• bitcoinBitcoin (BTC) $ 64,224.00
  • ethereumEthereum (ETH) $ 1,732.52
  • tetherTether (USDT) $ 0.998824
  • bnbBNB (BNB) $ 590.23
  • usd-coinUSDC (USDC) $ 0.999806
  • xrpXRP (XRP) $ 1.15
  • solanaSolana (SOL) $ 74.01
  • tronTRON (TRX) $ 0.326717
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • hyperliquidHyperliquid (HYPE) $ 68.26
  • dogecoinDogecoin (DOGE) $ 0.083279
  • usdsUSDS (USDS) $ 0.999656
  • rainRain (RAIN) $ 0.014433
  • leo-tokenLEO Token (LEO) $ 9.51
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • zcashZcash (ZEC) $ 459.55
  • stellarStellar (XLM) $ 0.213583
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • whitebitWhiteBIT Coin (WBT) $ 52.69
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • moneroMonero (XMR) $ 322.91
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • cardanoCardano (ADA) $ 0.162152
  • canton-networkCanton (CC) $ 0.154968
  • chainlinkChainlink (LINK) $ 7.98
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • usd1-wlfiUSD1 (USD1) $ 0.999437
  • labLAB (LAB) $ 15.48
  • the-open-networkGram (prev. Toncoin) (GRAM) $ 1.69
  • susdssUSDS (SUSDS) $ 1.08
  • ethena-usdeEthena USDe (USDE) $ 0.998793
  • daiDai (DAI) $ 0.999798
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • bitcoin-cashBitcoin Cash (BCH) $ 198.35
  • memecoreMemeCore (M) $ 2.84
  • litecoinLitecoin (LTC) $ 45.14
  • wethWETH (WETH) $ 2,268.37
  • hedera-hashgraphHedera (HBAR) $ 0.079964
  • hashnote-usycCircle USYC (USYC) $ 1.13
  • nearNEAR Protocol (NEAR) $ 2.25
  • usdt0USDT0 (USDT0) $ 0.998824
  • suiSui (SUI) $ 0.711283
  • global-dollarGlobal Dollar (USDG) $ 0.999918
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • shiba-inuShiba Inu (SHIB) $ 0.000005
  • crypto-com-chainCronos (CRO) $ 0.059183
  • avalanche-2Avalanche (AVAX) $ 6.28
  • tether-goldTether Gold (XAUT) $ 4,144.63
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • bittensorBittensor (TAO) $ 237.14
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.14
  • worldcoin-wldWorldcoin (WLD) $ 0.603705
  • uniswapUniswap (UNI) $ 3.04
  • pax-goldPAX Gold (PAXG) $ 4,155.17
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.058231
  • mantleMantle (MNT) $ 0.532574
  • aster-2Aster (ASTER) $ 0.644631
  • ondo-financeOndo (ONDO) $ 0.340083
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • polkadotPolkadot (DOT) $ 0.972086
  • ripple-usdRipple USD (RLUSD) $ 0.999821
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • okbOKB (OKB) $ 75.99
  • htx-daoHTX DAO (HTX) $ 0.000002
  • falcon-financeFalcon USD (USDF) $ 0.993486
  • pi-networkPi Network (PI) $ 0.134936
  • skySky (SKY) $ 0.059147
  • usddUSDD (USDD) $ 0.999034
  • bfusdBFUSD (BFUSD) $ 0.998912
  • internet-computerInternet Computer (ICP) $ 2.29
  • bitget-tokenBitget Token (BGB) $ 1.77
  • morphoMorpho (MORPHO) $ 1.86
  • pepePepe (PEPE) $ 0.000003
  • ethereum-classicEthereum Classic (ETC) $ 7.43
  • aaveAave (AAVE) $ 74.85
  • quant-networkQuant (QNT) $ 70.59
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • united-stablesUnited Stables (U) $ 0.999940
  • superstate-short-duration-us-government-securities-fund-ustbInvesco Short Duration US Government Securities Fund (USTB) $ 11.12
  • kucoin-sharesKuCoin (KCS) $ 7.25
  • blockchain-capitalBlockchain Capital (BCAP) $ 107.07
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.21
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • cosmosCosmos Hub (ATOM) $ 1.78
  • usdtbUSDtb (USDTB) $ 0.999872
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • render-tokenRender (RENDER) $ 1.70
  • ethenaEthena (ENA) $ 0.093436
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.11
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.079397
  • algorandAlgorand (ALGO) $ 0.093465
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • stable-2​​Stable (STABLE) $ 0.034762
  • kaspaKaspa (KAS) $ 0.029857
  • wbnbWrapped BNB (WBNB) $ 759.61
  • nexoNEXO (NEXO) $ 0.794865
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • jupiter-exchange-solanaJupiter (JUP) $ 0.224582
