The JaredFromSubway Ethereum MEV bot was drained of $15 million after an attacker deployed fake liquidity pools and tokens to manipulate the bot's opportunity-detection logic. The attacker ran harmless test transactions first to study the bot's behavior, then crafted routes that caused the bot to grant ERC-20 token approvals to attacker-controlled contracts without consuming them. Once sufficient approvals accumulated (up to 92.16 WETH), the attacker used transferFrom to withdraw WETH, USDC, and USDT. JaredFromSubway, known for aggressive sandwich attacks on regular traders, initially offered a $3M bounty for full return of funds, later raising it to $7.5M for 50% return, and is reportedly negotiating with a white-hat group.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Karma slaps backRelated Articles:
903 Impressions