The attacker behind the exploit that drained the JaredFromSubway MEV bot has lost roughly $505,000 mistiming trades with the stolen funds, according to on-chain tracker Lookonchain. About a month after converting the stolen assets to ETH, the exploiter sold 2,327 ETH for $3.94 million at a price of $1,695, then bought back 2,063 ETH for the same $3.94 million at $1,912 roughly ten hours later — a round trip that cost them 264 ETH, worth about $505,000 at current prices.
The underlying exploit that produced those funds was itself a notable story in Ethereum's MEV ecosystem. JaredFromSubway.eth operated one of the most active MEV bots on Ethereum, extracting tens of millions of dollars from traders since 2023 through sandwich attacks — a controversial but common MEV strategy that front-runs and back-runs victims' trades to capture the price difference. In June, an unknown attacker deployed 66 fake token contracts to trick the bot into granting spending approvals to malicious helper contracts, then swept its real holdings in a single coordinated transaction, draining an estimated $15 million.
A bounty that went nowhere
JaredFromSubway initially offered a $3 million bounty for the return of the stolen funds, later raising the offer to $7.5 million — 50% of the stolen total — in exchange for giving back the rest. The attacker never responded, instead routing the funds toward Tornado Cash, the crypto mixer used to obscure the trail of stolen assets. No funds have been recovered.
The irony wasn't lost on the community
JaredFromSubway's bot had itself extracted value from ordinary traders for years through sandwich attacks before becoming the victim of a more sophisticated exploit — a reversal that drew widespread commentary when the hack was first disclosed. The latest on-chain data adds a second layer of irony: after successfully stealing millions from one of Ethereum's most notorious extraction operations, the attacker has now given back a meaningful chunk of the haul through ordinary bad trade timing, the same kind of market risk MEV bots are typically built to exploit rather than fall victim to.
Related: Researcher Hacked North Korea's Hackers, Found 1,640 Breached Firms