Relay Plans Full Reimbursement for 5,600 Users After Sandwich Attacks
An API flaw exposed pending orders before execution, enabling MEV searchers to profit about $136,000 from affected transactions.

Relay plans to fully reimburse about 5,600 users after an API vulnerability exposed pending order details and enabled sandwich attacks before transactions were executed.
MEV searchers — bots that seek profit by exploiting transaction ordering — used the exposed routing information to trade around affected orders. The attackers gained about $136,000 in total, while the median loss per affected user was $11.88.
Relay estimates that its reimbursement program will distribute about $312,000. Payments will be sent automatically to the relevant wallet addresses, and users will not need to submit claims.
The cross-chain execution protocol also paid Outputlayer a $50,000 bug bounty for identifying the vulnerability. The incident highlights how information exposed before execution can create risks for users relying on automated crypto transaction routing.


