JaredFromSubway Ethereum MEV bot lost $15 million after attacker used fake trading pools and token approvals

The JaredFromSubway Ethereum trading bot lost about $15 million after an attacker tricked it into approving malicious contracts and then drained its funds. According to Blockaid and JaredFromSubway, the attacker created fake MEV (maximal extractable value) opportunities using bogus pools and tokens so the bot would grant ERC-20 spending approvals to attacker-controlled helper contracts; the attacker later used those lingering approvals and the transferFrom function to withdraw WETH, USDC, and USDT.
Why it matters: This is a major crypto theft that shows how automated on-chain trading systems can be manipulated even without directly breaking a blockchain. Crypto firms, bot operators, and smart-contract developers should review approval logic, route validation, and allowance revocation controls immediately.

Sources

JaredFromSubway MEV bot hacked in $15 million crypto theft
Bill Toulas 2026.06.22 100% relevant
This article appears to be the first item here establishing the specific $15 million theft from the JaredFromSubway MEV bot through fake pool and token manipulation.
← Back to all stories