Core Summary
Ethereum’s most prominent sandwich attack bot, Jaredfromsubway.eth, fell victim to an ironic reverse exploit. Security firm Blockaid disclosed that an attacker tricked the bot into approving fake trading routes, then used those approvals to drain approximately $7.5 million in WETH, USDC, and USDT tokens.
Event Details
According to CoinDesk, Blockaid’s security research team discovered that an attacker designed deceptive trading route contracts that induced the Jaredfromsubway.eth bot to interact with them and grant token transfer approvals. Once authorized, the attacker swiftly transferred all WETH, USDC, and USDT tokens from the bot’s wallet. The incident is seen as a classic case of “the hunter becomes the hunted” in decentralized finance.
Sandwich attacks exploit blockchain transaction transparency by inserting transactions between a user’s buy and sell orders, profiting from artificially inflated prices. Jaredfromsubway.eth was one of the most frequent executors of this strategy on Ethereum, with estimated cumulative profits in the tens of millions.
Analysis
This incident reveals deep-seated risks in DeFi smart contract interactions. Even highly automated on-chain bots remain vulnerable to carefully crafted social engineering attacks. The attacker exploited the bot’s mechanism for automatically approving trading routes by disguising malicious contracts as legitimate liquidity pools.
More broadly, this highlights the “approval management” security vulnerability in the DeFi ecosystem. Users typically grant token transfer permissions when interacting with smart contracts, and these permissions can be maliciously exploited once given. Security experts recommend that all on-chain participants regularly review and revoke unnecessary token approvals.
Editor: GoodInfo Global News Team