Cross-chain trading platform Relay API exposes pending transactions, which will compensate approximately $312,000
Co-founder and Chief Operating Officer of the cross-chain trading platform Relay, Jason Maier, stated that the team discovered an issue with the Relay API over the weekend, which exposed pending transaction information before trade execution. MEV seekers exploited the pending routing status to infer on-chain paths and front-run trades before order execution, resulting in worse execution prices for users trading through Relay.
This activity occurred from September 12 to September 26, primarily concentrated from September 23 to 26. Seekers profited approximately $136,000 from this, affecting around 5,600 users, with a median impact of $11.88. Relay will pay a $50,000 bounty to Outputlayer for reporting the issue and will automatically compensate affected users without the need for applications; funds will be directly sent to wallets, with a total compensation amount of approximately $312,000.
Jason Maier stated that MEV can arise through public mempool exposure, order detail inference, malicious participation in auctions, or data gaps between service providers, and protecting a single link in the transaction path is not sufficient. He mentioned that the team will continue to enhance the execution quality and privacy of the entire transaction path and called on security researchers to report vulnerabilities when discovered.






