Inside a Sandwich Attack: Lessons From the $7.5 Million Heist Against JaredfromSubway.eth

In a dramatic reversal of fortune within the decentralized finance (DeFi) ecosystem, the most notorious and successful "sandwich" trading bot on the Ethereum blockchain, known by the ENS name JaredfromSubway.eth, fell victim to a highly sophisticated exploit over the weekend. The bot, which has earned tens of millions of dollars by front-running and back-running retail…

 Avatar

by

8 minutes

Read Time

In a dramatic reversal of fortune within the decentralized finance (DeFi) ecosystem, the most notorious and successful "sandwich" trading bot on the Ethereum blockchain, known by the ENS name JaredfromSubway.eth, fell victim to a highly sophisticated exploit over the weekend. The bot, which has earned tens of millions of dollars by front-running and back-running retail trades, was lured into a "honeypot" trap that resulted in the loss of at least $7.5 million in various cryptocurrencies. This incident marks one of the largest successful counter-exploits against a Maximal Extractable Value (MEV) bot in the history of the Ethereum network, highlighting the predatory and increasingly dangerous nature of the "Dark Forest"—a term often used by developers to describe the Ethereum mempool.

For years, JaredfromSubway.eth has operated as a dominant force in the MEV landscape. By monitoring the mempool—the public waiting area where transactions sit before being validated and added to the blockchain—the bot identifies large trades and "sandwiches" them. This involves placing a buy order immediately before the victim’s trade (front-running) to drive the price up, and a sell order immediately after (back-runnning) to capture the profit from the price slippage. While legal within the current rules of the Ethereum protocol, the practice is widely criticized for increasing costs for average users and degrading the overall trading experience on decentralized exchanges like Uniswap.

The Mechanics of the Honeypot Exploit

The exploit that drained JaredfromSubway.eth was not a traditional hack of a private key or a protocol-level vulnerability. Instead, it was a "honeypot" attack specifically designed to exploit the automated logic of the sandwich bot. The attacker deployed a series of 66 fraudulent smart contracts that mimicked legitimate tokens and liquidity pools. These contracts were designed to appear as lucrative opportunities for a sandwich attack, displaying imbalances that a high-frequency trading bot would typically find irresistible.

When the JaredfromSubway.eth bot detected these simulated opportunities, it followed its programmed routine to execute a series of trades. To interact with these pools at the necessary speed, the bot’s logic automatically granted "token spending approvals" to the malicious smart contracts. In the DeFi world, an approval allows a smart contract to move a specific amount of a user’s tokens from their wallet. To save on gas fees and ensure efficiency, many bots—and even many retail users—grant "unlimited" approvals to the contracts they interact with.

The attacker’s strategy relied on the bot’s optimization for speed over security. Because the bot is designed to act in milliseconds to beat out rival MEV operators, it did not perform a deep audit of the 66 new contracts it was interacting with. Once the bot granted these spending permissions, the attacker did not strike immediately. Instead, they waited until the bot had granted approvals across dozens of fake contracts, effectively giving the attacker the keys to the bot’s legitimate assets, including Wrapped Ethereum (WETH) and various stablecoins. Once the trap was fully set, a "tripwire" function in the malicious code was activated, allowing the attacker to drain $7.5 million from the bot’s primary wallet in a single coordinated strike.

A Chronology of the Attack and the Money Trail

The attack unfolded with clinical precision, beginning with the deployment of the fraudulent infrastructure days before the final drain. According to on-chain data and analysis provided by blockchain security firms, the attacker meticulously set up dozens of pairs on decentralized exchanges. These pairs utilized "stooge assets"—tokens with no real value that were programmed to appear as if they were experiencing high-volume trading activity.

Once the JaredfromSubway.eth bot bit the bait and granted the necessary permissions, the drain occurred rapidly. The stolen assets consisted of approximately $7.5 million in a mix of Ether (ETH) and stablecoins such as USDC and USDT. The attacker, well aware of the risks associated with holding centralized stablecoins, moved immediately to prevent the issuers (Circle and Tether) from freezing the funds. Within minutes of the exploit, the attacker swapped all stolen stablecoins into ETH. This process, known as "hardening" the assets, ensures that the funds cannot be remotely blacklisted by a central authority.

