Relay, a cross-chain trading platform, said it found an API issue over the weekend that exposed pending transaction information before execution, according to a post from co-founder and COO Jason Maier. He said MEV searchers used pending routing state to infer on-chain paths and trade ahead of order execution, resulting in worse execution prices for users trading through Relay.
Maier said the activity took place from Sept. 12 to Sept. 26, with most of it concentrated between Sept. 23 and Sept. 26. The searchers made about $136,000 in profit, while roughly 5,600 users were affected. The median impact per user was $11.88.
Relay said it will pay a $50,000 bounty to Outputlayer for reporting the issue. The platform also plans to compensate affected users automatically, with no application required. Funds will be sent directly to wallets, and the total compensation amount is about $312,000.
Maier added that MEV can arise through public mempools, inference from order details, malicious participation in auctions, or data gaps between service providers. He said protecting only one part of the transaction path is not enough, and that the team will keep working on execution quality and privacy across the full trade path while encouraging security researchers to report vulnerabilities they find.
Relay said it discovered an API issue over the weekend that exposed pending transaction information before trades were executed, according to a post from co-founder and chief operating officer Jason Maier.
Maier said MEV searchers used pending routing state to infer on-chain paths and trade ahead of order execution, which led to worse execution prices for users trading through Relay.
Timeline and user impact
He said the activity ran from Sept. 12 to Sept. 26, with most cases concentrated between Sept. 23 and Sept. 26. The searchers made about $136,000 in profit. About 5,600 users were affected, and the median impact was $11.88.
Bounty and compensation
Relay said it will pay a $50,000 bounty to Outputlayer, which reported the issue. The company also said compensation will be sent automatically to affected users, with no claim process required. Funds will be transferred directly to wallets, and the total payout is about $312,000.
What Maier said next
Maier said MEV can emerge through public mempools, inference from order details, malicious participation in auctions, or data gaps between service providers. In his view, protecting a single part of the transaction path is not enough.
He said the team will continue improving execution quality and privacy across the full transaction path, and called on security researchers to report vulnerabilities after finding them.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.