Pluang Jaredfromsubway.eth MEV Bot Exploit Results in $7.5M Drain
Article Content
- •Jaredfromsubway.eth lost approximately $7.5 million due to a transaction approval exploit.
- •The attacker deployed 66 fake token contracts to manipulate the bot's automated decision-making.
- •The incident highlights significant vulnerabilities in automated trading systems within DeFi.
The Ethereum MEV bot Jaredfromsubway.eth was exploited, resulting in a loss of approximately $7.5 million. The attacker utilized 66 counterfeit token contracts to trick the bot into approving transactions that ultimately drained its funds. This attack exploited the bot's automated execution workflow, specifically targeting its transaction approval process. Blockaid, the security firm that analyzed the incident, confirmed that this was not a typical phishing or smart-contract vulnerability. Instead, the attack leveraged the bot's own logic against it, highlighting risks associated with automated trading systems. The bot's operator has disputed the loss amount, claiming it is closer to $15 million and has offered a $1 million bounty for the recovery of the funds. This incident underscores the vulnerabilities inherent in MEV bots and the potential for significant financial loss.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (16)
Following this threat?
Track Ethereum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…