Relay Has Agreed to Reimburse 5,600 Users for API Breach

The protocol will distribute $312,000 to users after an API flaw allowed MEV bots to profit from pending orders.

Updated on Sept. 29, 2026 in Cybersecurity

Isometric editorial illustration of interconnected fiber-optic cable connectors and network ports, symbolizing a technical data infrastructure.
Relay will reimburse 5,600 users a total of $312,000 following an API vulnerability that allowed automated bots to front-run pending trade orders. AI Illustration. Upload story photo >

Live Poll

Do you trust crypto platforms to keep your transaction data secure from exploitation?

Relay has announced it will automatically reimburse 5,600 users affected by an API vulnerability that exposed pending order details. The incident allowed MEV searchers to profit $136,000 at the expense of users before the exploit was addressed.

Why it matters

This incident highlights the ongoing risks of transaction front-running in decentralized protocols, where exposed API data can be exploited by automated systems. The protocol is acting to maintain user trust by covering losses incurred through this vulnerability.

The median loss per user was $11.88 resulting from the exposure of pending order data. The protocol also paid a $50,000 bug bounty to the firm Outputlayer for identifying the vulnerability.

The players

Relay

A decentralized protocol managing transaction execution and order routing.

Outputlayer

A security firm that identified the API flaw and received a bug bounty.

The details

The vulnerability originated in an API (application programming interface — a set of definitions that allow software to communicate) that inadvertently exposed pending order details before execution. MEV (maximal extractable value — automated bots that analyze mempools to reorder or front-run transactions for profit) searchers utilized this routing information to execute trades around the pending orders. These automated bots effectively captured value that should have belonged to the original users.

Timeline

  1. September 29, 2026: Announcement and article publication date.

The Tech Race

This incident reflects the broader challenge of protecting transaction privacy against MEV searchers in decentralized finance. It mirrors ongoing efforts across the industry to secure mempools against automated exploitation strategies.

Affected users will receive reimbursements automatically to their original wallet addresses without requiring manual claim submissions. While the total distribution is set at $312,000, the exact timing for these transfers has not been specified.

The takeaway

The protocol is prioritizing restitution to mitigate the fallout from an exploited API flaw. Users should watch for incoming transaction confirmations in their wallets, as the total $312,000 distribution is planned to finalize the remediation of this vulnerability.

Further reading

For more on the challenges of securing decentralized transaction flows, visit Cybersecurity.

Live Poll

Do you trust crypto platforms to keep your transaction data secure from exploitation?

Relay Has Agreed to Reimburse 5,600 Users for API Breach | Highwise Tech