Relay API Vulnerability: 5,600 Users Hit by Sandwich Attacks, $312K Reimbursement Planned

Abstract:Relay disclosed an API flaw that exposed pending cross-chain transaction information before execution. MEV searchers profited about $136K, around 5,600 users were affected, and Relay plans roughly $312K of automatic reimbursement.

Cross-chain execution protocol Relay has disclosed an API security issue that exposed information about pending user transactions before they completed.

The disclosure is important because the incident did not require an attacker to drain a treasury, compromise private keys or break a bridge contract. Instead, the exposed information let MEV searchers infer the route and timing of user transactions, trade around them and worsen users execution.

Relay says approximately:

5,600 users

were affected.

Incident window

Relay says the affected activity occurred between:

September 12 and September 26, 2026

with most of the exploit activity concentrated between:

September 23 and September 26

The team discovered the issue over the weekend before the September 29 public disclosure.

What the API exposed

The vulnerable API exposed pending transaction information before execution.

Current disclosures describe exposed information around:

  • pending order state;
  • route status;
  • execution path.

MEV searchers could use those signals to infer what a user was about to do on-chain.

That gives an adversary a timing advantage before the users transaction reaches final execution.

Why this enables a sandwich attack

A classic sandwich pattern works like this:

  • attacker sees or infers a pending user trade;
  • attacker trades first in the direction that worsens the users price;
  • user trade executes at a less favorable price;
  • attacker trades again after the user to capture the price movement.
  • Relays incident is unusual because the pre-execution information leak occurred through an API/data path, not solely through a public mempool.

    This expands the MEV threat model.

    Searcher profit: approximately $136K

    Relay says MEV searchers made approximately:

    $136,000

    from the affected activity.

    This is the searchers estimated profit, not the total reimbursement amount.

    Approximately $312K reimbursement

    Relay plans to reimburse affected users approximately:

    $312,000

    in total.

    The company says reimbursement:

    • does not require a claim;
    • will be sent automatically;
    • goes directly to affected wallet addresses.

    The reimbursement can exceed searcher profit because user economic impact is not necessarily identical to the adversarys realized P&L. Users can suffer slippage/execution degradation beyond what one searcher ultimately retains as net profit.

    Median impact: $11.88

    Relay says the median impact per affected user was approximately:

    $11.88

    That indicates the event was distributed across thousands of relatively small user-level losses rather than a few large treasury drains.

    The aggregate impact still matters because users reasonably expect an execution router not to leak order information before completion.

    Outputlayer bug bounty

    Security team Outputlayer identified and reported the issue.

    Relay says it paid Outputlayer:

    $50,000

    as a bug bounty.

    The disclosure suggests coordinated remediation rather than adversarial public exploitation by the reporting team.

    API privacy is part of transaction security

    Cross-chain systems are often evaluated around:

    • smart-contract audits;
    • bridge-signing security;
    • solver correctness;
    • chain finality.

    The Relay incident shows another layer:

    information confidentiality before execution.

    A transaction can be cryptographically valid and the protocol contracts can work exactly as designed while users still lose value because their intended trade leaks too early.

    Relays broader MEV explanation

    Relay says MEV can emerge through multiple paths:

    • public mempool exposure;
    • inference from order details;
    • malicious participation in auctions;
    • data gaps between service providers.

    The teams conclusion is that protecting only one step of a cross-chain transaction path is insufficient.

    For example, private order submission does not help if a downstream routing API leaks the route.

    Why cross-chain execution increases the data surface

    A cross-chain trade can involve:

    • origin wallet;
    • API;
    • router;
    • quote engine;
    • solver;
    • bridge;
    • relayer;
    • destination DEX;
    • analytics or monitoring provider.

    Each system can expose:

    • destination;
    • asset;
    • size;
    • timing;
    • route;
    • pending state.

    The privacy boundary is therefore larger than a single blockchain mempool.

    User impact

    Affected users experienced worse execution than they should have received.

    The main harms include:

    • avoidable slippage;
    • price movement against their order;
    • reduced confidence in routing privacy;
    • inability to detect the cause at transaction time.

    Because compensation is automatic, users should not need to sign a separate claim transaction.

    Scam boundary

    The automatic reimbursement model creates an important security rule:

    Relay says users do not need to submit a reimbursement claim.

    Any message asking affected users to:

    • connect to a “Relay reimbursement portal”;
    • disclose a seed phrase;
    • send a verification payment;
    • approve an unrelated token;

    should be treated as suspicious unless independently verified through Relays authenticated channels.

    What is not yet public

    The currently available disclosure does not provide a complete technical post-mortem describing:

    • the exact API endpoint;
    • access-control design;
    • whether responses were public or obtainable through normal integration access;
    • every affected chain;
    • searcher identities;
    • exact per-chain loss distribution;
    • final reimbursement completion.

    WikiBit therefore does not invent those details.

    Evidence Status

    Confirmed / Project-Reported

    • API exposed pending transaction information before execution.
    • Activity occurred Sep. 12–26.
    • Most activity concentrated Sep. 23–26.
    • Approximately 5,600 users affected.
    • Searcher profit approximately $136K.
    • Median user impact approximately $11.88.
    • Approximately $312K reimbursement planned.
    • Reimbursement automatic; no user claim required.
    • Outputlayer paid $50K bug bounty.

    Developing

    • Full technical root cause.
    • Exact endpoint/data fields exposed.
    • Chain-by-chain impact.
    • Final reimbursement completion.
    • Additional searchers/affected transactions.
    • Long-term privacy architecture changes.

    Risk Assessment

    High execution-integrity / information-leak risk.

    The direct dollar impact is modest relative to major bridge or CEX hacks, but the flaw affected thousands of users and exposed a critical assumption in cross-chain execution: order confidentiality before settlement.

    What to Watch Next

    Technical post-mortem, confirmation reimbursement was completed, API/route privacy changes, solver and auction redesign, third-party data-provider controls and any repeat MEV patterns.

    FAQ

    How many users were affected?

    Relay says approximately 5,600 users.

    How much did the searchers make?

    Approximately $136,000.

    How much will Relay reimburse?

    Approximately $312,000 in total.

    Do users need to file a claim?

    Relay says no; compensation will be automatic.

    Was Relays bridge contract hacked?

    The disclosed issue concerns API exposure of pending transaction information, not a confirmed bridge-contract drain.

    Why does reimbursement exceed searcher profit?

    User execution harm and searcher net profit are different measures; Relays reimbursement amount reflects its compensation calculation rather than simply returning attacker profit.

Disclaimer

The views in this article only represent the author's personal views, and do not constitute investment advice on this platform. This platform does not guarantee the accuracy, completeness and timeliness of the information in the article, and will not be liable for any loss caused by the use of or reliance on the information in the article.
Previous Post

Prediction-Market Insider Trading: Why Identity and Surveillance Are Becoming Core Infrastructure

Next

Bitget Hack Update: ETH Withdrawals Reopen and NEAR Intents Holds Hacker-Linked Funds