TGViewer
Coin Trend Network Coin Trend Network @yfdffdthruk · 7 subscribers
Post #9 3
Ethereum’s Jaredfromsubway MEV bot drained after approving its own $7.5M theft
Attackers used fake markets to turn Jaredfromsubway.eth’s trading approvals into a $7.5 million allowance drain.The Jaredfromsubway MEV bot, linked to roughly 70% of Ethereum sandwich attacks, lost more than $7.5 million in an allowance drain after its automated system authorized attacker-controlled contracts to spend its tokens.
The bot, known as Jaredfromsubway.eth, approved a series of transactions that appeared to be part of profitable trading routes. Those permissions remained active, allowing the attacker to remove wrapped ether and two major stablecoins from contracts associated with the operation.
The incident effectively caused one of Ethereum’s largest extractive trading systems to approve its own theft. It also highlights a vulnerability facing automated traders that must evaluate markets, authorize contracts, and execute transactions within seconds.Onchain security company Blockaid said the attacker did not compromise the bot’s private keys or exploit a flaw in a widely used decentralized finance protocol. Instead, the operation targeted the rules the bot used to identify and pursue potential profits.How Jaredfromsubway.eth was drained
According to Blockaid, the attacker had spent several weeks deploying imitation tokens, liquidity pools, and supporting contracts that resembled markets the bot might normally trade against.
The fake assets included versions of wrapped EthereumUSDC, and USDT, paired via trading routes designed to generate profitable-looking signals. Jaredfromsubway.eth detected those routes and followed its usual process of permitting helper contracts to move tokens as part of the expected trades.
Some early transactions used the permissions as anticipated, helping establish a pattern that the bot’s system continued to accept. Later transactions left the approvals unused.That distinction gave the attacker an opening through ERC-20 approvals, which allow another address or smart contract to spend a specified amount of tokens belonging to the approving account.
The permission can remain available after the original transaction unless it is exhausted, reduced, or revoked.
Once the attacker had accumulated enough unspent allowances, the contracts used the ERC-20 transferFrom function to move real WETH, USDC, and USDT from the bot’s accounts.
On-chain records show repeated transfers totaling about 92 WETH, $143,000 USDC, and $149,000 USDT from a contract linked to the bot. The funds were directed to an address controlled by the attacker.
More from @yfdffdthruk
  1. Sep 23, 2026来自速搜推荐 @SSOU 📢利博代理 利博官网 真人... 📢皇冠正盘|皇冠正网|皇冠... 📢皇冠娱乐 皇冠平台 皇冠... 📢皇冠平台|皇冠真人|皇冠... 📢万利官…
  2. Sep 10, 2026来自速搜推荐 @SSOU 📢巫师财经💸💵💶 📢真人视讯:欧博|亚星百家... 📢风笛儿 📢3D排三每日分享频道 📢solaire修车 so... 📢欧博私网 亚星…
  3. Sep 3, 2026来自速搜推荐 @SSOU 📢UG环球开户 UG环球官... 📢世界杯世俱杯-世俱杯赌球... 📢迷奸 下药 📢网红福利 📢棋牌游戏-电子游戏-体育... 📢美狮美高梅平…
  4. Jul 23, 2026来自速搜推荐 @SSOU 📢欧博注册 欧博网址 欧博... 📢UG环球开户 UG环球官... 📢球速体育/代理/官方招商... 📢内涵搞笑&每日一笑 📢旺博真人视讯百家乐…
  5. Jul 6, 2026There was just under $1.8 trillion in adjusted stablecoin transaction volume in June. Sour…
  6. Jul 6, 2026Adjusted stablecoin transaction volume hit a record $1.79 trillion in June, up 63% from Ma…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →