Ethereum's most active sandwich bot, the wallet known as Jaredfromsubway.eth, was drained of about $7.5 million in WETH, USDC, and USDT on June 21, 2026, according to security firm Blockaid, which investigated the incident. The bot was not hacked in the usual sense. No private key leaked and no smart contract was broken. The attacker instead turned the bot's own profit-seeking logic against it.
Jaredfromsubway.eth has been the dominant name in Ethereum maximal extractable value (MEV) since early 2023, running an estimated 70% of the network's sandwich attacks. Those attacks cost ordinary traders close to $60 million a year by slipping buy and sell orders around their pending trades. In May 2026 the bot even sandwiched a transaction from Ethereum co-founder Vitalik Buterin, a moment that summed up how little of the chain was off-limits to it.
A trap built from the bot's own appetite
Blockaid's account of the exploit reads less like a break-in and more like a long con. Over several weeks, the attacker deployed counterfeit token contracts and liquidity pools that mimicked legitimate assets, including WETH, USDC, and USDT. To the bot's automated scanners, these looked like fresh, profitable opportunities to sandwich.
The bot did what it always does. It identified the fake pools as targets worth trading against and granted token approvals to attacker-controlled helper contracts so it could move quickly when a victim trade appeared. The attacker had designed the routing so that those approvals stayed open. Once the bot had signed off, the attacker used the standing permissions to pull funds directly out of the bot's operating wallets.
"The attacker instead targeted the bot's decision-making system," Blockaid said, rather than exploiting a contract vulnerability or relying on phishing. That distinction matters. The bot was compromised through the data it trusted, not the code it ran.
A predator caught reading its own playbook
Sandwich bots win by seeing what other traders cannot. They watch the public mempool, spot a large pending swap, and wrap it with their own orders to extract the price difference. The entire model depends on reacting faster and with better information than the target.
That same model became the weakness. A system tuned to chase every profitable signal could be fed a stream of fake signals until it acted against its operator's interest. The bot that built a business on other people's blind spots had a blind spot of its own: it assumed the pools it found were real.
Some of the stolen funds were routed through Tornado Cash, the on-chain mixer, a common laundering step that complicates recovery. As of publication, the funds had not been returned.
Approvals are the quiet attack surface
The mechanics here are not exotic, and that is the uncomfortable part. Token approvals are the same permissions every Ethereum user grants when they let a decentralized exchange or app spend a token on their behalf. Most people sign them once and forget them. An approval that stays open is a standing invitation, and attackers increasingly target the permission layer rather than the contracts themselves.
For anyone who manages funds from a self-custodial wallet, the lesson is practical: review and revoke approvals you no longer use, and treat broad spending permissions as a liability rather than a convenience. The bot lost $7.5 million because it left doors open across many contracts it no longer needed. Individual users rarely run that many approvals, but the failure mode scales down to a single forgotten permission on a single token.
There is a broader signal too. Automated on-chain agents, from MEV bots to the newer wave of AI trading systems, are only as safe as the inputs they trust. An agent that acts on unverified data can be steered into harming the very wallet it is meant to protect. As more capital flows to autonomous strategies, the cost of feeding one bad data is no longer theoretical.
Overview
Jaredfromsubway.eth, the wallet responsible for most of Ethereum's sandwich attacks, lost roughly $7.5 million in stablecoins and WETH on June 21, 2026. Blockaid found that the attacker spent weeks planting fake token contracts and liquidity pools to bait the bot's MEV logic into approving attacker-controlled contracts, then used those open approvals to drain the wallets. Part of the haul moved through Tornado Cash. The episode is a rare case of an MEV predator being beaten at its own game, and a reminder that open token approvals remain one of the most underrated risks in on-chain finance.



