price up, waits for the victim’s order to execute at the worse rate, then sells to capture the spread. The user pays more. The bot takes the difference.

Scale that across thousands of trades per day and the numbers get serious fast. Ethereum sandwich attacks cost traders about $60 million a year, with somewhere between 60,000 and 90,000 individual attacks happening every month between November 2024 and October 2025, according to on-chain data. Roughly 70% of those attacks traced back to jaredfromsubway.eth. The bot has been running since early 2023 and does not discriminate by wallet size or trade size. It simply watches and inserts itself wherever a profit signal appears.

Sandwich attackers are not hackers in the traditional sense. No contracts get broken into. No private keys get stolen. The bot operates entirely within the rules of how Ethereum’s mempool works, which is part of what makes it so difficult to stop and so contentious within the crypto community.

USDC price and market data — sandwich bot context
Source: CoinMarketCap

The Time It Sandwiched Vitalik Buterin

The scope of jaredfromsubway.eth’s reach became genuinely absurd when reports emerged earlier this year that it had sandwiched a small swap made by Ethereum co-founder Vitalik Buterin. According to reporting published in May, the bot put up $1.14 million in capital to frontrun Buterin’s trade. The profit from the whole maneuver? $4. After fees, the bot actually lost money on that particular trade.

That is the kind of story that makes the case better than any statistic. jaredfromsubway.eth had sandwiched Vitalik Buterin’s own swap for essentially nothing, deploying over a million dollars in capital to extract pocket change. The bot was not making strategic choices. It was pattern-matching and executing at machine speed, on autopilot, indifferent to who was on the other side.

That level of indiscriminate automation is exactly what made jaredfromsubway.eth so effective at scale. It is also what made it vulnerable. When the attacker came along with fake token contracts designed to look like profit signals, the bot responded the same way it always did. It committed approvals. No questions asked.

What Happens to the Stolen Funds?

On-chain data shows some of the drained funds moving toward Tornado Cash, the cryptocurrency mixing protocol. If the attacker follows the standard playbook for large Ethereum heists, the stolen tokens get fragmented through the mixer to break the transaction trail and eventually surface in fresh wallets or bridge to other chains where they are harder to track.

Whether any of it is recoverable is almost certainly a no. Blockchain transactions are final. Open token approvals, once exploited, cannot be reversed. The $7.5 million is gone unless the attacker makes an unusual decision to return it, which happens in white-hat scenarios occasionally but is rare with this kind of premeditated long-game attack.

The Tornado Cash routing also has legal implications. Using that mixer following a theft puts the funds in territory that makes legitimate recovery through any exchange or fiat off-ramp substantially harder. For the attacker, that may be the entire point.

  • Fake WETH and stablecoin contracts deployed over several weeks as bait
  • Token approvals harvested through fake liquidity pool test trades
  • Open approvals used to drain WETH, USDC, and USDT from bot contracts
  • Stolen funds traced moving toward Tornado Cash mixer

The Bigger Lesson for Ethereum MEV Bots

Saturday’s incident does not make sandwich attacks less harmful to ordinary Ethereum users. The damage jaredfromsubway.eth inflicted across three-plus years of operation is not reversed by one exploit. Every trader who paid inflated slippage because of this bot still paid it. That $60 million per year number does not change.

But the event does expose something real about the architecture of MEV bots. These systems operate by generating transaction approvals at machine speed, trusting pattern recognition over manual review. That speed and automation is the whole value proposition. It is also a permanent attack surface. An attacker with enough patience and enough fake token contracts can train the system to trust them over time.

The Blockaid framing is worth sitting with here. This was an attack on the bot’s decision-making system, not its code. The code worked exactly as written. What got fooled was the automated judgment about what counts as a profit opportunity. Fixing that requires something harder than a patch.

jaredfromsubway.eth spent years profiting from traders who did not see the bot coming. On Saturday, the bot did not see the trade coming either.

Frequently Asked Questions

What is a sandwich bot on Ethereum?

A sandwich bot is an automated trader that detects pending transactions in Ethereum’s public mempool, buys ahead of them to push prices up, waits for the target trade to execute at the worse price, then sells immediately. The bot captures the price difference as profit, effectively taxing the original trader without their knowledge or consent.

How did the jaredfromsubway.eth bot get drained of $7.5 million?

An attacker deployed dozens of fake token contracts and fake liquidity pools over several weeks to trick the bot into issuing open token approvals to attacker-controlled contracts. Once those approvals remained open after test trades, the attacker used them to directly withdraw WETH, USDC, and USDT from the bot’s contracts, totaling more than $7.5 million.

