JaredFromSubway MEV bot Incident Analysis
ID: 64dbcbaf-581d-5a60-a828-5324775c21db
STIX ID: report--64dbcbaf-581d-5a60-a828-5324775c21db
Feed Name: CertiK Blog
On 20 June 2026 an attacker exploited an approval-hijacking flaw in the JaredFromSubway MEV bot by deploying fake wrapper tokens and liquidity pools that caused the bot to grant persistent ERC-20 allowances which were never consumed or revoked; the attacker later activated those baits to drain ~4,424 ETH (stablecoins and wrapped ETH) and laundered funds via Tornado Cash. The report provides the attack timeline, helper and exploiter addresses, technical root cause (wrapTo/transferFrom allowance logic bypass), transaction references, and a fund flow summary.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
