NewsCryptoGoodDollar Reserves Lose More Than $100,000 in Superfluid-Linked Exploit

GoodDollar Reserves Lose More Than $100,000 in Superfluid-Linked Exploit

Author: CoinLineup·

Key Takeaways

  • The reported outflows comprised 86,588 cUSD from GoodDollar’s Celo reserve and $20,857 from its XDC reserve.
  • Superfluid attributed the Celo incident to a malicious Super App that circumvented the network’s normal stream-liquidation process.
  • Superfluid said the flaw was specific to its Celo configuration and did not affect other networks through the same vulnerability.
  • GoodDollar resumed Celo claiming, G$ transfers and identity verification, while reserve operations and bridging remained suspended as of September 10.
  • The final loss, recovery amount, external liquidity-pool impact and relationship between the Celo exploit and XDC outflow remain unresolved.
GoodDollar Reserves Lose More Than $100,000 in Superfluid-Linked Exploit

An attacker drained more than $100,000 from GoodDollar’s reserves through a bug in the Superfluid protocol, affecting the project’s funds on the Celo blockchain. GoodDollar operates a universal basic income program that distributes a small daily amount of its G$ token to nearly one million people. The targeted reserve supports that token.

According to CryptoSlate’s report, which cited a September 9 update from GoodDollar, the reported reserve drain was divided between Celo and the XDC network. The figures have not been independently confirmed on-chain, and GoodDollar said neither reserve was completely emptied.

Reported reserve outflows

An attacker exchanged 86,588 cUSD from GoodDollar’s reserve on Celo, according to the report. A second outflow of $20,857 came from the project’s reserve on the XDC network. The available material does not explain how the XDC outflow was connected to the Celo-related vulnerability.

Together, the reported amounts exceed $100,000. They represent reported outflows rather than a confirmed final net loss.

GoodDollar members claim a small amount of G$ each day. The project maintains reserves to support the token, and those reserves were the source of the funds affected in the incident.

Superfluid bug affected Celo deployment

The incident was linked to Superfluid, a protocol that enables “money streams,” or payments that flow continuously over time. GoodDollar uses Superfluid to distribute its daily income.

In a preliminary disclosure posted September 8, Superfluid’s Security Council said a malicious “Super App”—an automated program connected to Superfluid—bypassed the normal stream liquidation process on Celo.

As a result, G$ balances that should have been liquidated remained available. The attacker then exchanged those balances against GoodDollar reserve assets and other liquidity pools on Celo, the council said.

The Security Council said the vulnerability depended on Superfluid’s specific Celo setup. Other networks running Superfluid were not affected by this particular flaw. GoodDollar also attributed the Celo incident to the Superfluid bug.

GoodDollar wrote on X:

Update: The incident affecting GoodDollar on Celo was due to a bug in the Superfluid protocol that allowed a malicious Super App to bypass Superfluid’s normal stream liquidation process. As a result, G$ balances that should have been liquidated remained available, leaving more… — GoodDollar 💙🌏 (@gooddollarorg) September 9, 2026

The post is available from GoodDollar’s X account.

Response timeline

The Security Council said an infrastructure alert first identified insolvent Celo accounts on September 3 at 7:11 p.m. UTC.

Superfluid deployed a Celo hotfix and reinstated Super App whitelisting on September 4 at 2 p.m. UTC. All insolvent accounts were closed one hour later, at 3 p.m. UTC.

The council also reviewed Super App registration processes across all networks to invalidate inactive or unused whitelisted deployers, according to council member hellwolf. The broader review does not indicate that other networks were exposed to the Celo-specific vulnerability.

The council said the exploit path could no longer be reproduced after the fix.

Recovery and remaining uncertainties

The reported outflows do not establish the incident’s final financial impact. GoodDollar has not disclosed how much, if anything, could be recovered after remediation. External G$ liquidity pools were also affected, but the losses from those pools have not been disclosed.

GoodDollar said Celo claiming, G$ transfers and identity verification had resumed, according to CryptoSlate. However, reserve operations on both Celo and XDC, as well as bridging, remained paused as of September 10.

The project also advised users not to swap G$ for the time being. It said limited liquidity could result in substantial slippage and abnormal prices, causing trades to execute at unexpectedly unfavorable rates.

Several aspects of the incident remain unresolved. The connection between the Celo-specific Superfluid bug and the XDC outflow has not been explained. Superfluid’s September 8 disclosure was preliminary, and the council said a full technical report would follow. The extent of reserve exposure, the effects on users and the final recovery amount therefore remain unverified.

The reported facts describe the current status of the incident but do not establish a final net loss or the outcome of the recovery process. GoodDollar’s warning remains relevant to users holding G$ while reserve operations and liquidity conditions are disrupted.

This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk.