Threat Intelligence JaredFromSubway MEV bot loses $15 million in exploit June 23, 2026 Share By SC Staff (Adobe Stock) Coverage from Bleeping Computer indicates that the JaredFromSubway Ethereum MEV bot experienced a significant financial loss of $15 million due to an attacker exploiting its opportunity-detection logic. The exploit, detected by blockchain security firm Blockaid, involved an attacker creating fake cryptocurrency trading opportunities using fabricated pools and tokens. These deceptive setups tricked the JaredFromSubway bot into approving helper contracts controlled by the attacker. The bot, designed for rapid identification and execution of profitable MEV opportunities, analyzed these fake routes, believing them to be financially rewarding. The attacker meticulously planned the heist, initially conducting harmless test transactions to confirm the bot's routines before altering the route to accumulate spending permissions without immediate use. Ultimately, the attacker leveraged these accumulated approvals to withdraw WETH, USDC, and USDT from the bot's contract. MEV bots like JaredFromSubway, known for aggressive "sandwich" attacks, scan blockchains for transaction timing advantages. JaredFromSubway initially offered a $3 million bounty for the return of funds, later increasing it to $7.5 million for 50% of the stolen amount, but has received no response. Negotiations with a "white-hat hacking group" are ongoing. Source: Bleeping Computer SC Staff Related Threat Intelligence Law enforcement disrupts SocGholish botnet and Evil Corp servers SC Staff June 18, 2026 Authorities from the Netherlands, Canada, the United States, and Germany removed the SocGholish malware and backdoors from 14,971 compromised WordPress websites, also taking 106 servers and domains offline. Threat Intelligence Attacker establishes persistent access to French business using OpenSSH and Tailscale SC Staff June 18, 2026 The attacker utilized a multi-stage in-memory malware chain, including a VBScript stager, a PowerShell loader, and Havoc's Demon agent, to gain initial access. Threat Intelligence China-linked group uses InfiniteRed malware to target medical research institutions SC Staff June 15, 2026 The attackers, identified as UNC6508, likely exploited older, vulnerable versions of REDCap to gain initial access, although the exact method remains undetermined. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Virtual Conference Securing the Future of Finance: Strategies to Counter Modern Cyber Threats On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Backdoor Deauthentication Attack Denial of Service Dictionary Attack Disruption Drive-by Download Fault Line Attacks Hybrid Attack Password Cracking Reconnaissance You can skip this ad in 5 seconds