Celo Bug Exposes GoodDollar Reserves to Over $100,000 in Losses
A decentralized universal basic income protocol called GoodDollar suffered a security breach on September 9, resulting in over $100,000 being drained from its reserves. The attack was attributed to a bug in Superfluid's Celo deployment, which allowed a malicious application to bypass whitelisting requirements and exchange excess G$ against assets in the GoodDollar Reserve.
The vulnerability, known as a 'Super App' bug, left insolvent G$ balances active, allowing them to be exchanged for other assets. Superfluid detected the issue on September 3 and deployed a hotfix the following day, reinstating whitelisting requirements and closing affected accounts.
GoodDollar's reserves were not depleted, but its Celo and XDC reserve operations remain paused while bridging is suspended and liquidity in external pools remains limited. The project has warned users against swapping G$ until liquidity improves, citing potential slippage and divergent prices.