
The attacker behind the exploit targeting the Ethereum MEV bot Jaredfromsubway has reportedly continued laundering stolen funds through Tornado Cash, despite being offered a deal to return half the assets in exchange for a white hat bounty.
On chain activity shows the exploiter moved about 2,000 ETH through Tornado Cash, sold 1,422 ETH for roughly $2.4 million in DAI, and now holds only a small balance of around 5 ETH. The movements suggest the attacker is not engaging with recovery negotiations.
How the Exploit Worked
According to blockchain security firm PeckShield, the incident occurred on June 20 and resulted in the attacker draining significant assets, including 1,474 WETH, 2.87 million USDC, and 2 million USDT.
Security researchers at Blockaid explained that the attacker created fake wrapper tokens such as fWETH, fUSDC, and fUSDT, and paired them with counterfeit liquidity pools. These setups appeared legitimate to the bot’s automated MEV detection system, which is designed to identify profitable trading opportunities.
The bot then executed its normal process, approving transactions through helper contracts that initially behaved as expected during testing. However, the attacker later exploited these lingering approvals, allowing continued access to the bot’s funds without raising immediate alarms.
When the final stage was triggered, the attacker used standard transfer mechanisms to drain assets directly from the bot’s contract. Blockchain analyst RaFi described the operation as a sophisticated example of on chain social engineering rather than a traditional code exploit.
Failed Negotiations and Bounty Offers
After discovering the exploit, the operator of Jaredfromsubway attempted multiple recovery strategies. They first offered a $1 million reward for the return of funds, along with an additional bounty for anyone who could identify the attacker.
Later, the offer increased to a $3 million time sensitive bounty with assurances of confidentiality and no legal action. When no response followed, the operator escalated further, proposing to accept 2,150 ETH, roughly half of the stolen amount, if returned within 48 hours.
They also warned that failure to comply would lead to legal and law enforcement action.
Funds Moved Instead of Returned
Despite the offers, on chain tracking services such as Onchain Lens report that the attacker continued moving funds. Around 2,000 ETH was routed through Tornado Cash, while another 1,422 ETH was converted into DAI worth approximately $2.4 million. Only a minimal balance remained in the attacker’s wallet.
Ongoing Response and Industry Reaction
The bot operator recently claimed that a group identifying as white hat hackers had made contact and that discussions were ongoing, though no outcome has been confirmed.
Meanwhile, developers across the ecosystem continue exploring ways to reduce MEV related vulnerabilities. One proposed solution includes encrypted mempool designs, such as initiatives being explored in other blockchain ecosystems, aimed at hiding transaction details until execution to prevent similar exploits.#crypto#cryptonews https://coinsignals.net https://t.me/coinsignalpublic