A Note To The Relayers...

To our community,
Over the past few days, we’ve seen speculation about wallet compromises and questions regarding the safety of using Relay.
We want to take a moment to directly address these claims, provide clarity and reassurance, and ultimately, reinforce how Relay is designed to keep your funds safe.
Relay is Safe ✅.
Relay has not been compromised. There are no vulnerabilities in the Relay app — and there never were.
🧵 TL;DR
- Some users had wallets compromised and mentioned they recently used Relay.
- We investigated everything — logs, infra, onchain data.
- All evidence points to external wallet compromises (phishing, malware, browser extensions).
- In every single case, the wallets were already compromised before interacting with Relay.
- Relay cannot drain wallets — we never request unlimited approvals and don’t touch private keys.
- Relay remains secure. We take your safety seriously.
🚨 What Happened?
A few users reported wallet drains. Some had recently used Relay, so speculation started.
We immediately launched a full investigation. After reviewing our infra, codebase, logs, and onchain activity:
Relay has not been breached, exploited, or compromised.
🔍 What We Found
Our team:
- Audited frontend/backend logs
- Reviewed codebase changes
- Cross-checked onchain activity
- Reproduced scenarios reported by affected users
Findings:
These incidents were external to Relay — likely caused by phishing attacks or wallet-draining malware (like those highlighted in recent Microsoft and MetaMask reports).
📌 In every case:
- Wallets were compromised before using Relay.
- Assets were bridged/swapped successfully via Relay.
- Then, attackers sent funds out in direct ETH transfers — no approvals, no contract calls.
- That’s only possible if someone already has access to your private key.
🛡️ Why Relay is Safer by Design
Relay Only Uses Limited Approvals
We never ask for unlimited access to your tokens.
You only approve the exact amount you're swapping. No leftovers, no lingering risk.

Even in a worst-case exploit, Relay cannot be used to drain your wallet.
🔄 Bonus: Relay Reduces Approvals Altogether
We built Relay to avoid approvals where possible:
- Gas Token Execution – Use ETH/MATIC directly. No need to wrap.
- Direct Transfers – Send USDC directly to the smart contract with calldata to match.
- Permit Support – Sign and swap in one step (ERC-2612 coming soon).
- Smart Wallet Batching (EIP-5792) – Approve + swap in a single atomic tx.
- EIP-7702 Ready – Once live, EOAs can do the same.
🧠 Can Relay Drain My Wallet?
No. Never.
If you hear otherwise, consider these two common scenarios:
- Delayed Swap – The swap hasn’t fulfilled yet, so funds seem "gone" — but they're just in transit. Learn how to check your transactions status here.
- External Compromise – An attacker already had access. The moment a swap completes, they drain the wallet.
Relay cannot act on your behalf. We don’t touch your keys, store your data, or initiate any transaction you haven’t signed.
👁️ Transparency is Non-Negotiable
We built Relay with one goal: earn trust by design.
That’s why we:
- Never request unlimited approvals
- Avoid confusing transaction flows
- Publish audits + updates
- Investigate every report thoroughly
If we ever did find an issue, we’d fix it fast — and tell you first.
🧯 What This Means
Relay is not the cause of recent wallet compromises.
We:
- Don’t store seed phrases or keys
- Don’t initiate transactions
- Don’t have backend wallet access
- Never request risky token approvals
Everything you do on Relay is signed by you and submitted onchain. It’s public and verifiable.
🔐 Protect Yourself Onchain
Using the internet with money is risky. Some quick tips:
- Use a hardware wallet for funds you care about.
- Avoid unnecessary browser extensions.
- Never save your seed phrase unencrypted.
- Triple-check URLs. Bookmark trusted ones (e.g.,
relay.link
). - Stay informed — malware threats are evolving fast.
💬 Need Help?
Relay wouldn’t exist without our community — your trust, feedback, and support are what allow us to keep building. If you’ve experienced an issue or need help understanding what’s going on with your wallet, please reach out to us directly: support.relay.link
Stay Safu.
LFR