QooryBeta
Back to narratives
SecurityEmerging
Conversation intelligence

Polymarket and JaredFromSubway MEV bot suffer security incidents

Two separate security incidents in the crypto space: Polymarket's frontend was compromised via a third-party vendor, leading to ~$2.9M in user funds stolen. Meanwhile, the JaredFromSubway MEV bot was exploited, resulting in a loss of 4,424 ETH (~$7.5M).

Heat
116
Confidence
90%
Evidence
6
Updated

Why It Happened

Polymarket breach originated from a compromised third-party vendor, highlighting supply chain attack risks. The JaredFromSubway exploit involved a vulnerability in the MEV bot's code, as analyzed by CertiK.

Outcome So Far

Polymarket has committed to reimbursing all affected users. The JaredFromSubway exploit details are under analysis.

Actors

Timeline order

Post
Parent event 01

X conversation update

1 related posts from @ShibainuCoin

Related posts@ShibainuCoin
@ShibainuCoin
Open on X0 views · 1.9K likes · 423 reposts

Post
Parent event 02

X conversation update

1 related posts from @mikebelshe

Related posts@mikebelshe
@mikebelshe
Open on X238.9K views · 482 likes · 26 reposts

Post
Parent event 03

JaredFromSubway MEV bot exploited for ~$7.5M

On June 20, the JaredFromSubway MEV bot was exploited, losing 4,424 ETH (~$7.5M). CertiK published a full analysis.

Related posts@CertiKAlert@IntCyberDigest
@CertiKAlert
Open on X4.1K views · 22 likes · 4 reposts
@IntCyberDigest
Open on X1.6K views · 20 likes · 1 reposts

Post
Parent event 04

X conversation update

2 related posts from @WhiteHatMage, @zippy257

Related posts@WhiteHatMage@zippy257
@WhiteHatMage
Open on X1.5K views · 88 likes · 9 reposts
@zippy257
Open on X830 views · 34 likes · 8 reposts