Revoke.cash logo

Celer Frontend Hack

Check if your address is affected.

17 Aug 2022
$240k stolen
Ethereum Logo
BNB Chain Logo
Arbitrum Logo
Optimism Logo
Avalanche Logo
Polygon Logo
Aurora Logo
Metis Logo
Astar Logo
Fantom (Unsupported) Logo

cBridge is Celer Network's app for moving tokens between blockchains. On 17 August 2022, attackers abused the internet's routing system, known as BGP, to take over traffic meant for a server that told the cBridge website which contracts to use. That server was hosted by Amazon, and the attackers briefly convinced parts of the internet that they owned some of Amazon's addresses. For a few hours, some cBridge visitors were shown contracts controlled by the attackers and were asked to give them unlimited approvals to their tokens.

Around $240k in tokens was taken from wallets that approved the attackers' contracts, which had been set up on ten chains including Ethereum, BNB Chain, Polygon, Arbitrum, Optimism and Avalanche. The attackers then moved the stolen funds through the Tornado Cash mixer. Celer shut down cBridge as a precaution, published the list of malicious contracts and asked users to revoke approvals to them. It also promised to fully compensate users affected during the incident, asking them to revoke those approvals first.

Celer said its protocol and smart contracts were not affected, because the attack targeted the internet infrastructure around the website rather than the bridge itself. The addresses listed here are the attackers' contracts, not Celer's. If you used cBridge around 17 August 2022, check whether you approved any of them on any chain and revoke those approvals. Revoking prevents further losses from your wallet, but it does not recover tokens that were already taken.

Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.

Next time, revoke it automatically

Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.

See how Auto-Revoking works →
Get Ultimate
Back to Exploits