Top

Relay says 5,600 users hit by API flaw, plans full reimbursement

September 29, 2026, 2:32 AM
Cross-chain protocol Relay said about 5,600 users were affected by sandwich attacks caused by an API security vulnerability. The incident occurred after pending order information was exposed externally before trades were executed, allowing MEV searchers to exploit the data and transaction route status to carry out the attacks. Relay said the attackers generated about $136,000 in profit. The protocol also said it paid a $50,000 bounty to security team Outputlayer for identifying and reporting the vulnerability, and plans to fully reimburse affected users a total of about $312,000.

Leave the first comment

You need to log in to leave a comment.
Log In
Loading