Celer's cBridge covers a very wide set of chains at fees among the lowest in the category, using liquidity pools and a state guardian network for verification. Its contracts have operated without a direct exploit.
What happened in 2022
Attackers compromised DNS records and served a malicious front end at the legitimate domain. Users who connected and approved transactions had funds stolen — around $240,000 in total. The contracts were untouched; the website was the vector. Celer restored control, compensated affected users and hardened its DNS and hosting.
Why this matters generally
Front-end compromise is one of the most common ways DeFi users lose money and one of the least discussed. A protocol's audit says nothing about its domain security, and users have no practical way to verify that the interface they loaded is the correct one beyond bookmarking, checking certificates and reading what they sign on a hardware wallet screen.
Security model and cost
The state guardian network is permissioned, which is a weaker assumption than bonded consensus or light clients. Fees run 0.04% to 0.1% and transfers are fast on liquidity-rich routes.
Who should use it
Users needing cheap transfers on a route others do not cover, arriving via a bookmarked URL and verifying transactions on a hardware wallet.