MEV Bot JaredFromSubway Attacked, Approximately $15 Million in Assets Stolen

PANews, June 21 – MEV bot developer JaredFromSubway.eth posted that his MEV bot was hacked and drained of approximately $15 million in assets. He publicly offered a $1 million bounty for the full return of the funds, promising complete confidentiality and a secure return, emphasizing that this is a legitimate and time-sensitive bounty, and calling on the hacker to contact him privately.

Security firm Blockaid stated that the attacker constructed fake token wrappers and liquidity pools, tricking the automated MEV execution system into granting token approvals to attacker-controlled contracts. The attacker then exploited the unrevoked approvals to transfer out assets such as WETH, USDC, and USDT held by the bot via transferFrom. Blockaid noted that this incident was neither a traditional phishing attack nor a smart contract vulnerability in the victim contract itself; rather, the attacker exploited a flaw in the bot’s mechanism for automatically identifying arbitrage opportunities and generating approvals.

Share to:

Author: PA一线

This content is for market information only and is not investment advice.

Follow PANews official accounts, navigate bull and bear markets together
PANews APP
Data: Solana blockchain 24-hour application revenue reaches $2.8 million, ranking first
PANews Newsflash