‹ BackAPI vulnerability

API vulnerability

Relay
2026-09-29 02:23:46

Relay to Fully Reimburse Users After API Flaw Exposed Orders to Sandwich Attacks

Cross-chain execution protocol Relay said an earlier flaw in its API exposed pending order information before trades were executed, allowing MEV searchers to use routing state to carry out sandwich attacks. The incident affected about 5,600 users. Relay said the attackers made about $136,000, while the median user loss came to roughly $11.88. The team also said it paid a $50,000 bug bounty to Outputlayer, the security team that identified the issue. Relay plans to fully reimburse affected users for about $312,000 in total. According to the disclosure, users will not need to file claims or submit applications, as compensation will be sent automatically to the relevant wallet addresses. The details were reported by Odaily.

10
Relay to Fully Reimburse Users After API Flaw Exposed Orders to Sandwich Attacks