Summary
JaredfromSubway.eth, the most prolific sandwich-attack bot on Ethereum, was drained of at least $7.5 million in a reverse honeypot exploit on June 20–21, 2026.
An unknown attacker deployed 66 fake token contracts to trick the bot into granting token-spending approvals, then swept its real assets in a single coordinated transaction.
The stolen funds — ETH and stablecoins — were converted to ETH and sent to Tornado Cash. No funds have been recovered.
The exploit underscores the importance of revoking unused approvals and vetting smart contracts before interacting with them on-chain.












