The MeV robot JaredFromSubway, known for its links, was attacked over the weekend and about $7.5 million was transferred. The incident was not a traditional contractual loophole, but rather a series of carefully designed transactions by the attackers to induce robots to expose the logic of authorization and eventually gain control over part of the funds.

The authorization to use the attack was not withdrawn in time

Block Chain Security Blockaid stated that the attackers had first created seemingly profitable trading opportunities with counterfeit tokens and fraudulent smart contracts to attract the robot. JaredFromSubway continuously scans arbitrable transactions in the Taifung and, for part of its operations, it needs temporary authorization to transfer funds from an outside address.

The problem was not consistent with the mandate. Once part of the transaction has been completed, the relevant authority will be revoked immediately, but the subsequent build-up of the attacker did not trigger the process, which resulted in the site controlled by the attacker remaining in control. Blockaid believes that this is the key to the further transfer of funds.

Operator proposes 48 hours for return

The information on the chain indicates that the robot operator then sent a message to the assailant, suggesting that 2,150 ETHs would be returned within 48 hours and would receive a "50% white hat reward". At current prices, this part of ETH is approximately $3.7 million. If the counterparty refuses to return, the operator states that it will seek legal means and contact law enforcement authorities.

However, community responses to this statement are complex. Jared FromSubway has been well known in the past for the frequent use of “slammed attacks” and such tactics are usually included in the MEV category. The practice is to insert an order before and after the confirmation of the transaction, thereby affecting the value of the transaction and making a profit for the user, and is therefore a long-standing dispute.

Some of the assets were transferred to Tornado Cash

Another security agency, Peck Shield, stated that the attackers had converted some of their assets after stealing packaging to the south and stable currency and transferred some of them to Tornado Cash. The tool is often used to confuse financial flows along the chain, making follow-up more difficult.

MEV is the abbreviation of “maximum recoverable value” and usually refers to additional proceeds obtained by a certifier or other chain participant by adjusting the order of the transaction. Jared FromSubway has been one of the more active associated robots in the Taifung for many years, and this loss also shows that even the chain participants who have long relied on automation strategies to profit can be used in the opposite direction because of delegation of authority failures.