Crypto Prices

Ethereum’s Sandwich Bot Phenomenon: $295 Million Earned, $7.5 Million Lost in a Single Attack

52 minutes ago
2 mins read
1 views

Ethereum Smart Contract Accumulation and Exploitation

Since March 2023, a specific Ethereum smart contract has accumulated an astonishing 117,000 ETH, nearly equivalent to $295 million at current exchange rates. Notably, in June this year, an unidentified hacker leveraged this very contract’s mechanisms to pull off a lucrative attack, netting $7.5 million in total.

The Attack Mechanism

The attack involved the creation of 66 fraudulent token contracts on the Ethereum network, masquerading as well-known assets such as WETH, USDC, and USDT. Instead of targeting unsuspecting retail investors, the hacker set their sights on Jaredfromsubway.eth, a notorious player in the sandwich attack sphere—an operation that consistently profits by exploiting the timing of trades on decentralized exchanges.

As the attack unfolded, the bot’s automated trading algorithms—designed to identify potential arbitrage opportunities—approved token-spending transactions for the hacker’s false contracts.

With these approvals in place, the hacker executed a series of transactions, successfully draining the bot’s legitimate holdings of approximately $7.5 million worth of ETH and stablecoins. Post-exploitation, the hacker utilized Tornado Cash to launder the misappropriated funds, and to date, recovery efforts have been unsuccessful.

Impact on the Ethereum Community

This turn of events has not gone unnoticed in the Ethereum research community, highlighting the paradox of a bot originally designed to exploit other traders becoming a victim of its own tactics due to a similar exploitative mechanism.

The business model of sandwich attacks—the most exploitative version of what is known as Maximal Extractable Value (MEV)—has ballooned considerably. Since its first withdrawal reported in March 2023, this bot’s total ETH intake, now at 117,007 ETH as of August 28, marks a significant and steady ascent.

Understanding Maximal Extractable Value (MEV)

MEV refers to the profits that miners or any entity influencing transaction order within a block can extract by manipulating the sequence of transactions. This manipulation is possible due to the visibility of Ethereum’s mempool, where pending transactions sit before being confirmed. Knowing this, anyone can spot sizeable trades and play the system by stepping in with their own orders, often to the detriment of the original trader’s ability to capitalize fully.

The sandwich attack itself is a prominent illustration of MEV, where a bot detects a large trade, places its order just before the victim’s, and takes advantage of the resulting price fluctuation as a profit mechanism. Without any direct hack or contractual exploitation, this strategy is purely transactional and occurs frequently in today’s trading environment.

The Evolution of MEV and Its Challenges

While MEV is not a new concept—having been discussed by industry experts since 2019—the establishment of Flashbots in 2020 transformed the landscape by introducing a private auction framework for MEV. This system was intended to minimize the chaotic nature of public mempool transactions, a space previously described as a “dark forest.” The launch of MEV-Boost with Ethereum’s transition to a proof-of-stake mechanism further streamlined this process, making it a standard method for constructing blocks on the Ethereum network.

However, the competition within this framework raises concerns about centralization. Presently, a few entities control a significant majority of block proposals. According to data from relayscan.io, three major relays account for over 85% of the payloads processed within MEV-Boost, with a single builder controlling over half the block constructions. This centralization poses risks as it enables selective transaction ordering, undermining competition.

Future of Sandwich Attacks and MEV

Despite the striking figures surrounding these bots like Jaredfromsubway, the broader environment for sandwich attacks appears to be contracting. From around $10 million per month in late 2024, monthly earnings from these exploitative strategies have fallen to approximately $2.5 million by October 2025, thanks largely to the adoption of MEV protection tools by traders. These tools, which include private RPCs and order-flow auctions, keep transaction data out of the public view and thwart sandwich bots.

Nonetheless, during the peak of this strategy, sandwich attacks were still costing traders an estimated $60 million annually, illustrating how these systems continue to benefit block builders through the priority fees they earn.

Looking toward the future, the proposed enshrined proposer-builder separation (ePBS) module, which is part of the anticipated Glamsterdam upgrade, aims to incorporate MEV-Boost into Ethereum’s core protocols. This shift would eliminate reliance on external relays, thereby enhancing validators’ assurances regarding block contents through cryptographic guarantees. Until such upgrades are implemented, uncertainties regarding the full implications of MEV on Ethereum’s network will persist.

Popular