How much have Ethereum sandwich attacks cost traders?

Sandwich attacks cost Ethereum traders approximately $60 million per year. Between November 2024 and October 2025, there were 60,000 to 90,000 attacks per month, with roughly 70% attributed to jaredfromsubway.eth alone, making it by far the most active sandwich bot on the Ethereum network during that period.

Where did the stolen funds from the jaredfromsubway.eth exploit go?

On-chain data shows portions of the stolen WETH, USDC, and USDT were sent toward Tornado Cash, a cryptocurrency mixing protocol used to obscure transaction trails. Given the finality of blockchain transactions and the use of a mixer, recovery of the full $7.5 million is considered highly unlikely by security researchers.

This article is for informational purposes only and does not constitute investment advice. Every investment and trading decision involves risk. Readers should conduct their own research before making any financial decisions.

Share With Your Network :

Facebook
X
LinkedIn
Pinterest
Reddit
Telegram
WhatsApp
Email
Threads

James Wright

James Wright is a Crypto News Reporter at TheCryptoWorld, covering breaking developments across exchanges, regulation, and institutional adoption. With a journalism background rooted in business reporting, James transitioned to full-time crypto coverage in 2020 after covering the rise of decentralized finance for an independent fintech publication. He focuses on delivering fast, accurate reporting on the stories that move markets — from SEC enforcement actions to major exchange listings and corporate treasury moves.
0 0 votes
Article Rating
Subscribe
Notify of
guest

3 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
Darius Khoury
Darius Khoury
11 minutes ago

the irony of a sandwich bot getting sandwiched by its own approval logic is almost too perfect. anyone got the tx hash? curious which approval pattern they spoofed exactly

Lucas Fernandes
Lucas Fernandes
3 minutes ago

Jared has been printing money on Uniswap since 2023, no way he doesn’t recover this in a month or two. MEV bots eating MEV bots is just the natural cycle at this point.

Raj Kapoor
Raj Kapoor
1 minute ago

Reminds me of the 0x bot drain back in 2022, same story different year. Whenever a bot operator gets comfortable, someone reverse engineers the approval flow and walks off with the bag. 7.5M is steep but Jared has cleared way more than that on ETH over the years.

Table of Contents

Check also

Specific Crypto details

Fear & greed index
49
▲ +4 from yesterday
Updated: April 11, 2026
▼ Fear
Recovering from extreme fear
0
Extreme fear
25
Fear
50
Neutral
75
Greed
100
Extreme greed
Yesterday
45
Fear
Last week
30
Fear
April 8
11
Extreme fear
0 0 votes
Article Rating
Subscribe
Notify of
guest

3 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
Darius Khoury
Darius Khoury
11 minutes ago

the irony of a sandwich bot getting sandwiched by its own approval logic is almost too perfect. anyone got the tx hash? curious which approval pattern they spoofed exactly

Lucas Fernandes
Lucas Fernandes
3 minutes ago

Jared has been printing money on Uniswap since 2023, no way he doesn’t recover this in a month or two. MEV bots eating MEV bots is just the natural cycle at this point.

Raj Kapoor
Raj Kapoor
1 minute ago

Reminds me of the 0x bot drain back in 2022, same story different year. Whenever a bot operator gets comfortable, someone reverse engineers the approval flow and walks off with the bag. 7.5M is steep but Jared has cleared way more than that on ETH over the years.

SpaceX IPO Bitcoin Treasury Hits $1.45B in S-1 Filing

Bitcoin

May 21, 2026

SpaceX IPO Bitcoin Treasury Hits $1.45B in S-1 Filing

James Wright

DOJ Opens Binance Iran Sanctions Evasion Investigation

Regulation

4 weeks ago

DOJ Opens Binance Iran Sanctions Evasion Investigation

James Wright

Jane Street Bitcoin ETF (BTC) Cut 71%, $82M Into Ethereum ETFs

Ethereum

4 weeks ago

Jane Street Bitcoin ETF (BTC) Cut 71%, $82M Into Ethereum ETFs

James Wright

StablR Euro and USD Stablecoin Depeg After $2.8M Exploit

Stablecoins

4 weeks ago

StablR Euro and USD Stablecoin Depeg After $2.8M Exploit

James Wright

Market Analysis

The Future of Crypto, Covered Daily

Real-time news, expert analysis, and market insights  trusted by thousands of crypto investors worldwide.

You have been successfully Subscribed! Ops! Something went wrong, please try again.
3
0
Would love your thoughts, please comment.x
()
x