Hackers drain reserves from crypto initiative providing daily payments to nearly 1 million users
A vulnerability in Superfluid’s Celo deployment enabled attackers to drain over $100,000 from GoodDollar’s reserves, affecting a protocol that distributes daily income to nearly one million users. The incident highlights risks to decentralized finance systems backing real-world economic models, especially when core infrastructure depends on multiple blockchain networks.
- Attacker drained $86,588 in cUSD from GoodDollar’s Celo reserve and $20,857 from XDC reserve through Superfluid bug
- GoodDollar distributes G$ tokens daily to 963,000 registered users with 2.3 billion tokens claimed through its UBI protocol
- Celo holds 2.4 billion G$, roughly 28% of the token’s 8.7 billion total circulating supply across all networks
- $100,000+ Total amount drained from GoodDollar reserves via Superfluid vulnerability
- 963,000 Unique users claiming daily UBI payments through GoodDollar protocol
- 28% Share of G$ supply on Celo relative to total circulating tokens
- 8.7B Total G$ tokens in circulation across all blockchain networks
GoodDollar, a decentralized universal basic income protocol, suffered a significant security breach when a malicious application bypassed Superfluid’s safeguards on the Celo network. The attacker created excess G$ tokens and exploited liquidation failures to drain stablecoins from GoodDollar’s reserves, which are the economic foundation of its daily token distribution system. The protocol reported the incident on September 9 after detecting unauthorized outflows from both its Celo and XDC reserves.
The attack represents a critical vulnerability in the growing ecosystem of protocols attempting to implement universal basic income through cryptocurrency and blockchain technology. GoodDollar’s model relies on generating returns through decentralized finance positions, then distributing those yields to participants in the form of daily token claims. When reserve assets are compromised, the entire distribution mechanism faces disruption, potentially affecting nearly a million users who depend on regular token payouts.
Superfluid bug allowed liquidation safeguards to be bypassed
Superfluid, a protocol that manages token streams and automated payments across blockchains, serves as critical infrastructure for numerous DeFi applications. Its Security Council identified a vulnerability specific to its Celo deployment that permitted a malicious Super App to circumvent whitelisting requirements designed to prevent unauthorized operations. Once activated, the exploit left insolvent G$ balances active when the system should have automatically liquidated them, allowing the attacker to exchange those excess balances against assets held in GoodDollar’s reserve and external liquidity pools.
Superfluid’s liquidation mechanism is designed to prevent users from maintaining negative balances in token streams. When a user’s balance falls below zero, the protocol should automatically liquidate their position and prevent further transactions. The vulnerability allowed a sophisticated attacker to circumvent this safeguard, creating a situation where insolvent accounts remained active and could continue transacting against external capital sources.
Superfluid’s team detected insolvent accounts on September 3 and traced the problem to the Super App bug the following day.
The company deployed a hotfix, reinstated Super App whitelisting on Celo, and closed affected accounts. Superfluid confirmed that other networks running its protocol were not exposed to the same vulnerability, limiting the scope of the exploit to Celo. This discovery suggests the vulnerability was specific to how Superfluid’s contracts interact with Celo’s unique architecture or configuration, rather than a systemic flaw affecting all deployments of the protocol.
Celo hosts 28% of G$ supply, creating outsized risk to UBI distribution
Celo holds approximately 2.4 billion G$ tokens, making it the network with the second-largest concentration of GoodDollar’s supply after Fuse, which holds 4.19 billion. Ethereum accounts for 1.82 billion G$ and XDC for 292.5 million, distributing the token across multiple blockchains but leaving significant exposure on Celo. This multi-chain strategy is intended to provide redundancy and access to different user bases, but it also creates complexity in managing protocol stability across different network environments.
GoodDollar’s reserve model depends on holding stablecoins backed by yield generated through decentralized finance investments. That reserve supports both G$ token issuance and daily distributions to its 963,000 registered claimants, who have collectively claimed 2.3 billion G$ through the protocol. The concentration of supply on Celo made the network’s vulnerability especially consequential for the protocol’s economic stability and its ability to continue distributing daily payments to its user base.
The protocol’s expansion across multiple blockchains reflects both the opportunities and challenges facing cross-chain DeFi infrastructure. While decentralization across networks reduces single points of failure, it also exposes protocols to vulnerabilities in each underlying blockchain’s ecosystem and any third-party infrastructure they depend on.
Reserves remain intact but operations paused pending investigation
GoodDollar stated that neither its Celo nor XDC reserves were fully depleted, citing monitoring alerts, emergency pauses, and existing protocol safeguards that limited the damage.
Claiming, G$ transfers, and identity verification have resumed on Celo, but reserve operations on both Celo and XDC remain paused. Bridging across networks is suspended and liquidity in external pools has been severely constrained, prompting GoodDollar to warn users against swapping G$ tokens until market conditions stabilize to avoid significant price slippage. The pause in reserve operations means daily distributions may be temporarily suspended or limited in scope while the protocol investigates the full extent of the breach.
The XDC reserve loss of $20,857 remains unexplained, as Superfluid has not disclosed how the vulnerability specific to Celo produced outflows on XDC. Both GoodDollar and Superfluid are preparing incident reports that should clarify the total losses across external liquidity pools and reveal how the Celo exploit cascaded to other networks. Understanding this cross-network impact is critical for determining whether similar vulnerabilities exist on other blockchains where Superfluid operates.
GoodDollar has committed to addressing excess G$ tokens, restoring liquidity, and reopening paused functions, with separate incident reports from both projects expected to provide a complete accounting of losses and explain the cross-network impact of the exploit. The incident underscores the importance of rigorous security auditing and testing across different blockchain environments, particularly for infrastructure protocols that support critical economic functions like UBI distribution systems.
BlockWest is a news publication. Nothing here is investment advice. Read our disclaimer and editorial policy.
