Particle.news

JaredFromSubway MEV Bot Drained in Approval-Trap Honeypot

A verified exploit shows attacker-crafted tokens and fake pools forced the bot to grant persistent approvals that were later used to pull millions from its contracts.

Overview

  • Blockchain security firm Blockaid verified that the JaredFromSubway sandwich MEV bot was exploited and had roughly $7.5 million to $7.7 million moved out of its contracts in a drain that took place over the weekend.
  • The bot’s operator has publicly said the loss was $15 million and posted a $1 million bounty for full recovery, but that higher figure has not been independently confirmed.
  • The attacker spent weeks deploying 66 counterfeit token contracts and bogus liquidity pools to make trading routes look profitable so the bot would grant ERC‑20 approvals that later allowed transferFrom calls to drain WETH, USDC and USDT.
  • On‑chain tracing shows the stolen funds were swapped and portions routed through Tornado Cash and other addresses, and the attacker’s on‑chain identity remains unconfirmed.
  • The incident reverses the usual predator-prey dynamic in MEV trading and highlights a specific operational risk: automated approval handling and routing logic can be engineered into a honeypot, raising new security and governance questions for on‑chain trading bots.