This weekend, we identified an issue in Relay's API that exposed pending trade information before execution. MEV searchers used it to sandwich trades, worsening prices for people trading through Relay.
MEV is an ongoing challenge in onchain markets. No single fix can eliminate it. While we didn't meet the bar today, we will continue to push to make trading onchain safe, reliable, and accessible.
What happened
- This activity occurred from Sep 12 to Sep 26, with most of it concentrated from Sep 23 to 26.
- Searchers used pending route statuses to infer onchain routes and trade ahead of orders before execution, extracting roughly $136k in profit.
- About 5,600 users were affected, with a median impact of $11.88.
Compensation
- We are paying a $50k bounty to @Outputlayer for reporting it.
- We're compensating affected users for this incident directly. No claim required, funds will automatically be sent to your wallet.
- Total compensation is approximately $312k.
The broader challenge
We started Relay because we believe onchain markets should be simple, accessible, and safe. You shouldnโt have to understand mempools, routing, or MEV to trade with confidence. Making that possible means tackling the complexity and risks behind every trade, not just simplifying the interface.
MEV takes many forms. Attackers can exploit transactions in public mempools, infer trades from order details, maliciously participate in auctions, or find gaps in how data moves between providers. Protecting one part of the path is not enough if sensitive information is exposed elsewhere. Attack methods evolve, and protections need to evolve with them. This is an ongoing challenge we want to take on - raising the standard for execution quality and privacy across the full path of a trade.
While its our responsibility to monitor and mitigate issues, security researchers can help. If you identify a vulnerability, report it.
Our goal remains the same: better execution, stronger privacy, and a simpler experience for everyone using Relay.