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.04
  • gatechain-tokenGate (GT) $ 6.78
  • justJUST (JST) $ 0.083113
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.703845
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • venice-tokenVenice Token (VVV) $ 14.38
  • dexeDeXe (DEXE) $ 14.21
  • flare-networksFlare (FLR) $ 0.007408
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • filecoinFilecoin (FIL) $ 0.798995
  • beldexBeldex (BDX) $ 0.079459
  • ghoGHO (GHO) $ 0.998140
  • xdce-crowd-saleXDC Network (XDC) $ 0.029576
  • yldsYLDS (YLDS) $ 0.999747
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.15
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • hash-2Provenance Blockchain (HASH) $ 0.010204
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • usual-usdUsual USD (USD0) $ 0.999218
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • aptosAptos (APT) $ 0.662723
  • midnight-3Midnight (NIGHT) $ 0.032809
  • arbitrumArbitrum (ARB) $ 0.084416
  • clbtcclBTC (CLBTC) $ 76,920.00
  • pump-funPump.fun (PUMP) $ 0.001501
  • aerodrome-financeAerodrome Finance (AERO) $ 0.540827
  • adi-tokenADI (ADI) $ 4.11
  • a7a5A7A5 (A7A5) $ 0.012964
  • usxUSX (USX) $ 0.999414
  • injective-protocolInjective (INJ) $ 5.05
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • true-usdTrueUSD (TUSD) $ 0.998179
  • audieraAudiera (BEAT) $ 1.71
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • ousgOndo Short-Term U.S. Government Bond Fund (OUSG) $ 115.61
  • tbtctBTC (TBTC) $ 70,942.00
  • dashDash (DASH) $ 36.67
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.39
  • euro-coinEURC (EURC) $ 1.15
  • official-trumpOfficial Trump (TRUMP) $ 1.83
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006834
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.188354
  • vechainVeChain (VET) $ 0.004936
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • bonkBonk (BONK) $ 0.000005
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.608170
  • lighterLighter (LIT) $ 1.60
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • hastra-primePRIME (PRIME) $ 1.04
  • kite-2Kite (KITE) $ 0.165674
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000068
  • sei-networkSei (SEI) $ 0.055032
  • apxusdapxUSD (APXUSD) $ 0.889661
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • humanityHumanity (H) $ 0.194954
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • celestiaCelestia (TIA) $ 0.377433
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998038
  • jito-governance-tokenJito (JTO) $ 0.718296
  • the9bitThe9bit (9BIT) $ 0.042627
  • spx6900SPX6900 (SPX) $ 0.373071
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • blockstackStacks (STX) $ 0.183611
  • sun-tokenSun Token (SUN) $ 0.017228
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • skyaiSkyAI (SKYAI) $ 0.331356
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • curve-dao-tokenCurve DAO (CRV) $ 0.215486
  • ether-fiEther.fi (ETHFI) $ 0.352454
  • kinesis-goldKinesis Gold (KAU) $ 136.01
  • pyth-networkPyth Network (PYTH) $ 0.037426
  • gnosisGnosis (GNO) $ 108.57
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • apenftAINFT (NFT) $ 0.00000027
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • usdgoUSDGO (USDGO) $ 0.999782
  • doublezeroDoubleZero (2Z) $ 0.074848
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • bittorrentBitTorrent (BTT) $ 0.00000026
  • noonNoon (NOON) $ 0.751949
  • grassGrass (GRASS) $ 0.419161
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • tezosTezos (XTZ) $ 0.234783
  • pendlePendle (PENDLE) $ 1.48
  • royal-dollarRoyal Dollar (RUSD) $ 1.00
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • flokiFLOKI (FLOKI) $ 0.000026
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • conflux-tokenConflux (CFX) $ 0.047812
  • plasmaPlasma (XPL) $ 0.098318
  • monadMonad (MON) $ 0.020753
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • zebec-networkZebec Network (ZBCN) $ 0.002468

