📣 The famous MEV bot "JaredFromSubway" has been exploited for over $7.5M, with some funds moved via TornadoCash.
The attacker manipulated the bot's automated MEV execution system without exploiting a smart contract bug or using phishing.
• Created fake tokens and liquidity pools that appeared profitable
• Tricked the bot into approving attacker-controlled contracts as spenders
• Initially consumed approvals to avoid detection
• Later left approvals active, giving attacker-controlled contracts access to funds
• Used the standing approvals to drain $WETH, $USDC, and $USDT via transferFrom()

16
10
10
6
6
6
6
6
4
3
2July 17, 2026 5K