Relay refunded $312K to 5,600 users after an API flaw exposed pending trades to MEV sandwich attacks.
Security & Exploits ·
Relay issued refunds totaling $312K to approximately 5,600 users following discovery of an API flaw that exposed pending trades to MEV sandwich attacks. The vulnerability allowed malicious actors to observe transactions in the mempool—the broadcast network where transactions wait before blockchain inclusion—and reorder or insert their own trades at profitable positions.
Sandwich attacks exploit the time window between when a user broadcasts a transaction and when it is finalized on-chain. During this gap, bots or block builders can front-run a trade by inserting their own transaction ahead of it, then follow with another transaction behind it, capturing the price movement caused by the original order. MEV (Maximal Extractable Value) encompasses this and related profit extracted through transaction reordering—a documented source of hundreds of millions in annual losses across major blockchains.
The scope of trades affected by Relay's API exposure and the full mechanics of how the flaw was discovered remain unclear. It is also not specified whether the $312K represents the total MEV extracted from affected users or only Relay's compensation decision.