Loading Date...
Daily Edition
Breaking
DeFi Security

Ethereum’s Largest ‘Sandwich’ Bot Exploited for $7.5 Million in Ironic Turn

A prominent Ethereum 'sandwich' bot, known for exploiting transaction ordering, has itself been exploited for $7.5 million. The attacker utilized fake trading routes to drain significant assets from the bot's operator.

4m Read Published June 22, 2026
Ethereum's Largest 'Sandwich' Bot Exploited for $7.5 Million in Ironic Turn

Ethereum ‘Sandwich’ Bot Falls Victim to $7.5 Million Exploit

In a twist of irony that has sent ripples through the decentralized finance (DeFi) community, one of Ethereum’s most prominent ‘sandwich’ bots has been drained of approximately $7.5 million. The exploit, detailed by blockchain security firm Blockaid, saw the attacker cleverly trick the bot’s operator, known by the ENS domain Jaredfromsubway.eth, into approving malicious trading routes. This allowed the attacker to siphon off substantial amounts of Wrapped Ether (WETH), USD Coin (USDC), and Tether (USDT).

Understanding Sandwich Bots

Sandwich bots are a controversial but prevalent feature in the DeFi ecosystem, particularly on decentralized exchanges (DEXs). They operate by exploiting the transparent nature of blockchain transaction orderings. A typical sandwich attack involves three key steps:

  • Monitoring Pending Transactions: The bot constantly scans the mempool for large buy or sell orders that are likely to cause a significant price movement on a DEX.
  • Front-Running the Trade: Before the victim’s transaction is executed, the bot places its own buy order. This order is strategically timed to occur just before the victim’s order.
  • Back-Running the Trade: After the victim’s large order is executed, causing the price to shift, the bot immediately places a sell order for the same asset, profiting from the price difference created by the victim’s trade and the bot’s initial front-running buy.

These operations essentially ‘sandwich’ the victim’s transaction between the bot’s two trades, hence the name. While profitable for the bot operator, they result in worse execution prices for the victim, a phenomenon often referred to as ‘slippage.’

The Ironic Exploit Unveiled

The recent incident represents a significant turning of the tables. Instead of being the predator, the sandwich bot became the prey. According to Blockaid’s analysis, the attacker did not exploit a flaw in the bot’s core logic or the underlying DEX. Instead, the exploit leveraged social engineering and deceptive smart contract interactions.

The attacker reportedly presented Jaredfromsubway.eth with seemingly legitimate, albeit fake, trading opportunities. By tricking the bot operator into signing approval transactions for these fraudulent routes, the attacker gained the necessary permissions to interact with the bot’s funds.

How the Funds Were Drained

Once the approvals were granted, the attacker executed a series of carefully orchestrated transactions. These transactions effectively rerouted the victim’s own assets away from the legitimate trading pools and into the attacker’s control. The core of the attack involved:

  • Deceptive Token Approvals: The operator approved malicious smart contracts under the guise of legitimate trading activities.
  • Exploiting Approval Permissions: The attacker utilized the ‘allowance’ granted by the victim to transfer assets directly from the bot’s wallet.
  • Strategic Asset Movement: The drained assets, primarily WETH, USDC, and USDT, were then moved to wallets controlled by the attacker, likely to be laundered or cashed out.

Implications for DeFi Security

This incident serves as a stark reminder of the evolving landscape of DeFi security. Exploits are not limited to traditional smart contract vulnerabilities; they increasingly involve sophisticated social engineering and the manipulation of user permissions.

For operators of high-value bots and DeFi participants in general, this highlights several crucial security practices:

  • Vigilance with Permissions: Never grant token approvals without thoroughly understanding the contract address and the associated permissions. Use tools that help analyze contract interactions before signing.
  • Multi-Signature Wallets: For significant holdings, employing multi-signature (multisig) wallets can add a critical layer of security, requiring multiple approvals for transactions.
  • Regular Audits: While this exploit targeted the operator rather than a protocol flaw, regular smart contract audits are fundamental for any DeFi entity.
  • Segregation of Funds: Keeping operational funds separate from personal or primary investment wallets can limit the damage in case of an individual compromise.

The $7.5 million loss underscores that even sophisticated players within the DeFi space are not immune to evolving attack vectors. The irony of a sandwich bot, designed to profit from transaction manipulation, being a victim of a similar, albeit more direct, exploit, emphasizes the constant need for heightened security awareness and robust defense mechanisms in the world of decentralized finance.

Share This Investigation

More From DeFi Security

View All
Weekly Briefing

The DeFi Breaking Intelligence Letter

Receive curated summaries of protocol adjustments, security audit reports, and structural on-chain changes. No spam, only analyzed metrics.

We protect your security. Unsubscribe at any time with a single click.