Relay2026-09-29 02:19:44Relay says API flaw exposed pending trade data, affecting about 5,600 usersRelay, a cross-chain trading platform, said it found an API issue over the weekend that exposed pending transaction information before execution, according to a post from co-founder and COO Jason Maier. He said MEV searchers used pending routing state to infer on-chain paths and trade ahead of order execution, resulting in worse execution prices for users trading through Relay. Maier said the activity took place from Sept. 12 to Sept. 26, with most of it concentrated between Sept. 23 and Sept. 26. The searchers made about $136,000 in profit, while roughly 5,600 users were affected. The median impact per user was $11.88. Relay said it will pay a $50,000 bounty to Outputlayer for reporting the issue. The platform also plans to compensate affected users automatically, with no application required. Funds will be sent directly to wallets, and the total compensation amount is about $312,000. Maier added that MEV can arise through public mempools, inference from order details, malicious participation in auctions, or data gaps between service providers. He said protecting only one part of the transaction path is not enough, and that the team will keep working on execution quality and privacy across the full trade path while encouraging security researchers to report vulnerabilities they find.20