1 min read

Relay Plans Full Reimbursement for 5,600 Users After Sandwich Attacks

An API flaw exposed pending orders before execution, enabling MEV searchers to profit about $136,000 from affected transactions.

Anonymous hands hold a smartphone beside a glass footbridge / TokenPost.ai
Anonymous hands hold a smartphone beside a glass footbridge / TokenPost.ai

Relay plans to fully reimburse about 5,600 users after an API vulnerability exposed pending order details and enabled sandwich attacks before transactions were executed.

MEV searchers — bots that seek profit by exploiting transaction ordering — used the exposed routing information to trade around affected orders. The attackers gained about $136,000 in total, while the median loss per affected user was $11.88.

Relay estimates that its reimbursement program will distribute about $312,000. Payments will be sent automatically to the relevant wallet addresses, and users will not need to submit claims.

The cross-chain execution protocol also paid Outputlayer a $50,000 bug bounty for identifying the vulnerability. The incident highlights how information exposed before execution can create risks for users relying on automated crypto transaction routing.

Loading…