Celer cBridge 2022 DNS hijacking
A DNS cache-poisoning attack redirected some cBridge frontend users toward malicious smart contracts capable of draining approved tokens. Celer took the frontend offline, advised approval revocation, and restored it with additional monitoring.
Incident facts
- Incident title
- Celer cBridge 2022 DNS hijacking
- Bridge
- Celer cBridge
- Incident date
- 2022-08-17
- Incident type
- Frontend Compromise
- Major incident
- Yes
- Affected chains
- Ethereum, Unknown
- Affected assets
- Unknown
- Attack category
- Frontend Or Dns Compromise
- Reported loss
- Approximately $240,000 reported
- Amount confidence
- Medium
- Loss amount basis
- Contemporaneous Reporting Based On Celer'S Incident Updates
- Recovery
- None
- Reimbursement
- Announced
- Restart
- Reopened
- Current outcome
- Active After Incident
- Postmortem
- Partial
- Resolution
- Unresolved
- Last reviewed
- 2026-06-15
- Last verified
- 2026-06-15
Amount and valuation
Contemporaneous reporting described approximately $240,000 in user losses from the malicious frontend redirection.
The amount is qualified because no dedicated official reconciliation was located in this batch.
frontend users redirected to malicious contractsapproximately $240,000
Qualified reported estimate.
Why this remains unresolved
- Celer committed to compensate affected users, but final completion and the reconciled amount are not established in this batch.
Timeline events
Celer paused the cBridge frontend after DNS hijacking reports2022-08-17
Celer detected suspicious DNS activity, took the cBridge frontend offline, and advised users to revoke approvals associated with malicious contracts.
The underlying bridge contracts were not identified as the primary compromise.
Celer committed to compensate affected users2022-08-18
Celer's incident updates said affected users would be fully compensated following the frontend DNS cache-poisoning attack.
Final compensation completion was not located in this batch.
cBridge frontend restored with additional monitoring2022-08-18
Celer restored the cBridge frontend after mitigation and said additional monitoring was in place.
Event type normalized from legacy descriptive value frontend_restored.
Evidence records
- Celer reported potential DNS hijacking of the cBridge frontendCeler Network · Tier 1 · High reliability · primary · 2022-08-17Claim scope: Incident Case
Primary contemporaneous incident warning.
- Celer Network cBridge resumes operation after suffering DNS exploitCryptoSlate · Tier 2 · High reliability · secondary · 2022-08-18Claim scope: Restart
Secondary source for the reported amount, compensation commitment, and frontend restoration.
- Celer Network Suspects DNS Hijacking, Shuts Its cBridgeDailyCoin · Tier 2 · Medium reliability · secondary · 2022-08-19Claim scope: Incident Case
Secondary contemporaneous account preserving the frontend/DNS distinction.
- Celer Network Suspects DNS Hijacking, Shuts Its cBridgeDailyCoin · Tier 2 · Medium reliability · secondary · 2022-08-19Claim scope: Reimbursement
Event-scoped duplicate of bir_src_000079: contemporaneous reporting based on Celer's updates supports the commitment to compensate affected users.
- Celer cBridge DNS incident update and compensation commitmentCeler Network · Tier 1 · High reliability · primary · 2022-08-18Claim scope: Reimbursement
First-party update describing the DNS cache-poisoning incident, planned frontend restoration with added monitoring, and full compensation commitment for affected users.
- Celer cBridge DNS incident update and compensation commitmentCeler Network · Tier 1 · High reliability · primary · 2022-08-18Claim scope: Reimbursement
Event-scoped primary copy supporting restoration of the cBridge frontend with additional monitoring after mitigation.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- The exact number of affected users and final compensated total require later source review.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.