Relay discloses API exposure of pending order information and plans to pay approximately 312000 USD
BIBIBI
AT A GLANCE
Relay said that API exposure of transaction information triggered sandwich attacks and that it will automatically compensate affected users approximately 312000 USD。
Article
Cross-chain trading protocol Relay due to API a vulnerability suffered a sandwich attack and will compensate approximately 312000 USD BlockBeats reported that September 29, cross-chain trading protocol Relay disclosed that its API had previously exposed information about pending transactions,MEV searchers used this information to front-run and sandwich users’ orders. The incident mainly occurred on September 12 to 26, particularly concentrated on 23 through 26, affecting approximately 5600 users, with a median loss of approximately 11.88 USD, while searchers collectively earned approximately 136000 USD.
Relay will pay a @Outputlayer bounty to 50000 USD who discovered and reported the issue, and will automatically compensate the wallets of affected users a total of approximately 312000 USD, with no separate application required. Relay said it will continue to improve execution quality and privacy protection along the transaction route.
Original link https://m.theblockbeats.info/flash/369462
Key points
01
Relay disclosed that its API had exposed information about pending transactions,MEV enabling searchers to front-run and sandwich users’ orders.
02
The incident mainly occurred on September 12 to 26, particularly concentrated on 23 through 26.
03
Approximately 5600 users were affected, with a median loss of approximately 11.88 USD, while searchers collectively earned approximately 136000 USD。
04
Relay has paid a bounty to @Outputlayer who discovered and reported the issue, amounting to 50000 USD.
05
Relay will automatically compensate the wallets of affected users a total of approximately 312000 USD, with no separate application required.
06
Relay said it will continue to improve execution quality and privacy protection along the transaction route.
AI-assisted interpretation
The following is analysis, separate from reported facts. Verify important claims independently.
Pending user order information was exposed through API, after which MEV searchers could view transactions in advance and conduct front-running and sandwiching; this type of operation is known as a sandwich attack. The report, citing Relay’s disclosure, said approximately 5600 users were affected and that Relay plans to compensate the relevant wallets directly.
Why it matters to readers
Exposure of pending transaction information can affect users’ execution outcomes and transaction privacy; the automatic compensation arrangement concerns whether affected users can receive compensation.
If you used Relay during the relevant period, check whether your wallet receives automatic compensation; the original report said no separate application is required.
Risks and unknowns
The evidence did not include Relay’s original announcement, and the disclosed content and figures have not yet been checked against the original materials.
Not specified API The specific root cause of the vulnerability, the remediation timeline, or whether it has currently been fully remediated.
The execution timeline for compensation, the actual number of people covered, and whether any omissions occurred were not specified.
The searcher's profits, user count, and loss data lack verification by third parties or on-chain analysis.
Related Developments
Loading event timeline…
Related concepts
API
This term is not in the glossary yet. Browse related concepts in the glossary.