GoodDollar, a decentralized universal basic income protocol paying daily G$ tokens to nearly 1 million registered users, disclosed this week that a Superfluid bug let an attacker drain more than $100,000 from its reserves. The project said 86,588 cUSD left its Celo reserve and another $20,857 came out of its XDC reserve.
The exploit worked through a malicious Super App deployed on Celo. Superfluid is a streaming payments protocol that GoodDollar uses to move value through its UBI distribution system. According to Superfluid’s Security Council, the malicious application bypassed a whitelisting requirement and left insolvent G$ balances active when they should have been liquidated. Those excess balances were then exchanged against assets held in the GoodDollar Reserve and other liquidity pools.
Neither project has named a suspect, and neither has described the attacker’s onchain footprint in detail. The loss total could still grow once external liquidity pools are fully accounted for, since both teams have acknowledged those pools were affected but not disclosed the size of the damage there.
How the Bug Worked
Superfluid’s system relies on whitelisted applications to stream tokens. When a stream becomes insolvent, meaning the sender no longer holds enough tokens to cover what they are streaming, the protocol is supposed to liquidate the balance and cut the stream off. The bug in the Celo deployment allowed a malicious app to skip that liquidation step entirely, keeping insolvent balances alive long enough to swap them for real value held by other protocols.
The Security Council said the vulnerability was specific to the Celo deployment and that other Superfluid networks were not exposed to the same flaw. The team detected insolvent accounts on September 3, traced the liquidation failure to the Super App bug the following day, deployed a hotfix, reinstated Super App whitelisting on Celo, and closed the affected accounts. The fix landed on September 4, five days before GoodDollar’s public disclosure.
What Was Lost and What Is Paused
GoodDollar said its Celo and XDC reserves were not depleted, crediting monitoring alerts, emergency pauses and existing protocol safeguards with limiting the damage. External G$ liquidity pools were also affected, though neither project has disclosed the size of those losses. Claiming, G$ transfers and identity verification have resumed on Celo.
Reserve operations on Celo and XDC remain paused, however, while bridging is suspended and liquidity in external pools stays limited. The project is now working to remove the excess G$ supply the attacker created and rebuild liquidity before normal operations resume. No timeline has been given for the reserve restarts, and users still receive their daily claims, which continue from whatever operational budget remained available.
Why GoodDollar Matters
GoodDollar is one of the longer-running UBI experiments in crypto. It distributes G$ tokens daily to registered users who complete identity verification, with the reserve backed by stablecoins and yield from DeFi investments used to support G$ issuance and the daily distributions. The project was incubated by eToro’s foundation and has been running since 2020, making it one of the few crypto UBI programs to survive multiple market cycles.
The token’s supply is spread across several chains. About 2.4 billion G$ circulates on Celo, roughly 28% of the token’s 8.7 billion circulating supply, second only to the 4.19 billion on Fuse. Ethereum holds about 1.82 billion G$, and XDC accounts for 292.5 million. The Celo deployment is where the exploit hit, which is also where a large share of claimants interact with the protocol.
A Pattern of Small but Real Losses
The loss is small by the standards of a year that has already seen a $320 million exploit drain 95% of the Liquid Network’s reserves, forcing the Bitcoin sidechain to halt and restart block production. But the GoodDollar incident is notable for a different reason. The attacker did not break cryptography or steal keys. The bug sat in application-layer logic, a whitelisting bypass in a streaming protocol, and it persisted long enough for someone to find it and profit from it.
Whitelisting systems are a common trust assumption in DeFi infrastructure, and this incident shows how a single bypassed gatekeeper can put every dependent protocol at risk. GoodDollar’s reserve design, which keeps stablecoins in a pool that streams can draw against, meant the excess G$ had somewhere real to be spent. The same design that makes daily UBI payouts possible also concentrated the value an attacker could reach.
Security researchers have made this point repeatedly this year. The Liquid Network breach, the GoodDollar drain, and a copy-and-paste address swap attack that kept hitting users even after a malware cleanup all point at infrastructure and user-interface weaknesses rather than broken cryptography. The money is moving through the seams between protocols, not through the math underneath them.
What Happens Next
GoodDollar has not said whether it will compensate external liquidity providers affected by the drain, or how it plans to remove the excess G$ from circulation. Superfluid’s Security Council has published the fix and confirmed the flaw was contained to Celo. Users of the protocol on other chains were not affected.
The incident lands during a rough stretch for crypto security. The Liquid Network restarted this week after its own exploit, and several smaller protocols have reported losses in recent days. For a project whose entire premise is paying people a small daily income, even a six-figure loss eats into the reserve that funds the mission. The pause on reserve operations will test how resilient the UBI distribution system is when the backing behind it stops moving, and how quickly the project can rebuild trust with the liquidity providers it depends on.
