Cross-chain protocol Relay announced that approximately 5,600 users were affected by a sandwich attack due to an API security vulnerability. This incident occurred when order information awaiting processing before a transaction was executed was exposed externally. MEV searchers exploited this information and the transaction path status to execute sandwich attacks, reportedly generating approximately $136,000 in profit. Relay paid a $50,000 bounty to the security team Outputlayer, which discovered and reported the vulnerability, and decided to fully compensate the affected users with a total of approximately $312,000.