An attacker drained more than $100,000 from GoodDollar’s reserves through a bug in the Superfluid protocol, a GoodDollar exploit that hit the project’s funds on the Celo blockchain. GoodDollar is a project that pays a small daily income to nearly a million people, and its safety pool of funds was the target.
KEY TAKEAWAYS
- The reported reserve drain exceeded $100,000, split across two blockchains.
- The incident is linked to a bug in the Superfluid protocol on the Celo network.
- Full technical details, external pool losses, and final recovery status remain unverified.
GoodDollar reserves drained of over $100K
GoodDollar runs a “universal basic income” program. Members claim a small amount of its G$ token every day. To back that token, the project holds a pool of funds called a reserve. For related coverage, see SEC Approves Nasdaq Texas Commodity Trust Rules With 15% Cap.
That reserve is where the money went missing. According to reporting by CryptoSlate, citing a September 9 update from GoodDollar, an attacker exchanged 86,588 cUSD out of the Celo reserve. For related coverage, see Bitrace: Fulilai Removes Merchants Amid Xinbi Crackdown.
Reported Celo reserve outflow
86,588 cUSD
A second, smaller amount came from the project’s reserve on the XDC network. That outflow was $20,857, the same reporting states, though the route linking it to the Celo bug is not explained. For related coverage, see U.S. Bank Tests USBDC Stablecoin Payment on Stellar.
Reported XDC reserve outflow
$20,857
Together, those two figures make up the “more than $100,000” in the headline. Importantly, GoodDollar said the Celo and XDC reserves were not fully emptied. These are reported amounts, not on-chain confirmed totals.
The reported Superfluid bug connection
The drain traces back to Superfluid, a protocol that lets users send “money streams,” meaning payments that flow continuously over time. GoodDollar uses it to distribute its daily income.
Superfluid’s Security Council explained the flaw in a preliminary disclosure posted September 8. A malicious “Super App,” an automated program plugged into Superfluid, bypassed the normal stream liquidation process on Celo.
In plain terms, balances that should have been shut off stayed active. The attacker then exchanged those balances against GoodDollar’s reserve assets and other Celo liquidity pools, the council said.
The council stressed the bug depended on Superfluid’s specific Celo setup. All other networks running Superfluid were unaffected by this particular flaw. GoodDollar echoed this in its own update.
Update:
The incident affecting GoodDollar on Celo was due to a bug in the Superfluid protocol that allowed a malicious Super App to bypass Superfluid’s normal stream liquidation process.
As a result, G$ balances that should have been liquidated remained available, leaving more…
— GoodDollar 💙🌏 (@gooddollarorg) September 9, 2026
Source: @gooddollarorg on X
The response followed a clear timeline. An infrastructure alert first flagged insolvent Celo accounts on September 3 at 7:11 PM UTC, the council said.
Superfluid then deployed a Celo hotfix and reinstated Super App whitelisting on September 4 at 2 PM UTC. All insolvent accounts were closed one hour later, at 3 PM UTC.
The council also reviewed Super App registration processes across every network to invalidate inactive or unused whitelisted deployers, according to council member hellwolf. That review reaches beyond Celo, without implying other networks were exposed to this bug.
What remains unverified about the impact and recovery
The reported drain figures do not equal a final net loss. GoodDollar has not disclosed how much, if anything, may be recovered after remediation.
GoodDollar said Celo claiming, G$ transfers, and identity verification had resumed, per CryptoSlate. But reserve operations on Celo and XDC and bridging remained paused as of September 10.
The project also advised users against swapping G$ for now. Limited liquidity could cause large slippage and abnormal prices, meaning trades could execute at unexpectedly bad rates. This mirrors the kind of thin-market caution seen around other disrupted tokens, similar to how liquidity warnings accompany newly listed trading pairs on exchanges like Upbit.
Several gaps still need verification. External G$ liquidity pools were also affected, but those losses have not been disclosed. The link between the Celo-only bug and the XDC outflow remains unexplained.
Superfluid’s September 8 note is preliminary, and a full technical report is still to come. The council said the exploit path could no longer be reproduced after the fix. Reserve exposure, user effects, and final recovery amounts are gaps in the current material, not evidence that the teams failed to respond.
For a regular crypto holder, the practical takeaway is simple. If you hold G$, heed the project’s warning and avoid rushed swaps in thin liquidity until reserve operations reopen. Watch for the promised full technical report before drawing conclusions about the total damage. Security incidents like this remain a recurring theme across crypto, much like the ongoing regulatory scrutiny facing crypto providers in India.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.