Following the conversion to ETH, the attacker utilized a series of intermediary wallets to split the funds, a common tactic used to complicate the work of blockchain investigators. Data from Chainalysis Reactor shows that the funds were eventually funneled into Tornado Cash, a decentralized privacy protocol that uses zero-knowledge proofs to obfuscate the origin and destination of transactions. Tornado Cash was sanctioned by the U.S. Office of Foreign Assets Control (OFAC) in 2022 due to its use by North Korean hackers and other criminal entities, yet it remains operational on the Ethereum network as a tool for those seeking financial anonymity.

Inside a Sandwich Attack: Lessons From the $7.5 Million Heist Against JaredfromSubway.eth

Background: The Dominance of JaredfromSubway.eth

To understand the significance of this exploit, one must understand the scale of JaredfromSubway.eth’s operations. Since its emergence in early 2023, the bot has become a symbol of the MEV era. At its peak, the bot was estimated to be generating upwards of $60 million in annual revenue. Its activity was so intense that it frequently ranked as the single largest consumer of gas on the entire Ethereum network, sometimes accounting for more than 5% of all network fees in a single day.

The operator of the bot has remained anonymous, though the name "JaredfromSubway" is a satirical reference to a disgraced former spokesperson for the American fast-food chain. Despite the controversy surrounding sandwich attacks, the bot’s creator was often praised in certain developer circles for the technical sophistication and efficiency of the code, which allowed it to consistently outperform rival bots in the highly competitive "gas wars" of the Ethereum mempool. However, that same drive for efficiency—skipping the verification of new, unproven smart contracts—ultimately became the bot’s Achilles’ heel.

Broader Implications for the DeFi Ecosystem

The successful "hacking" of a major MEV bot provides several critical lessons for the broader cryptocurrency community. First and foremost, it highlights the persistent danger of unrevoked token approvals. For the average DeFi user, the incident serves as a stark reminder that every time a wallet signs an approval for a smart contract, it creates a potential back door to their funds. If that contract is malicious or later compromised, any assets associated with that approval are at risk. Security experts recommend that users regularly use tools like Revoke.cash to clear out old permissions and to never grant unlimited approvals to unverified or new protocols.

Furthermore, the attack underscores the "counterparty risk" inherent in permissionless blockchains. In traditional finance, a trader typically knows the identity of the exchange or the broker they are dealing with. In DeFi, the counterparty is often nothing more than a piece of code. If that code is unverified on Etherscan or has no established track record, the user is essentially entering into a blind contract. JaredfromSubway.eth’s bot was programmed to trust the code implicitly to gain a speed advantage, a trade-off that cost its operator $7.5 million.

The event has also sparked a debate within the Ethereum community regarding the ethics of "predatory" trading. While some observers expressed a sense of "schadenfreude" at the bot’s loss—viewing it as poetic justice for the millions of dollars the bot had extracted from retail traders—others pointed out that the attacker is likely just another sophisticated actor in the same ecosystem. This cycle of "predator versus predator" reinforces the idea that the Ethereum mempool remains an adversarial environment where only the most cautious and technically guarded participants survive.

Market Reaction and the Future of MEV

In the wake of the exploit, the JaredfromSubway.eth bot did not immediately cease operations, though its activity levels fluctuated as the operator likely worked to patch the vulnerabilities and tighten approval logic. The MEV market as a whole continues to evolve, with new protocols like MEV-Share and Flashbots seeking to mitigate the negative impact of sandwich attacks by creating more transparent and fair ways for users to submit transactions.

However, as long as the Ethereum mempool remains transparent and "slippage" remains a factor in decentralized trading, the incentive for sandwiching will persist. The $7.5 million honeypot attack is a landmark event that proves even the most dominant players in the space are not immune to the risks they help create. As DeFi continues to mature, the focus is shifting toward "intent-based" trading and "private mempools," which aim to hide transactions from bots entirely, potentially ending the era of the sandwich attack once and for all.

For now, the loss of $7.5 million serves as a definitive case study in the risks of automated high-frequency trading on the blockchain. It proves that in the world of decentralized finance, the line between the hunter and the hunted is razor-thin, and a single overlooked line of code can lead to a multi-million dollar catastrophe. Chainalysis and other security firms continue to monitor the movement of the stolen funds from the Tornado Cash mixers, though the likelihood of recovery remains low given the nature of the privacy tools employed by the attacker.

About the Author

About the Author

Easy WordPress Websites Builder: Versatile Demos for Blogs, News, eCommerce and More – One-Click Import, No Coding! 1000+ Ready-made Templates for Stunning Newspaper, Magazine, Blog, and Publishing Websites.

BlockSpare — News, Magazine and Blog Addons for (Gutenberg) Block Editor

Search the Archives

Access over the years of investigative journalism and breaking reports