logo

JaredFromSubway MEV bot Incident Analysis

ID: 64dbcbaf-581d-5a60-a828-5324775c21db

STIX ID: report--64dbcbaf-581d-5a60-a828-5324775c21db

Feed Name: CertiK Blog

Threat Score
76/100

Date Published: 2026-06-26

Date Updated: 2026-06-27

...
...

On 20 June 2026 an attacker exploited an approval-hijacking flaw in the JaredFromSubway MEV bot by deploying fake wrapper tokens and liquidity pools that caused the bot to grant persistent ERC-20 allowances which were never consumed or revoked; the attacker later activated those baits to drain ~4,424 ETH (stablecoins and wrapped ETH) and laundered funds via Tornado Cash. The report provides the attack timeline, helper and exploiter addresses, technical root cause (wrapTo/transferFrom allowance logic bypass), transaction references, and a fund flow summary.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.