Relay API Flaw Triggers $312,000 in Compensation for 5,600 Users
The vulnerability exposed pending cross-chain transaction details before execution, worsening user prices and enabling about $136,000 in MEV profits.

Relay will distribute about $312,000 to roughly 5,600 users after a flaw in its API exposed pending cross-chain transaction details before execution, allowing MEV searchers to trade ahead of orders and worsen execution prices.
The activity took place from Sept. 12 through Sept. 26 and was concentrated between Sept. 23 and Sept. 26. The searchers generated about $136,000 in profits, while the median impact on affected users was $11.88.
Relay said compensation will be sent automatically to affected wallets, with no claim required. The platform will also pay Outputlayer a $50,000 bounty for identifying and reporting the issue.
The incident involved exposed route status that enabled searchers to infer the path of pending transactions before they were completed. Relay said MEV can arise through public mempools, inferred order details, malicious participation in auctions or data gaps between service providers.
The platform said it will continue improving execution quality and privacy across the full transaction path and encouraged security researchers to report vulnerabilities.


