AuditAid blog

Notes on smart contract & ZK security

Vulnerability deep-dives, audit methodology, and what we learn building an AI auditor for Solidity and zero-knowledge systems.

Dangling Approvals: The $7.5M JaredFromSubway Counter-MEV Honeypot

Ethereum's most prolific sandwich bot was drained for ~$7.5M — not by a key leak or a protocol bug, but by its own profit logic. A technical post-mortem: what the on-chain transfers reveal, the assumptions that got it drained, and why 'approve exact amounts' wouldn't have saved it.

June 24, 2026 · 10 min read

← Back to home