Cross-chain infrastructure provider Relay says a vulnerability in its API exposed information about pending user orders before execution, giving MEV searchers enough advance knowledge to carry out sandwich attacks against roughly 5,600 users.
Relay co-founder and COO Jason Maier disclosed the incident on September 29, saying the activity occurred between September 12 and September 26. Attackers generated approximately $136,000 in profit, while the median affected user lost about $11.88.
Relay plans to reimburse affected wallets in full, with total compensation expected to reach approximately $312,000. Users will not need to submit claims; the company said reimbursements will be sent automatically to the wallets identified in its investigation.
Relay also awarded security research team Outputlayer a $50,000 bug bounty for identifying and reporting the issue. Maier’s disclosure of the incident said the vulnerability involved API information about pending orders becoming visible before those orders were executed.
That information was particularly valuable to MEV searchers because knowing what a user was about to buy could allow an attacker to trade immediately ahead of the order, push the execution price against the user and then sell after the user’s trade moved the market.
The Leak Turned Routing Data Into a Trading Advantage
A sandwich attack normally depends on seeing another trader’s order before execution. The attacker buys immediately before the victim, allows the victim’s order to move the price higher, and then sells into that price movement.
The risk is well known in decentralized trading, where MEV and sandwich attacks have become an important part of the competition between routing systems, aggregators and intent-based execution platforms.
Relay’s incident is more unusual because the relevant information appears to have leaked through infrastructure intended to coordinate private cross-chain execution rather than through an ordinary public mempool.
Relay describes itself as intent-based cross-chain payment infrastructure. A user specifies the desired transaction outcome, while Relay’s solvers handle routing, execution and settlement across networks. The company says it has enabled more than $20 billion of volume across over 100 million transactions and works with applications including MetaMask, Phantom, OpenSea and Coinbase Wallet.
One particularly relevant integration is FOMO, a social trading application that uses Relay to let users trade across chains from a single USDC balance. Relay said earlier this year that FOMO had processed $317 million through its infrastructure in three months, with more than 500,000 successful cross-chain transactions.
Researchers Saw the Sandwich Pattern Before Relay Confirmed the API Flaw
The first public clues emerged before Relay’s formal disclosure.
Outputlayer flagged suspicious trading on Robinhood Chain, identifying a wallet that appeared to be front-running FOMO users through Relay. The security team said one observed attacker had executed 328 sandwich attacks and caused more than $14,000 of user impact during its first day of tracked activity, typically entering one to four blocks ahead of Relay’s solver.
The venue matters. Robinhood Chain is an Ethereum Layer 2 built using Arbitrum technology, and trading activity on the network has expanded rapidly since its July launch.
Bitquery subsequently conducted a broader on-chain reconstruction covering Relay-filled memecoin trades on the network. Its investigation identified three bot groups that front-ran 3,532 orders between September 12 and September 25, representing approximately $6.5 million of affected order flow.
Bitquery estimated that those trades involved roughly 2,319 different wallets, with the bots generating about $61,725 in gross profit while users experienced an estimated $181,000 in execution losses.
Those figures are narrower than Relay’s final post-incident numbers. Relay says approximately 5,600 users were affected and that MEV searchers earned roughly $136,000 during the full September 12-26 period. The difference suggests Relay’s internal investigation captured additional affected transactions, users or searcher activity beyond the subset reconstructed publicly on-chain.
Why Relay Is Reimbursing $312,000 When Attackers Made $136,000
One number stands out immediately: Relay’s planned reimbursement is more than twice the profit attributed to the attackers.
That is not necessarily inconsistent.
A sandwich attack can cost the victim substantially more than the amount ultimately retained by the attacker. Some of the price deterioration can be absorbed by liquidity-provider fees, launchpad fees, swap fees, arbitrage and other market participants.
Bitquery observed exactly that dynamic in its earlier reconstruction. It estimated approximately $181,000 of user losses while the three bot groups it tracked grossed only around $62,000. Roughly $42,000 was attributed to fees collected by a launchpad’s trading mechanism, with additional value distributed elsewhere through the execution path.
Relay’s $312,000 reimbursement therefore appears designed around restoring what affected users lost relative to expected execution rather than simply returning the estimated $136,000 captured by the searchers.
That distinction is important for users. Reimbursing attacker profit alone would leave customers carrying the rest of the execution damage.
The Bigger Problem Is That the Attack Happened Before the Blockchain Could Warn Anyone
This is where the incident becomes more interesting than a relatively small crypto exploit.
There is no indication that attackers drained Relay’s contracts or stole funds by breaking cryptography. The weakness was informational.
The system apparently revealed something valuable before it was supposed to become public.
That matters because modern cross-chain trading increasingly depends on hiding complexity from users. Applications collect an intent, infrastructure chooses a route, solvers execute it, and the trader sees only the final result. That model can deliver fast execution, but it also concentrates sensitive order information inside APIs, routing engines and backend systems.
If any layer exposes the asset, direction, timing or slippage parameters of a pending order, that information can become economically valuable before a transaction ever reaches the blockchain.
In that sense, the Relay incident is different from a conventional bridge exploit. No pool needed to be drained. Attackers only needed enough information to consistently get into the market a fraction of a second before legitimate users.
The blockchain then did exactly what it was supposed to do: it processed the transactions in the order they arrived.
Order Privacy Is Becoming Part of Execution Quality
For Relay, the financial cost is manageable. A roughly $312,000 reimbursement and $50,000 bounty are small relative to the billions of dollars the company says have moved through its infrastructure.
The more important cost is proving that the execution layer can be trusted with private order information.
Relay competes partly on speed, abstraction and reliability. Those advantages depend on users and applications being comfortable handing routing decisions to infrastructure they cannot directly observe.
That changes the meaning of “best execution” in crypto.
Finding the cheapest route is not enough. A route that produces a good quoted price but leaks the trade before settlement can ultimately give the user a worse result than a more expensive route with stronger order privacy.
The industry’s routing layer therefore has to protect two things simultaneously: the transaction itself and the information describing the transaction before it executes.
This is particularly important as cross-chain trading becomes more automated. Wallets, trading applications and eventually autonomous agents will increasingly submit intents without users manually choosing venues or bridges. More responsibility moves into the execution infrastructure, and so does more economically sensitive information.
Relay’s Next Test Is Whether the Fix Removes the Information Advantage
The automatic reimbursement is the right immediate response for users because it avoids forcing thousands of wallets through a manual claims process.
But reimbursement closes the financial damage, not the technical question.
The more important follow-up will be whether Relay explains exactly what the API exposed, who could access that information, how long pending orders were visible and what controls now prevent the same data from being reconstructed through another endpoint.
Researchers will also be able to watch the blockchain for a fairly simple signal: whether the highly unusual pattern of bots repeatedly appearing just ahead of Relay fills disappears after the remediation.
If it does, the incident may end up as an expensive but contained infrastructure failure.
If similar front-running reappears, it would suggest the information advantage was not limited to one API endpoint.
For investors and users, that is the part worth watching. Relay has already quantified the losses, identified thousands of affected wallets and committed to making them whole. The harder task now is demonstrating that pending order information is genuinely private again.
Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms.
He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments.
Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

