Cross-chain execution protocol Relay has disclosed an API security issue that exposed information about pending user transactions before they completed.
The disclosure is important because the incident did not require an attacker to drain a treasury, compromise private keys or break a bridge contract. Instead, the exposed information let MEV searchers infer the route and timing of user transactions, trade around them and worsen users execution.
Relay says approximately:
5,600 users
were affected.
Incident window
Relay says the affected activity occurred between:
September 12 and September 26, 2026
with most of the exploit activity concentrated between:
September 23 and September 26
The team discovered the issue over the weekend before the September 29 public disclosure.
What the API exposed
The vulnerable API exposed pending transaction information before execution.
Current disclosures describe exposed information around:
- pending order state;
- route status;
- execution path.
MEV searchers could use those signals to infer what a user was about to do on-chain.
That gives an adversary a timing advantage before the users transaction reaches final execution.
Why this enables a sandwich attack
A classic sandwich pattern works like this:
- attacker sees or infers a pending user trade;
- attacker trades first in the direction that worsens the users price;
- user trade executes at a less favorable price;
- attacker trades again after the user to capture the price movement.
- does not require a claim;
- will be sent automatically;
- goes directly to affected wallet addresses.
- smart-contract audits;
- bridge-signing security;
- solver correctness;
- chain finality.
- public mempool exposure;
- inference from order details;
- malicious participation in auctions;
- data gaps between service providers.
- origin wallet;
- API;
- router;
- quote engine;
- solver;
- bridge;
- relayer;
- destination DEX;
- analytics or monitoring provider.
- destination;
- asset;
- size;
- timing;
- route;
- pending state.
- avoidable slippage;
- price movement against their order;
- reduced confidence in routing privacy;
- inability to detect the cause at transaction time.
- connect to a “Relay reimbursement portal”;
- disclose a seed phrase;
- send a verification payment;
- approve an unrelated token;
- the exact API endpoint;
- access-control design;
- whether responses were public or obtainable through normal integration access;
- every affected chain;
- searcher identities;
- exact per-chain loss distribution;
- final reimbursement completion.
- API exposed pending transaction information before execution.
- Activity occurred Sep. 12–26.
- Most activity concentrated Sep. 23–26.
- Approximately 5,600 users affected.
- Searcher profit approximately $136K.
- Median user impact approximately $11.88.
- Approximately $312K reimbursement planned.
- Reimbursement automatic; no user claim required.
- Outputlayer paid $50K bug bounty.
- Full technical root cause.
- Exact endpoint/data fields exposed.
- Chain-by-chain impact.
- Final reimbursement completion.
- Additional searchers/affected transactions.
- Long-term privacy architecture changes.
Relays incident is unusual because the pre-execution information leak occurred through an API/data path, not solely through a public mempool.
This expands the MEV threat model.
Searcher profit: approximately $136K
Relay says MEV searchers made approximately:
$136,000
from the affected activity.
This is the searchers estimated profit, not the total reimbursement amount.
Approximately $312K reimbursement
Relay plans to reimburse affected users approximately:
$312,000
in total.
The company says reimbursement:
The reimbursement can exceed searcher profit because user economic impact is not necessarily identical to the adversarys realized P&L. Users can suffer slippage/execution degradation beyond what one searcher ultimately retains as net profit.
Median impact: $11.88
Relay says the median impact per affected user was approximately:
$11.88
That indicates the event was distributed across thousands of relatively small user-level losses rather than a few large treasury drains.
The aggregate impact still matters because users reasonably expect an execution router not to leak order information before completion.
Outputlayer bug bounty
Security team Outputlayer identified and reported the issue.
Relay says it paid Outputlayer:
$50,000
as a bug bounty.
The disclosure suggests coordinated remediation rather than adversarial public exploitation by the reporting team.
API privacy is part of transaction security
Cross-chain systems are often evaluated around:
The Relay incident shows another layer:
information confidentiality before execution.
A transaction can be cryptographically valid and the protocol contracts can work exactly as designed while users still lose value because their intended trade leaks too early.
Relays broader MEV explanation
Relay says MEV can emerge through multiple paths:
The teams conclusion is that protecting only one step of a cross-chain transaction path is insufficient.
For example, private order submission does not help if a downstream routing API leaks the route.
Why cross-chain execution increases the data surface
A cross-chain trade can involve:
Each system can expose:
The privacy boundary is therefore larger than a single blockchain mempool.
User impact
Affected users experienced worse execution than they should have received.
The main harms include:
Because compensation is automatic, users should not need to sign a separate claim transaction.
Scam boundary
The automatic reimbursement model creates an important security rule:
Relay says users do not need to submit a reimbursement claim.
Any message asking affected users to:
should be treated as suspicious unless independently verified through Relays authenticated channels.
What is not yet public
The currently available disclosure does not provide a complete technical post-mortem describing:
WikiBit therefore does not invent those details.
Evidence Status
Confirmed / Project-Reported
Developing
Risk Assessment
High execution-integrity / information-leak risk.
The direct dollar impact is modest relative to major bridge or CEX hacks, but the flaw affected thousands of users and exposed a critical assumption in cross-chain execution: order confidentiality before settlement.
What to Watch Next
Technical post-mortem, confirmation reimbursement was completed, API/route privacy changes, solver and auction redesign, third-party data-provider controls and any repeat MEV patterns.
FAQ
How many users were affected?
Relay says approximately 5,600 users.
How much did the searchers make?
Approximately $136,000.
How much will Relay reimburse?
Approximately $312,000 in total.
Do users need to file a claim?
Relay says no; compensation will be automatic.
Was Relays bridge contract hacked?
The disclosed issue concerns API exposure of pending transaction information, not a confirmed bridge-contract drain.
Why does reimbursement exceed searcher profit?
User execution harm and searcher net profit are different measures; Relays reimbursement amount reflects its compensation calculation rather than simply returning attacker profit.

