Original | Odaily Planet Daily (@OdailyChina)
Author | Azuma (@azuma_eth)
The well-known MEV bot address Jaredfromsubway.eth, long active on the Ethereum network, suffered a highly targeted on-chain attack on Saturday, resulting in losses exceeding $7.5 million.
According to investigations by Blockaid and multiple on-chain analytics firms, this incident was not a traditional phishing attack or smart contract vulnerability exploitation, but rather a targeted "counter-MEV honeypot attack" designed to exploit the behavioral logic of MEV bots.
Over the preceding weeks, attackers systematically deployed 66 counterfeit token contracts and fake liquidity pools, carefully disguising these assets on-chain as mainstream stable assets such as WETH, USDC, and USDT, and constructing seemingly legitimate arbitrage trading paths.
During this process, the attack chain unfolds step by step—fake liquidity pools generate signals of arbitrage opportunities; MEV bots automatically detect these opportunities and execute trades; the bots grant permissions to auxiliary contracts controlled by the attacker; these permissions are not promptly revoked, resulting in persistent access exposure; ultimately, the attacker invokes pre-deployed backdoor logic within a single transaction to directly transfer assets such as ETH, USDC, and USDT held in the MEV bot’s address.
On-chain data shows that the total value of assets stolen from Jaredfromsubway.eth has exceeded $7.5 million. The attacker has since split and transferred part of the assets, further obfuscating the fund flows using mixing tools.
Who is Jaredfromsubway.eth? The most notorious MEV bot address.
This attack has drawn significant attention because the target, Jaredfromsubway.eth, is itself one of the most active, profitable, and notorious MEV bots on the Ethereum network.
所谓“MEV攻击”,本质上是一类围绕“交易排序权”展开的链上套利行为。在以太坊网络中,交易在被打包进区块之前会先进入mempool等待处理,而区块构建者或搜索者可通过调整交易顺序、插入交易或重新排列区块内的交易来获取额外收益。
The most typical type of attack is the "sandwich attack"—where an attacker inserts buy and sell orders before and after a user’s transaction, profiting from price slippage in a short time frame. This behavior is extremely common in high-liquidity DeFi trading pairs and constitutes one of the most fundamental profit models in the MEV ecosystem.
Jaredfromsubway.eth is the most representative automated executor under this mechanism. Unlike traditional "single-point arbitrage bots," this MEV bot functions more like a highly industrialized MEV execution system. It continuously monitors the mempool for unconfirmed transactions, identifies profitable sandwich opportunities in real time, and constructs transactions, bids on gas fees, and inserts them into the block order—all within an extremely narrow time window—to systematically capture slippage profits.
Cointelegraph Research data shows that between November 2024 and October 2025, the Ethereum network experienced approximately 60,000 to 90,000 sandwich attacks per month, with about 70% linked to the strategy system of Jaredfromsubway.eth.
In May this year, Ethereum co-founder Vitalik Buterin was targeted by Jaredfromsubway.eth when exchanging 26,544 DigitalBits (XDB).
There is no official statistic on Jaredfromsubway.eth’s historical revenue, but conservative estimates suggest that the address has accumulated tens of millions of dollars in MEV rewards during its active period. At peak times, its daily earnings reached hundreds of thousands of dollars, and it consistently ranked among the top positions on Ethereum’s MEV leaderboards.
Crypto security threats intensify: even top predators are not immune
While reflecting on the saying “the hawker has finally been pecked in the eye,” the attack on Jaredfromsubway.eth has once again sounded the alarm on cryptocurrency risks.
In previous understanding, MEV bots like Jaredfromsubway.eth belonged to the "predator" side of the chain—they continuously exploited slippage and arbitrage opportunities in user transactions through automated strategies, occupying a privileged position within the ecosystem and arguably representing the most iconic class of attackers in the cryptocurrency market.
But this time, it became a target that was deliberately designed, manipulated, and ultimately exploited—without the attacker choosing a traditional vulnerability exploitation path. Instead, they constructed a long-term “behavioral trap,” causing MEV bot automated systems to gradually make incorrect decisions while fully complying with the established rules.
It must be acknowledged that even participants like Jaredfromsubway.eth, once masters at exploiting rules, are now increasingly exposed to more complex attack surfaces.
Additionally, it is worth noting that after Jaredfromsubway.eth was compromised, an unknown account on X with 94,000 followers changed its name to Jaredfromsubway.eth and falsely claimed to be offering a “$1 million reward for the full return of all funds.”

Multiple developers have issued a risk warning, emphasizing that this account is not the official Jaredfromsubway.eth account (the MEV Bot team has no official account), and it is possible that this account may be used for scams in the future—users are strongly advised to remain vigilant.

