JaredFromSubway exploiter moves 2,000 ETH via Tornado Cash
The JaredFromSubway exploiter moved 2,000 ETH through Tornado Cash and swapped 1,422 ETH for DAI, raising fresh questions about laundering and post-exploit risk.
The wallet linked to the JaredFromSubway MEV bot exploiter has moved 2,000 ETH through Tornado Cash and separately swapped 1,422 ETH for DAI, signaling active post-exploit fund dispersal rather than dormant holdings.
What the on-chain data shows
Blockchain records reveal two distinct operations from the JaredFromSubway-linked wallet. The first routed 2,000 ETH through Tornado Cash, the Ethereum mixing protocol used to obscure transaction trails. The second converted a 1,422 ETH tranche into DAI, the decentralized stablecoin.
TLDR: KEY POINTS
- 2,000 ETH moved through Tornado Cash to obscure the fund trail
- 1,422 ETH swapped for DAI in a separate transaction
- The activity pattern indicates active fund management, not a dormant exploit wallet
The two-step approach, mixing a portion while converting another to stablecoins, is consistent with deliberate post-exploit fund management. The transactions suggest the operator is actively working to reposition assets across different forms and obfuscation layers.
JaredFromSubway gained notoriety as one of Ethereum’s most aggressive MEV bots, extracting value from ordinary users through sandwich attacks. Security firm Blockaid previously flagged activity tied to the bot, and the operator has faced scrutiny over the scale of extraction, which one report described as a $7.5 million attack that prompted legal action discussions.
Why the Tornado Cash and DAI combination matters
Routing ETH through Tornado Cash breaks the on-chain link between source and destination wallets, making it significantly harder for investigators to trace fund flows. For an exploiter sitting on identifiable proceeds, this is a standard first step in dispersal.
The separate DAI swap serves a different purpose. Converting volatile ETH into a dollar-pegged stablecoin locks in a fixed value regardless of subsequent ETH price movement. For someone managing exploit proceeds, this eliminates market risk on a substantial portion of holdings.
Stablecoin conversion also complicates potential recovery efforts. When stolen assets change form from ETH to DAI, any future freeze or clawback attempt must target a different smart contract and a different set of liquidity pools. The shift from a native asset to a decentralized stablecoin adds legal and technical friction to recovery, a dynamic that has played out in other exploit aftermaths, including cases like the Altura vault closure where stablecoin movements created additional complexity for affected parties.
What DeFi security watchers should monitor next
Large post-exploit transfers after a period of dormancy typically signal renewed attempts to cash out or redistribute funds. The combination of mixing and stablecoin rotation suggests a methodical approach rather than a single opportunistic withdrawal.
Investigators and on-chain analysts will likely focus on Tornado Cash withdrawal patterns in the coming days, watching for deposits that match the size and timing profile of the 2,000 ETH input. DAI movements from the swap destination wallet will also become a focal point for further surveillance.
For protocols and security teams, this episode reinforces why ongoing wallet monitoring matters well beyond the initial exploit event. Exploit wallets can sit dormant for months before activating, and the dispersal phase often provides new intelligence about the operator’s infrastructure and exit strategies.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
Defiliban · Oliver Benjamin
Oliver Benjamin
@oliver-benjamin