Ethereum MEV Bot JaredFromSubway Drained in Token Approval Exploit
Security
Bearish

Ethereum MEV Bot JaredFromSubway Drained in Token Approval Exploit

The Ethereum MEV bot JaredFromSubway was compromised via malicious token approvals, resulting in a loss of funds. Estimates of the total drain range from $7.5 million to $15 million depending on the valuation method used.

Sep 25, 2026, 08:02 AM1 min read

Written by CoinArticle’s AI Newsroom · from 2 cited sources. How we work

How the Attack Unfolded

The MEV bot JaredFromSubway was drained through malicious token approvals that allowed an attacker to withdraw assets held in the bot's contract. The exploit leveraged what researchers describe as a counter-MEV honeypot mechanism, suggesting the attacker may have set a trap designed to catch MEV bots attempting to extract value from transactions.

Conflicting Loss Estimates

Reports of the total loss differ significantly. Bitcoinist reported the drain at $7.5 million, while NewsBTC cited figures as high as $15 million. The discrepancy likely reflects different pricing snapshots or methodologies for valuing the bot's holdings at the time of the exploit. Without a detailed breakdown from either source, the exact composition of drained tokens and their precise prices at loss time remain unclear.

Implications for Bot Security

The incident highlights a vulnerability in MEV bot architecture: unlimited token approvals granted to contracts can be weaponized if that contract is compromised or if the approvals are socially engineered into the bot's configuration. JaredFromSubway was one of the most active MEV bots on Ethereum, making it a high-value target for attackers.

Why It Matters

For Traders

MEV bot compromise raises questions about counterparty risk in bot-executed strategies; traders relying on similar bots should audit their token approval grants immediately.

For Investors

The attack demonstrates that even sophisticated, well-funded MEV operators remain vulnerable to social engineering and contract exploitation, a structural risk in the current DeFi tooling landscape.

For Builders

Bot and contract developers should implement approval limits, timelocks on permission changes, and honeypot detection to harden against similar attacks.

This article is for information only and is not financial advice. Read the full disclaimer.

Live prices:Ethereum

Related Articles

Latest News