A bug in Superfluid's Celo deployment allowed a malicious application to mint excess G$ tokens and drain more than $100,000 from the reserves of GoodDollar, the decentralized protocol that distributes a daily universal basic income to nearly one million registered users.

The incident, disclosed by GoodDollar on September 9, hit the economic core of a protocol whose G$ issuance and UBI distributions depend on yield generated from stablecoin-backed reserves.

What Was Taken

According to GoodDollar's disclosure, 86,588 cUSD was exchanged out of its Celo reserve, with another $20,857 leaving its XDC reserve. External G$ liquidity pools were also affected, though neither project has quantified those losses.

The absolute figure is small by the standards of this year's exploits. The exposure is not: roughly 2.4 billion G$ circulates on Celo — about 28% of the token's 8.7 billion circulating supply — and the reserve is the mechanism that stands behind it. GoodDollar's dashboard counts more than 963,000 unique UBI claimants and 2.3 billion G$ distributed to date.

How the Bypass Worked

Superfluid's Security Council published a preliminary disclosure describing a vulnerability specific to its Celo deployment. A malicious Super App bypassed a whitelisting requirement, allowing insolvent G$ balances to remain active when the protocol's liquidation safeguards should have closed them out. Those excess balances were then exchanged against assets in the GoodDollar Reserve and other liquidity pools.

The timeline from the council's disclosure: Superfluid detected insolvent accounts on September 3, traced the liquidation failure to the Super App bug on September 4, then deployed a hotfix, reinstated Super App whitelisting on Celo and closed the affected accounts. Other Superfluid deployments were not exposed to the flaw, the council said.

Recovery, With One Hole in the Story

GoodDollar says its Celo and XDC reserves were not depleted, crediting monitoring alerts, emergency pauses and existing protocol safeguards. Claiming, G$ transfers and identity verification have resumed on Celo.

Reserve operations on both networks remain paused, bridging is suspended, and the protocol has advised users against swapping G$ until liquidity recovers, warning that thin markets could produce heavy slippage and prices detached from normal levels.

The unresolved item is the XDC outflow. Superfluid's account places the vulnerability exclusively on Celo, yet GoodDollar reports $20,857 exchanged out of its XDC reserve — a separate network the bug, as described, should not have reached. Neither project has explained how excess G$ produced an outflow on XDC. Both are preparing separate incident reports, which are expected to account for the external-pool losses and the cross-chain discrepancy.

Until then, the public record holds a familiar shape: a contained exploit, a recovering protocol, and one number that does not yet fit the explanation.

TrustGrade covers the security and trust ecosystem around digital assets. For verified trust data on the platforms and firms shaping it, see trustgrade.ai.