Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1577+ Articles
153+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. JaredFromSubway MEV Bot Hacked in $15 Million Crypto Theft
JaredFromSubway MEV Bot Hacked in $15 Million Crypto Theft
NEWS

JaredFromSubway MEV Bot Hacked in $15 Million Crypto Theft

The JaredFromSubway Ethereum MEV bot lost $15 million after an attacker exploited its opportunity-detection logic by creating fake trading setups, draining funds in a sophisticated on-chain manipulation attack.

Dylan H.

News Desk

June 22, 2026
3 min read

JaredFromSubway MEV Bot Loses $15 Million in Sophisticated Exploit

A prominent Ethereum maximal extractable value (MEV) bot known as JaredFromSubway has been drained of approximately $15 million after an attacker successfully manipulated its opportunity-detection logic to siphon funds through carefully crafted fake trading conditions.

MEV bots are automated programs that monitor the Ethereum mempool and attempt to profit by reordering, inserting, or censoring transactions within blocks — a practice known as maximal extractable value. The JaredFromSubway bot had gained notoriety for aggressive sandwich attack strategies targeting decentralized exchange (DEX) traders.

How the Attack Worked

Rather than exploiting a traditional software vulnerability, the attacker weaponized the bot's own profit-seeking logic against it. By constructing artificial trading "opportunities" on-chain, the attacker tricked the MEV bot into initiating transactions that ultimately transferred funds out of the bot's control.

The attack is a stark example of economic logic exploitation — a class of attack where the business logic of a smart contract or automated system is manipulated rather than exploiting a code bug. Key elements included:

  • Fake liquidity positions crafted to appear as profitable arbitrage windows
  • Multi-step transaction sequences that passed the bot's profitability checks but drained funds at execution
  • On-chain obfuscation to delay detection of the drain

Impact and Aftermath

The total loss across the incident reached approximately $15,000,000 USD in Ethereum and ERC-20 tokens. The attack unfolded rapidly on-chain, with blockchain analytics firms flagging the anomalous outflows shortly after they occurred.

The incident highlights the systemic risk inherent in MEV strategies: the same aggressive, automated logic that generates profit also creates exploitable attack surfaces when adversaries understand the bot's decision-making model well enough to game it.

Implications for DeFi Security

MEV bots operate in an adversarial environment by design, but this attack demonstrates that the bots themselves can become the target. Several takeaways for DeFi operators and researchers:

  • Sandwich bots are not immune to being sandwiched — adversaries can construct traps that exploit the attacker's own logic.
  • Economic security requires modeling adversarial simulation, not just code audits.
  • Rate limiting, circuit breakers, and loss limits should be built into high-capital automated systems.
  • On-chain transparency is a double-edged sword: the same mempool visibility that enables MEV also allows adversaries to study and exploit bot behaviour.

Key Takeaways

DetailValue
BotJaredFromSubway (Ethereum MEV)
Loss~$15 million USD
Attack vectorEconomic logic manipulation
ChainEthereum
DateJune 2026

The JaredFromSubway incident joins a growing list of high-value DeFi exploits in 2026 and serves as a reminder that economic security analysis is as critical as code auditing in the decentralized finance space.


Source: BleepingComputer

#Cryptocurrency#DeFi Security#MEV#Blockchain#Exploit

Related Articles

More Than $10 Million Stolen from Crypto Platform THORChain

THORChain officials confirmed that one of their six vaults was compromised in a security incident, leading to a loss of approximately $10.7 million. The...

3 min read

$13.74M Hack Shuts Down Sanctioned Grinex Exchange After

Grinex, a Kyrgyzstan-based cryptocurrency exchange sanctioned by the U.S., U.K., and EU for facilitating sanctions evasion, has suspended all operations...

3 min read

Hacker Charged with Stealing $53 Million from Uranium

U.S. prosecutors have charged a Maryland man with hacking DeFi protocol Uranium Finance twice and laundering over $53 million through cryptocurrency mixers.

4 min read
Back to all News