Relay Has Agreed to Reimburse 5,600 Users for API Breach
The protocol will distribute $312,000 to users after an API flaw allowed MEV bots to profit from pending orders.
Updated on Sept. 29, 2026 in Cybersecurity

Live Poll
Do you trust crypto platforms to keep your transaction data secure from exploitation?
Relay has announced it will automatically reimburse 5,600 users affected by an API vulnerability that exposed pending order details. The incident allowed MEV searchers to profit $136,000 at the expense of users before the exploit was addressed.
Why it matters
This incident highlights the ongoing risks of transaction front-running in decentralized protocols, where exposed API data can be exploited by automated systems. The protocol is acting to maintain user trust by covering losses incurred through this vulnerability.
The median loss per user was $11.88 resulting from the exposure of pending order data. The protocol also paid a $50,000 bug bounty to the firm Outputlayer for identifying the vulnerability.
The players
Relay
A decentralized protocol managing transaction execution and order routing.
Outputlayer
A security firm that identified the API flaw and received a bug bounty.
The details
The vulnerability originated in an API (application programming interface — a set of definitions that allow software to communicate) that inadvertently exposed pending order details before execution. MEV (maximal extractable value — automated bots that analyze mempools to reorder or front-run transactions for profit) searchers utilized this routing information to execute trades around the pending orders. These automated bots effectively captured value that should have belonged to the original users.
Timeline
September 29, 2026: Announcement and article publication date.
The Tech Race
This incident reflects the broader challenge of protecting transaction privacy against MEV searchers in decentralized finance. It mirrors ongoing efforts across the industry to secure mempools against automated exploitation strategies.
Affected users will receive reimbursements automatically to their original wallet addresses without requiring manual claim submissions. While the total distribution is set at $312,000, the exact timing for these transfers has not been specified.
The takeaway
The protocol is prioritizing restitution to mitigate the fallout from an exploited API flaw. Users should watch for incoming transaction confirmations in their wallets, as the total $312,000 distribution is planned to finalize the remediation of this vulnerability.
Further reading
For more on the challenges of securing decentralized transaction flows, visit Cybersecurity.
Live Poll
Do you trust crypto platforms to keep your transaction data secure from exploitation?







