Hacks & Exploits
GoodDollar Suffers $100,000 Loss Due to Superfluid Bug Exploit
GoodDollar, a decentralized universal basic income (UBI) protocol, has announced a significant loss exceeding $100,000 due to a bug in the Superfluid protocol. The incident occurred on September 9, when an attacker exploited a vulnerability that allowed them to drain funds from GoodDollar's reserves.
The exploit involved the creation of excess G$ tokens on the Celo network, leading to the exchange of 86,588 cUSD from GoodDollar's Celo reserve and an additional $20,857 from its XDC reserve. The malicious Super App bypassed Superfluid’s liquidation safeguards, affecting external G$ liquidity pools as well, although the extent of those losses remains undisclosed.
GoodDollar's dashboard indicates that the protocol has over 963,000 unique UBI claimants and has distributed 2.3 billion G$ tokens, making the reserve crucial for its daily distribution system. Approximately 28% of the total G$ supply circulates on Celo, with 2.4 billion G$ tokens in total across various networks.
Superfluid's Security Council stated that the vulnerability was specific to its Celo deployment, allowing the malicious application to bypass whitelisting requirements. After detecting insolvent accounts on September 3, Superfluid implemented a hotfix and reinstated whitelisting on Celo, closing the affected accounts.
GoodDollar has reassured users that its Celo and XDC reserves were not fully depleted, thanks to monitoring alerts and existing protocol safeguards. However, operations on Celo and XDC remain paused, and users have been advised against swapping G$ until liquidity improves.
The unexplained loss from the XDC reserve has raised further questions, as GoodDollar plans to address the excess G$, restore liquidity, and reopen paused functions. Both GoodDollar and Superfluid are preparing incident reports to provide a detailed account of the exploit and its implications.
FAQ
What caused the $100,000 loss for GoodDollar?
The loss was due to a bug in the Superfluid protocol that allowed an attacker to exploit a vulnerability, draining funds from GoodDollar's reserves.
When did the exploit occur?
The exploit occurred on September 9, when the attacker created excess G$ tokens on the Celo network.
How much was drained from GoodDollar's reserves?
The attacker drained 86,588 cUSD from GoodDollar's Celo reserve and an additional $20,857 from its XDC reserve.
What actions has GoodDollar taken following the exploit?
GoodDollar has paused operations on Celo and XDC, advised users against swapping G$, and is working to address the excess G$ and restore liquidity.
What is the current status of GoodDollar's reserves?
GoodDollar's reserves were not fully depleted, and they have over 963,000 unique UBI claimants, but operations on Celo and XDC remain paused until liquidity improves.