Incident case

Celer cBridge 2022 DNS hijacking

A DNS cache-poisoning attack redirected some cBridge frontend users toward malicious smart contracts capable of draining approved tokens. Celer took the frontend offline, advised approval revocation, and restored it with additional monitoring.

reviewedcurrent

Incident facts

Incident title
Celer cBridge 2022 DNS hijacking
Bridge
Celer cBridge
Incident date
2022-08-17
Incident type
Frontend Compromise
Major incident
Yes
Affected chains
Ethereum, Unknown
Affected assets
Unknown
Attack category
Frontend Or Dns Compromise
Reported loss
Approximately $240,000 reported
Amount confidence
Medium
Loss amount basis
Contemporaneous Reporting Based On Celer'S Incident Updates
Recovery
None
Reimbursement
Announced
Restart
Reopened
Current outcome
Active After Incident
Postmortem
Partial
Resolution
Unresolved
Last reviewed
2026-06-15
Last verified
2026-06-15

Amount and valuation

Contemporaneous reporting described approximately $240,000 in user losses from the malicious frontend redirection.

The amount is qualified because no dedicated official reconciliation was located in this batch.

Why this remains unresolved

Timeline events

  • Celer paused the cBridge frontend after DNS hijacking reports2022-08-17

    Celer detected suspicious DNS activity, took the cBridge frontend offline, and advised users to revoke approvals associated with malicious contracts.

    Dns Hijacking And Frontend PauseHigh

    The underlying bridge contracts were not identified as the primary compromise.

  • Celer committed to compensate affected users2022-08-18

    Celer's incident updates said affected users would be fully compensated following the frontend DNS cache-poisoning attack.

    Compensation CommitmentHigh

    Final compensation completion was not located in this batch.

  • cBridge frontend restored with additional monitoring2022-08-18

    Celer restored the cBridge frontend after mitigation and said additional monitoring was in place.

    Bridge ReopenedHigh

    Event type normalized from legacy descriptive value frontend_restored.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.