The attacker moved 2,000 ETH through Tornado Cash and sold 1,422 ETH for $2.4M in DAI, with just 5 ETH left in their wallet.The attacker moved 2,000 ETH through Tornado Cash and sold 1,422 ETH for $2.4M in DAI, with just 5 ETH left in their wallet.

Jaredfromsubway Hacker Ignores 50% Bounty, Routes Funds to Tornado Cash

2026/06/24 04:37
Okuma süresi: 3 dk
Bu içerikle ilgili geri bildirim veya endişeleriniz için lütfen crypto.news@mexc.com üzerinden bizimle iletişime geçin.

The attacker behind the exploit of Ethereum MEV bot Jaredfromsubway has moved millions of dollars through Tornado Cash, despite a public offer to return half the stolen funds in exchange for a white-hat bounty.

The transfer suggests that the attacker may have little interest in negotiating, even with the bot’s operator offering rewards and claiming that they have had discussions with potential recovery groups.

How the Bot Got Beaten at Its Own Game

The exploit, according to Peckshield, happened on June 20 and netted the attacker 1,474 WETH, 2.87 million USDC, and 2 million USDT, with apparently no code being broken.

Another blockchain security firm, Blockaid, explained that the person responsible built a number of fake wrapper tokens, including fWETH, fUSDC, and fUSDT, and paired them with fake liquidity pools that appeared to the bot’s automated scanning system as profitable MEV opportunities.

It then did exactly what it was designed to do: spot a supposedly juicy trade and grant token approvals to the attacker’s helper contracts. Per Blockaid’s analysis, during early test transactions, those approvals were consumed normally, meaning nothing flagged as suspicious. Later, the exploiter crafted routes where the bot kept granting approvals that were never revoked, building up spending rights over the bot’s holdings in the process while waiting for the right moment.

When that moment finally came, the attacker’s contract used those open approvals to pull WETH, USDC, and USDT directly from the Jaredfromsubway contract using standard transferFrom calls. Crypto researcher RaFi, who posted a detailed thread about the incident, described it as a “masterclass in social engineering on-chain.”

The bot’s operator’s response came in waves. They first offered a $1 million reward to the hacker to return the stolen money and another $50,000 for anyone that could help them find the attacker. Soon after, they offered a $3 million “time-sensitive” bounty for the funds, promising full confidentiality and no questions asked.

With no discernible response coming, the Jaredfromsubway operator decided to send an on-chain message saying that they would accept 2,150 ETH, which is about 50% of the haul, and gave the attacker 48 hours to respond, with plans to “pursue all available legal and law-enforcement remedies” if the deadline passed without a return.

But the attacker seems to have given a response of a kind, with Onchain Lens reporting that they recently moved 2,000 ETH, worth about $3.4 million, through Tornado Cash. They are also said to have sold 1,422 ETH for around $2.4 million in DAI, and had only 5 ETH remaining in their wallet.

White-Hat Contact

As of the most recent update, the bot runner said that a self-described white-hat group had made contact and that negotiations were ongoing, although nothing had been confirmed.

Blockchain developers have been trying to find ways to reduce MEV activity, one such method being a proposal by Aptos to encrypt mempool systems so as to keep transactions private until they are executed.

The post Jaredfromsubway Hacker Ignores 50% Bounty, Routes Funds to Tornado Cash appeared first on CryptoPotato.

Piyasa Fırsatı
Ethereum Logosu
Ethereum Fiyatı(ETH)
$1,664.43
$1,664.43$1,664.43
+0.27%
USD
Ethereum (ETH) Canlı Fiyat Grafiği

CHZ +28%! Will History Repeat?

CHZ +28%! Will History Repeat?CHZ +28%! Will History Repeat?

0-fee opening long & short. Be ready for any move!

Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen crypto.news@mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

World Cup Combo: Aim for 200x

World Cup Combo: Aim for 200xWorld Cup Combo: Aim for 200x

Combine up to 20 World Cup matches in one order