JaredFromSubway, one of Ethereum’s best-known MEV bots, was drained of about $7.5 million after an attacker used token approvals to pull funds from its contract, according to crypto.news and on-chain records. The incident, reported over the weekend of June 20-21, involved wrapped Ether, USDC and USDT moving out of the bot’s Ethereum contract after permissions allowed an external wallet to transfer the assets.
Approval trap hits a notorious MEV bot
The reported drain appears to center on a classic DeFi risk: token allowances. In Ethereum applications, approvals let one address or contract spend tokens held by another. Traders and bots use them constantly for speed and automation. However, a bad approval can also become a direct path to a wallet drain.
In this case, records show the attacker did not need to break Ethereum itself. Instead, the wallet used granted approvals to pull major liquid assets from the JaredFromSubway contract. That makes the case especially striking because MEV bots usually exploit other users’ execution weaknesses, not the other way around.
Why JaredFromSubway matters
JaredFromSubway became famous in 2023 during the meme coin boom. The bot used sandwich attacks, where it placed trades before and after a user’s swap to capture profit from price movement. It also became one of Ethereum’s biggest gas spenders, drawing criticism from traders who saw MEV as a hidden tax on decentralized exchange activity.
The bot remained active through several market cycles and continued to attract attention in 2026. In May, it reportedly targeted a small swap by Ethereum co-founder Vitalik Buterin, renewing debate over toxic MEV and the need for better user protection.
DeFi security lesson
The drain shows that even advanced automated trading systems can carry approval risk. For users, funds and bot operators, the takeaway is simple: token permissions need constant review, tight limits and fast revocation when strategies change.
The episode may also sharpen the debate around MEV. If one of Ethereum’s most sophisticated bots can lose millions through authorization exposure, ordinary DeFi users face an even steeper security challenge.