MEV Bot Developer JaredFromSubway Loses $15M to Hacker Attack on June 21

ETH1.58%
USDC0.02%

According to Blockaid, a MEV bot operated by developer JaredFromSubway.eth was compromised on June 21, draining approximately $15 million in assets including WETH, USDC, and USDT.

The attacker exploited a flaw in the bot's auto-execution mechanism by creating fraudulent token wrappers and liquidity pools. These constructs induced the bot to grant token approvals to attacker-controlled contracts. The attacker then utilized unrevoked approvals to transfer assets via transferFrom calls. Blockaid noted this was not a traditional phishing attack or smart contract vulnerability, but rather an exploitation of the bot's automated authorization issuance process.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments