Ethereum MEV-Bot Hacker Turns $7.7M Heist Into a $505K Trading Loss
The unknown attacker behind June's exploit of the jaredfromsubway.eth sandwich bot sold ETH low after the hack, then bought it back thousands of dollars higher — shrinking their own haul.
By Jane Doe
Published on Aug 8, 2026
Quick Take
- An unidentified hacker exploited the jaredfromsubway.eth MEV (sandwich) bot on June 20–21, taking roughly $7.7 million using fake liquidity pools and deceptive tokens.
- After the hack, the attacker sold 2,327 ETH at prices just under $1,700, netting about $3.94 million.
- They later reversed course, buying back 2,063 ETH at an average of $1,912 — 264 fewer tokens for the same money.
- Net result of that round trip: a booked loss of about $505,000, on top of funds never returned despite a bounty offer.
What Happened
Roughly a month before this trade was flagged, an unknown attacker exploited jaredfromsubway.eth, a bot known for running MEV "sandwich" trades on Ethereum. On June 20–21, the attacker tricked the bot's automated systems using fake liquidity pools and deceptive tokens, extracting an estimated $7.7 million.
The stolen funds were moved through Tornado Cash, a privacy mixer, almost immediately after the exploit — a step that makes tracing and recovering funds significantly harder.
Since then, on-chain trackers (cited in the source as Lookonchain) have continued to watch the attacker's ETH moves. The latest activity shows the hacker selling ETH shortly after the hack and buying it back weeks later — but at a materially higher price.
Background: What is an MEV "sandwich" bot?
MEV (maximal extractable value) bots are automated programs that scan pending Ethereum transactions and insert their own trades before and after a target transaction to profit from the resulting price movement — commonly called "sandwiching." These bots operate constantly across decentralized exchanges and are themselves frequent targets for exploits, since they hold liquidity and execute trades autonomously with limited human oversight.
Why It Matters
MEV bots are often framed as predators that extract value from ordinary traders' transactions, so an exploit against one of them draws a different kind of attention than a typical DeFi hack — some in the community treat it as poetic rather than purely a crime story. But the underlying mechanics are the same as any exploit: fake liquidity and deceptive tokens were enough to trick a sophisticated automated system out of $7.7 million, underscoring that smart contract-interacting bots remain vulnerable to spoofed on-chain conditions.
The trading loss angle adds a second layer: even a successful hacker isn't necessarily a good trader. Selling into weakness and buying back into strength cost this attacker roughly half a million dollars of their own stolen proceeds — money that, notably, still hasn't been returned to the MEV bot's operators.
The Numbers
Methodology & sourcing notes
All figures above come directly from the source article, which attributes the on-chain trade data to the blockchain analytics tracker Lookonchain. The $3.94 million sale proceeds and 264-token shortfall on buyback are as stated in the source; the $505,000 loss figure is the source's own stated result of comparing sale proceeds to buyback cost.
Market Reaction
The source frames this purely as a story about the attacker's own trading decisions rather than a broader market reaction — there's no indication in the source that this individual's ETH movements affected Ethereum's price at large. The only price context given is the two levels tied to the hacker's own trades: an exit near $1,700 and a re-entry near $1,912.
What's Next / Things to Watch
- Bounty deadline has passed: The MEV bot's operators had offered the attacker a 50% bounty with a 48-hour window to return funds, or face "all available legal and law-enforcement remedies." The source confirms there has been no official response and no funds returned.
- Continued on-chain tracking: The source indicates trackers like Lookonchain are continuing to monitor the hacker's wallet activity, which is how this trading-loss episode came to light in the first place.
- Tornado Cash trail: Funds were already routed through Tornado Cash, which the source implies complicates any recovery or law-enforcement action, though it does not confirm any specific investigation is underway.
FAQs
How much did the jaredfromsubway.eth MEV bot lose in the exploit?
Around $7.7 million, taken via fake liquidity pools and deceptive tokens on June 20–21.
Why did the hacker lose money after already stealing millions?
They sold 2,327 ETH shortly after the hack at prices just under $1,700, then later bought back 2,063 ETH at an average of $1,912 — paying more per coin than they received, for fewer tokens, booking a roughly $505,000 loss on the round trip.
Did the attacker return any of the stolen funds?
No. Despite a 50% bounty offer with a 48-hour deadline from the bot's operators, the source confirms there has been no official response and none of the funds have been returned.
What is jaredfromsubway.eth?
It's the on-chain identity of a known Ethereum MEV ("sandwich") bot that automates trades around other users' pending transactions.
Where did the stolen ETH go?
The source states the attacker moved millions of dollars through Tornado Cash immediately after the hack.
- On-chain trade data attributed to Lookonchain, as cited in the source article. No direct URL to the Lookonchain data was provided in the source.
Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.