Mcap -- BTC -- ETH -- SOL -- BNB -- XRP -- F&G -- View Market
Loading prices…

Jaredfromsubway.eth, Ethereum's Biggest Sandwich Bot, Loses $7.5M to Fake Token Trap

Diagram showing fake token trap exploit flow that drained Jaredfromsubway.eth MEV bot

For roughly a year, Jaredfromsubway.eth operated as something close to a toll collector on Ethereum’s decentralized exchanges, executing between 60,000 and 90,000 sandwich attacks per month and capturing an estimated 70% of all such activity on the network. On Saturday, the bot became prey instead of predator, losing $7.5 million to an attacker who understood exactly how its automated hunting systems worked.

The irony is hard to miss. Jaredfromsubway.eth built its operation on exploiting DeFi traders’ pending transactions, front-running them to extract what researchers call an “invisible tax.” The attacker who drained it used a variation of the same principle: present something that looks like easy money, wait for the target to bite, then take everything.

Fake Tokens, Real Approvals

Blockchain security firm Blockaid published a breakdown of the exploit shortly after the incident, noting that it didn’t fit neatly into familiar categories. “This is not a classic phishing attack and not a traditional smart-contract vulnerability in the victim contract,” the firm said on X.

The attacker’s method was more elegant. They constructed a series of fake wrapper tokens and liquidity pools designed to mimic legitimate trading opportunities. The counterfeits included fake Wrapped Ether (fWETH), fake USDC (fUSDC), and fake USDT (fUSDT), all paired against a token called fake Cap (fCAP). To a human reviewing the contracts, the fakery might have been obvious. To an automated MEV bot scanning mempool transactions for profitable arbitrage routes, they looked like money waiting to be extracted.

Jaredfromsubway.eth’s systems did what they were programmed to do. The bot detected the apparent opportunities and generated token approvals, granting certain helper contracts permission to spend real WETH, USDC, and USDT on its behalf. In a normal MEV operation, these approvals would be consumed during the trade itself. But the attacker had crafted routes that left the approvals open after execution.

Once enough approvals accumulated across multiple bait transactions, the attacker executed what Blockaid described as a “final sweep,” calling transferFrom functions to pull real tokens from the Jaredfromsubway.eth contract. The total haul: more than $7.5 million in legitimate stablecoins and wrapped ether.

The technique exploited something fundamental about how MEV bots operate. These systems are optimized for speed and profit extraction, not deliberation. They process thousands of potential opportunities per block, making approval decisions in milliseconds. The attacker essentially poisoned the bot’s input data with carefully constructed lures, knowing the automated decision-making would handle the rest.

The Scale of Jaredfromsubway.eth’s Operation

To understand why this exploit matters beyond the immediate dollar figure, consider the bot’s footprint on Ethereum’s DeFi ecosystem. Cointelegraph Research data covering November 2024 through October 2025 found that Jaredfromsubway.eth was associated with approximately 70% of all sandwich attacks on the network during that period. Monthly attack volumes ranged from 60,000 to 90,000 incidents.

Sandwich attacks work by exploiting the brief window between when a user submits a swap transaction and when it actually executes on-chain. The attacker sees the pending trade in the mempool, places a buy order for the same token immediately before the victim’s transaction (pushing the price up), then sells right after the victim’s trade completes at the inflated price. The victim gets worse execution; the attacker captures the spread.

Researchers estimate these attacks cost Ethereum traders roughly $60 million per year in aggregate losses. That’s money extracted from ordinary users trying to swap tokens on Uniswap, Sushiswap, and other decentralized exchanges. Jaredfromsubway.eth, as the dominant operator, captured the lion’s share of that extraction.

Diagram showing the four-step exploit flow used to drain $7.5 million from Jaredfromsubway.eth MEV bot using fake tokens and open approvals

The bot’s profitability over its operational lifetime ran into the hundreds of millions of dollars, according to various on-chain analyses. The $7.5 million loss, while substantial, represents a fraction of total accumulated gains. Whether the operator behind the bot views this as a serious setback or merely a cost of doing business remains unclear.

MEV Economics and the Predator-Prey Reversal

Maximal extractable value (MEV) refers to the profit that can be captured by reordering, inserting, or censoring transactions within a block. Validators and specialized bots compete for this value, and the competition has spawned an entire sub-industry of searchers, builders, and relay operators. The dynamics are genuinely adversarial. Bots running MEV strategies aren’t providing a service to users; they’re extracting rent from them.

This creates an interesting moral dimension to Saturday’s exploit. Crypto investor David Gokhshtein captured the ambivalence in a post on X: “We shouldn’t be happy about this; no one should celebrate … but if you’ve ever been sandwiched by this … I’m pretty sure you’re not upset about this news.”

The sentiment reflects a broader tension in DeFi security discussions. When a protocol gets exploited, the community typically rallies around affected users and condemns the attacker. When an MEV bot gets drained, the reaction is more complicated. The “victim” made its money by victimizing others. The attacker used sophisticated technical knowledge to extract funds. The ethical calculus doesn’t resolve cleanly.

