← Radar

Incident case file

Sign in to watch

JaredFromSubway MEV Bot — Counter-MEV Honeypot Approval Drain

Incident date June 20, 2026

2 views

ActiveEthereumMEV bot exploit / approval hijacking (counter-MEV honeypot)Cluster: JARED-MEV-2026-06

Estimated loss

$7.5M

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Attacker: Principal: 0x3e37f4A10d771Ba9dE44b6d301410b1BEdeA65d0 (EIP-7702-delegated EOA). Downstream/distribution addresses: 0x74Dc5b93586D248D5Aec64b3586736FF0A0D0e65; 0x71d4416A7A85e08a5Fe7227Ca3B44Fc639e94e97; 0xd8C125efCBc99408eC8723E9BBd81d1E8D39D845; 0xe3Da36E4bd1a5738fa5D6Ef4F0e4dF40bDeB5f17 (routed 1,000 ETH to Tornado Cash); 0x139bE50D7c0829E0db6E9A444454517e24AbeE7a; 0x5aF38735B215b00aa7C9f93fEd7ee415CeCB36e1 (frontrunning); 0x19Ff2017803a832eE968454848DAb48fF39C881A; 0x7B4F24a4522bc2AEE9D1686FF

Funds moved to: Attacker consolidated proceeds into ~4,427 ETH. ~1,000-2,000 ETH routed through Tornado Cash (per The Block, June 22, 2026). ~1,422 ETH swapped for ~$2.45M DAI via DEX (per Value The Markets). Victim (bot operator) publicly offered a 50% white-hat bounty (~2,150 ETH) on-chain on June 22, 2026; the attacker declined and continued laundering. Status: largely unrecovered as of report date. Key sweep tx: 0x43ee75697d731f39f0e3c68fe6937715f2327563f6cb02fb0e9d454fbd634e6d. Additional drain tx hashes (
Victim: jaredfromsubway.eth, one of Ethereum's most active sandwich-MEV bots (no individual users; treasury/bot capital drained, hence victims_identified=0). Attacker deployed 66 fake token contracts mimicking WETH/USDC/USDT plus sham liquidity pools to bait the bot's automated strategy into granting token approvals to attacker-controlled helper contracts. Funds were later swept via transferFrom. No phishing, no key compromise, no DeFi protocol bug involved — confirmed by Blockaid CTO Raz Niv.

Timeline: T-X (weeks prior to June 20, 2026): Attacker deploys and seasons 66 fake token wrapper contracts and sham liquidity pools designed to look like profitable arbitrage opportunities, specifically targeting the automated, trust-minimized decision logic used by MEV bots. T0 (June 20, 2026, ~18:49 UTC): The bot's automated strategy interacts with the bait contracts and grants token approvals to attacker helper contract 0xE93e8AA4e88359dACf33c491Cf5bD56eB6C110c1. T+minutes: Attacker sweeps WETH, USDC and USDT from the bot via transferFrom calls, consolidating into 0x3e37f4A10d771Ba9dE44b6d301410b1BEdeA65d0 and downstream addresses. T+same day: Analyst Specter and Blockaid publicly flag the drain on X (June 20, 2026); PeckShieldAlert confirms the approval-hijack vector. T+2 days (June 22, 2026): The bot operator posts an on-chain message offering 50% of the stolen assets (~2,150 ETH) for return within 48 hours; the attacker declines. The Block reports ~2,000 ETH routed through Tornado Cash the same day. T+2-3 days: ~1,422 ETH swapped for ~$2.45M DAI via DEX (CryptoPotato, Crypto Briefing, June 22-23). Status as of report compilation: Active/unrecovered, no attribution to any named threat actor by any authoritative security firm.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)