T
iTokenly

JaredFromSubway.eth MEV Bot hack — June 2026

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Target typeOther
Loss$7,500,000Published estimates range $7,500,000 to $7,700,000Price at time of incident
MethodOther or undisclosedCounter-MEV honeypot. The attacker deployed 66 identical impostor token contracts from a single factory, each mimicking the name and interface of WETH, USDC or USDT and paired with a sham liquidity pool, so the routes read as profitable arbitrage to the bot's automated decision logic. Executing those routes caused the bot to grant standing ERC-20 spending approvals to attacker-controlled helper contracts. Hidden functions in all 66 contracts were then triggered in one transaction to sweep the real balances via transferFrom.
ChainsEthereum
OutcomeUnresolved

What happened

On 20 June 2026 the Ethereum MEV bot operating under the ENS name jaredfromsubway.eth, for years the most active sandwich-trading bot on the network, was drained in a single sweep transaction. Security firm Blockaid, which published the technical analysis, dates it to 18:49:11 UTC in block 25360696 and recorded 1,474.58 WETH, 2,870,573 USDC and 2,035,760 USDT leaving the bot's contracts, worth roughly $7.5 million.

The attack exploited neither a bug in the bot's own contracts nor a stolen private key. The attacker deployed 66 identical impostor token contracts from a single factory, each mimicking the name and interface of WETH, USDC or USDT and each paired with a sham liquidity pool. The fake routes read as profitable arbitrage to the bot's automated decision logic, which executed them and, as the trades required, granted progressively larger ERC-20 spending approvals to attacker-controlled helper contracts. Approvals accumulated across 42 transactions and 423 approval events, reaching about 92.16 WETH per contract. Each impostor token carried an owner-only withdraw function callable only by the attacker, which executed a transferFrom up to the standing approval amount; a single final transaction invoked all 66 at once.

Figures differ. Blockaid put the loss at roughly $7.5 million. On-chain tracker Lookonchain, cited by The Block, counted about 4,427 ETH, roughly $7.7 million, converted by the attacker, with 1,000 ETH deposited into Tornado Cash. A $15 million figure, repeated by BleepingComputer, originated with an X account that claimed to be the operator and offered a bounty; The Block reported that onchain commentators flagged that account as a likely impersonator and that it could not verify any link between the account and the bot. No funds have been recovered.

Sources

  1. BlockaidSecondary · retrieved 2026-08-01
  2. The BlockSecondary · retrieved 2026-08-01
  3. BleepingComputerSecondary · retrieved 2026-08-01
  4. The DefiantSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "JaredFromSubway.eth MEV Bot hack — June 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/jaredfromsubway-mev-bot
https://itokenly.com/hacks/jaredfromsubway-mev-bot

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.