From a pure security standpoint, though, the exploit demonstrates that even the most successful MEV operations carry structural risks. Bots like Jaredfromsubway.eth operate with significant capital deployed to automated systems. Those systems make decisions faster than humans can review them, which is precisely what enables the bot to capture MEV opportunities before competitors. But that same automation becomes a vulnerability when an adversary understands the decision logic.

The fake token trap worked because the attacker correctly modeled how the bot evaluates potential trades. They knew the system would grant approvals for contracts that appeared to offer profitable routes, and they knew those approvals could be exploited if the trade logic left them open. In a sense, they sandwiched the sandwich bot.

Similar exploit mechanics have targeted other DeFi participants. The XRP Ledger’s architecture specifically prevents flash loan attacks that have drained billions from Ethereum protocols by blocking atomic loan-and-exploit sequences. And just this month, a security researcher exploited a nine-year-old bug in a dormant ICO contract to free $2 million in trapped ether, demonstrating how old smart contract logic can harbor latent vulnerabilities for years.

What Happens to Sandwich Attack Volume Now

The $7.5 million drain doesn’t disable Jaredfromsubway.eth’s infrastructure. The bot’s code and operational systems remain intact; what the attacker extracted was working capital, not the underlying technology. Whether the operator chooses to recapitalize and continue operations, modify the approval logic to prevent similar exploits, or retire the bot entirely is unknown.

Given the operation’s historical profitability, continued activity seems likely. MEV extraction on Ethereum remains lucrative, and the competitive landscape includes numerous other bots that would simply absorb Jaredfromsubway.eth’s market share if it exited. The economics haven’t changed.

For Ethereum users, the implications are mixed. If the exploit prompts MEV operators to adopt more conservative approval strategies, that could marginally reduce the efficiency of sandwich attacks. But the fundamental vulnerability that enables sandwiching, the public mempool where pending transactions are visible before confirmation, remains unchanged. Users who want to avoid being sandwiched need to use private transaction relays or protocols with MEV protection, not hope that bot operators become more cautious.

Blockaid’s analysis suggests the broader MEV ecosystem will study this exploit carefully. Bots that generate approvals to third-party contracts as part of their execution flow may need to implement additional checks, potentially sacrificing some speed for security. The tradeoff between automation speed and approval hygiene isn’t trivial when milliseconds determine whether you capture an MEV opportunity or lose it to a competitor.

You can track broader Ethereum ecosystem metrics including DeFi activity on our market dashboard. For those monitoring the derivatives side of ETH exposure, the derivatives page tracks funding rates and open interest across major perpetual venues.

The Symmetry of Exploit Economics

There’s something almost poetic about the mechanics here. Jaredfromsubway.eth made its money by exploiting information asymmetry, seeing pending trades that users couldn’t hide and acting on that knowledge faster than anyone else. The attacker exploited a different asymmetry: understanding the bot’s automated decision-making better than its operator anticipated adversaries would.

Both strategies rely on presenting a target with information that triggers a predictable response, then profiting from that response. The sandwich bot sees a large swap and knows the user will execute it regardless of slippage within tolerance parameters. The fake token attacker sees an MEV bot and knows it will approve contracts that appear to offer profitable routes.

Neither player in this particular game was acting in the interest of ordinary DeFi users. The funds that Jaredfromsubway.eth accumulated came from traders receiving worse prices on their swaps. The funds the attacker extracted were profits from that extraction. It’s predators all the way down.

Whether this changes anything meaningful about MEV on Ethereum remains to be seen. The next major development in sandwich attack economics is more likely to come from protocol-level changes, like the adoption of private mempools or encrypted transaction inclusion systems, than from one bot losing capital to a clever adversary. The Fear and Greed Index suggests market sentiment remains cautious overall, and events like this don’t help confidence in DeFi’s security guarantees.

For now, the episode stands as a reminder that automation without adequate security modeling creates attack surfaces. Jaredfromsubway.eth optimized for speed and profit extraction; it apparently didn’t adequately model an adversary willing to construct elaborate fake infrastructure to exploit its approval logic. That’s the kind of oversight that costs $7.5 million.

Sources

Frequently asked questions

What is a sandwich attack in crypto?

A sandwich attack is when an MEV bot spots your pending trade on a blockchain, places its own buy order right before yours (driving up the price), then sells immediately after your transaction executes. You end up paying more, and the bot pockets the difference. Researchers estimate these attacks cost Ethereum traders around $60 million annually.

How was Jaredfromsubway.eth exploited?

An attacker created fake token pools using counterfeit versions of WETH, USDC, and USDT that mimicked profitable trading opportunities. When the bot’s automated system detected what looked like easy MEV profits, it granted token approvals to attacker-controlled contracts. Those approvals stayed open after the trades, allowing the attacker to drain $7.5 million in real tokens via a final sweep transaction.

Will sandwich attacks on Ethereum decrease after this exploit?

Unlikely in the short term. While Jaredfromsubway.eth was responsible for roughly 70% of sandwich attacks between November 2024 and October 2025, the bot infrastructure remains intact and other MEV operators continue running similar strategies. The exploit drained funds but didn’t destroy the bot’s code or operational capability.
Share:
Twitter Facebook LinkedIn Reddit WhatsApp Telegram Email