JaredFromSubway MEV bot gets drained in $7.5m approval trap

0 0


Ethereum’s well-known MEV bot JaredFromSubway was drained after an attacker used contracts that made its automated trading system grant token approvals, according to Blockaid.

Summary
  • Blockaid says attacker-controlled contracts tricked JaredFromSubway’s automated system into granting approvals later used for draining.
  • Jared publicly claimed a $15 million loss, while Blockaid’s public estimate stood near $7.5 million.
  • Crypto.news previously tied JaredFromSubway to Vitalik Buterin’s swap and heavy Ethereum gas use in 2023.

The security firm said the incident was not a normal phishing case and not a direct bug in the victim contract. 

“This is not a classic phishing attack and not a traditional smart-contract vulnerability in the victim contract,” Blockaid said. 

The firm said the bot approved attacker-controlled contracts during routes that appeared to be profitable MEV trades.

Blockaid says approvals stayed open

Blockaid said the attacker first tested routes where approvals were used at once, leaving no open allowance. Later, the attacker changed the route design so the bot gave approvals that were not spent or revoked.

One example cited by Blockaid involved an approval of about 92.16 WETH to an attacker helper contract. Etherscan data for the transaction showed jaredfromsubway.eth interacting with its MEV Bot 2 contract before the later sweep. The transaction record also showed ERC-20 movements tied to the same automated route.

Final sweep hit WETH, USDC and USDT

The final transaction used the open approvals to pull WETH, USDC and USDT from the JaredFromSubway MEV bot contract through transferFrom. Etherscan showed transfers from “jaredfromsubway: MEV Bot 2” to the attacker wallet beginning with 0x3e37.

Blockaid put the drained amount at about $7.5 million. The JaredFromSubway account later claimed the loss was $15 million and offered a $1 million bounty for the full return of the funds. That difference has not been fully explained in the public posts reviewed.

How the attacker turned the bot’s logic against it

The attack appears to have targeted the bot’s own trading workflow. MEV bots watch Ethereum activity and act on transactions that look profitable. In this case, attacker-controlled contracts made the route look useful enough for the bot to approve spending rights.

The attacker used 66 fake token contracts that copied the look and function of WETH, USDC and USDT. These contracts were paired with fake liquidity pools. The setup pushed the bot toward approvals that later became the path for the drain.

JaredFromSubway’s record is back in focus

JaredFromSubway is one of Ethereum’s most watched sandwich bots. In a sandwich attack, a bot places trades before and after a user’s swap. This can give the user a worse price while the bot captures the spread.

As previously reported by crypto.news, JaredFromSubway targeted a small swap by Ethereum co-founder Vitalik Buterin in April, using about $1.14 million in WETH volume across SushiSwap and Uniswap V2. Crypto.news also reported in 2023 that the bot used 455 ETH in gas within 24 hours and accounted for about 7% of Ethereum gas use during that period.

The exploit now puts attention on token approvals used by automated systems. The case shows how a system built to act quickly on open market data can be steered into unsafe permissions when controls around approvals are weak. It also adds a new chapter to the wider debate over MEV, sandwich trades and user protection on Ethereum.

For now, the key public details remain split between Blockaid’s technical thread, the on-chain records and posts from the JaredFromSubway account. No recovery had been confirmed in the reviewed updates.



Source link

Leave A Reply

Your email address will not be published.