The well-known MEV bot JaredFromSubway, operating on the Ethereum blockchain, lost $7.5 million in an attack involving malicious approvals. The incident occurred on June 22, 2026, and was confirmed by multiple blockchain security sources.
How the Attack Happened
Attackers used malicious approvals to gain access to funds held in the bot's contract. MEV bots like JaredFromSubway automate the search for profitable opportunities on Ethereum, but their complex contracts can contain vulnerabilities. In this case, the attackers managed to bypass security and withdraw assets.
Why This Matters for Stablecoin Users
Although the incident directly involves MEV bots, it highlights the risks associated with token approvals. Many users, especially when interacting with decentralized exchanges, grant unlimited approvals for token spending. If the approved contract is compromised, an attacker can drain all your funds.
Practical Tips for USDT and Other Stablecoin Users
- Revoke unnecessary approvals: Use services like Etherscan Token Approval or Revoke.cash to regularly check and revoke approvals for suspicious contracts.
- Choose networks with lower fees: Attacks on Ethereum are often costly due to high gas fees. Transferring USDT on the TRC-20 network (Tron) can reduce risks associated with complex Ethereum contracts.
- Use hardware wallets: For large stablecoin holdings, consider cold storage with limited approvals.
Conclusion
The JaredFromSubway incident is another reminder that security in DeFi requires constant vigilance. At VirtCardPay, we recommend users carefully manage approvals and choose networks with an optimal balance of speed, fees, and security. For daily USDT transactions, the TRC-20 network offers low fees and high speed, minimizing the attack surface.
A virtual card in 2 minutes
Pay for subscriptions, AI tools, travel, and international stores. Top up via USDT-TRC20 with no acquiring fees.