Odaily reports that the cross-chain execution protocol Relay team has disclosed that its API interface previously had a vulnerability that leaked pending order information before transaction execution, causing MEV searchers to exploit the relevant routing state to carry out sandwich attacks.
This attack involved approximately 5,600 users, with attackers profiting about $136,000 and the median user loss at about $11.88. Relay has paid a $50,000 bug bounty to the security team Outputlayer, which discovered the vulnerability, and plans to fully compensate affected users with approximately $312,000. The compensation requires no user application and will be automatically sent to the corresponding wallet addresses.