The Theft: Exploiting the MEV Bot
Published 6/21/2026, 6:12:42 AM
The $7.7M in stolen crypto ended up in Tornado Cash following a sophisticated "honeypot" exploit targeting the high-profile MEV bot jaredfromsubway.eth in June 2026. The attacker lured the bot into interacting with fraudulent token contracts, drained its accumulated profits, and systematically laundered the proceeds through the privacy protocol to break the on-chain link to the theft.
The Theft: Exploiting the MEV Bot
The source of the funds was the jaredfromsubway.eth bot (address: 0xae2fc483527b8ef99eb5d9b44875f005ba1fae13), which had gained notoriety for extracting millions from retail traders via sandwich attacks [Source: https://x.com/lookonchain?lang=en].
On June 21, 2026, an attacker deployed a "fake-token routes" strategy. They created 66 fraudulent token contracts and liquidity pools designed to appear as profitable arbitrage opportunities to the bot's automated logic [Note: the specific number of 66 contracts is not independently verified]. When the bot attempted to "sandwich" these trades, it granted token approvals to attacker-controlled helper contracts, allowing the attacker to drain the bot's holdings in a single transaction [Source: https://x.com/lookonchain?lang=en].
Flow of Funds
The attacker extracted a mix of stablecoins and wrapped assets, which were then consolidated into Ethereum (ETH) before being moved to Tornado Cash.
| Phase | Action | Assets Involved |
|---|---|---|
| Extraction | Drained from bot contracts | 1,474 WETH, 2.87M USDC, 2M USDT |
| Conversion | Swapped to native ETH | ~4,427 ETH total |
| Laundering | Initial Tornado Cash Deposit | 1,000 ETH [Source: https://coinfomania.com/inside-lookonchains-exploit-revelation-what-it-means-for-security/] |
| Residual | Secondary transfers | ~3,427 ETH moved to intermediate wallets |
Tornado Cash Deposit Mechanics
The attacker utilized Tornado Cash's privacy features to obscure the destination of the stolen $7.7M:
- Fixed Denominations: The attacker processed the initial 1,000 ETH through the 100 ETH pool, the protocol's largest standard denomination. This required ten separate deposits, allowing the funds to blend into a large "anonymity set" of other users' deposits.
- Zero-Knowledge Proofs: By depositing into the pool, the attacker generated a private "note." To withdraw these funds to a new, clean wallet, they provided a ZK-SNARK proof that they held a valid note without revealing which specific deposit it originated from.
- Relayer Usage: To ensure the new withdrawal wallets had no on-chain history, the attacker likely used Relayers. These third parties pay the gas fees for the withdrawal in exchange for a small fee, preventing any "dust" (small amounts of ETH) from a known source from linking the new wallet to the exploit.
Regulatory Context
This incident occurred during a period of resurgence for the protocol. Following a March 21, 2025, delisting by OFAC (triggered by the Van Loon v. Treasury ruling), Tornado Cash's market share recovered to over 40% of all mixer volume by late 2025 [Source: https://www.venable.com/insights/publications/2025/04/a-legal-whirlwind-settles-treasury-lifts-sanctions]. Despite this, the DOJ has continued to target large-scale laundering, including a $7.74M forfeiture case in June 2025 involving North Korean IT worker networks using similar mixing techniques [Source: https://cryptonews.com/tags/north-korea/page/2/].
In summary, the $7.7M moved from the MEV bot to the attacker via a honeypot exploit, was converted to 4,427 ETH, and at least 1,000 ETH was immediately laundered through Tornado Cash's 100 ETH pools to anonymize the trail.