Data leak [loss] $240,000

Tweet by CelerNetwork

2022-08-17 [vendor] Celer Network bridge
Primary Source ↗
Financial Loss $240,000 (240,000 USD)

Incident Details

The Celer Network’s cBridge project was targeted with a BGP hijacking attack. Users who tried to access the bridge’s frontend were instead shown a site that prompted them to authorize transactions that drained their wallets. The attacker was able to steal around 128 ETH (~$240,000) before the exploit was discovered and Celer took the frontend offline. The stolen funds were quickly transfered to the Tornado Cash cryptocurrency tumbler.

Total loss estimated at $240,000.

Technical Details

Initial Attack Vector
DNS hijacking / domain takeover (front-end compromise)
Vendor / Product
Celer Network bridge

Timeline

  1. 2022-08-17 Breach occurred
  2. 2022-08-17 Publicly disclosed