GoodDollar said on Sept. 9 that 86,588 cUSD had been exchanged out of its Celo reserve during the incident, while another $20,857 was exchanged from its XDC reserve. External G$ liquidity pools were also affected, although the projects have not yet disclosed the full amount lost from those pools.
The incident was linked to a vulnerability in Superfluid, a protocol used by GoodDollar for streaming G$ balances. Superfluid’s Security Council said a malicious Super App was able to bypass the normal stream-liquidation process on Celo, allowing insolvent G$ balances to remain active when they should have been liquidated.
Those excess balances were subsequently exchanged against assets held in GoodDollar’s reserve and other G$ liquidity pools on Celo, according to Superfluid’s preliminary disclosure. The protocol said the underlying bug resulted from the way its Celo deployment had historically been configured and emphasized that other Superfluid deployments were unaffected.
Superfluid first detected unusual activity on Sept. 3, when its infrastructure flagged several insolvent accounts on Celo. The following day, the team determined that the accounts could not be liquidated because of the vulnerability involving the malicious Super App.
Superfluid said it identified a hotfix later on Sept. 4 and deployed it on Celo at around 2 p.m. UTC. The fix reinstated the network’s Super App whitelisting process, while the affected insolvent accounts were closed about an hour later. The Security Council subsequently reviewed Super App registration processes across other networks and said the exploit path could no longer be reproduced.
The problem is that this explanation does not account for GoodDollar’s XDC loss.
Superfluid’s Security Council explicitly described the vulnerability as one that “could only have occurred on CELO,” while GoodDollar separately reported that $20,857 had been exchanged out of its XDC reserve. Neither project has yet explained how the Celo incident resulted in that XDC outflow.
The discrepancy is particularly important because XDC was not simply another pool on the Celo network. GoodDollar maintains reserves across multiple networks, and its dashboard shows hundreds of millions of G$ circulating on XDC. Recent figures indicate roughly 292.5 million G$ on XDC, compared with about 2.4 billion on Celo.
GoodDollar has said its reserves were not completely depleted and that monitoring alerts, emergency pauses and existing safeguards helped contain the incident. Claiming, G$ transfers and identity verification have resumed on Celo, but reserve operations on both Celo and XDC remain paused. Bridging has also been suspended while the incident is investigated.
The protocol has also warned users against swapping G$ while external liquidity remains thin. Limited liquidity could produce substantial slippage and prices that diverge significantly from normal market levels, making the aftermath of the exploit potentially more disruptive than the direct reserve loss alone.
The incident affects a protocol with a relatively large user base. GoodDollar describes itself as a decentralized universal basic income system, with its dashboard showing more than 963,000 unique claimants and approximately 2.3 billion G$ distributed. Its reserve therefore plays a central role in supporting the economics behind the token and its daily distribution system.
GoodDollar has said it will address the excess G$ created during the incident, restore liquidity and reopen the remaining paused functions once its remediation process is complete.
Both GoodDollar and Superfluid are expected to publish separate incident reports. Those reports are supposed to provide additional technical details, account for losses in external liquidity pools and, crucially, explain how the Celo exploit produced an outflow from GoodDollar’s XDC reserve.
Until then, the XDC component remains the biggest unresolved element of the incident.
The $20,857 Question Matters More Than the Size of the Loss
The obvious temptation is to focus on the roughly $107,000 disclosed reserve loss. In DeFi terms, that is not an especially large exploit.
The more interesting issue is the inconsistency in the technical explanation.
Superfluid says the vulnerability was Celo-specific. That appears reasonably straightforward: a configuration choice on Celo allowed a malicious Super App to bypass the normal whitelisting mechanism, which in turn prevented insolvent G$ streams from being liquidated. The resulting excess G$ could then be exchanged against liquidity on Celo.
But if that is the complete attack path, why did $20,857 leave the XDC reserve?
There are several possibilities, but none should be treated as fact yet. The excess G$ could have moved through a bridge or some other cross-chain mechanism. There could have been a liquidity relationship between the Celo and XDC environments that allowed an event originating on Celo to affect the XDC reserve. The reserve accounting itself could also be more complicated than the initial disclosures suggest.
And there is a less comfortable possibility: the Celo vulnerability may not explain every transaction associated with the incident.
That is why the promised incident reports matter. The transaction trail should make this relatively easy to establish. If the projects can show the exact path from the malicious Super App to the Celo reserve, through any intermediate liquidity or bridging mechanism and eventually to the XDC reserve, then the apparent contradiction disappears.
If they cannot, the industry will have to consider whether there was another weakness involved.
The distinction is important because cross-chain infrastructure changes the way security incidents should be assessed. A vulnerability can be technically confined to one blockchain while its economic consequences spread elsewhere. Saying that “only Celo was vulnerable” does not automatically mean that “only Celo could lose money.”
GoodDollar’s decision to keep bridging paused therefore looks sensible. Until the teams understand how the XDC loss occurred, reopening the mechanism connecting different networks could recreate an exposure they have not yet fully mapped.
There is another issue here that is easy to overlook. GoodDollar’s reserve was not completely drained, but the incident still created excess G$ and disrupted liquidity. That means the damage is not limited to the assets that actually left the reserve. Thin liquidity, unusual G$ balances and suspended bridging can create secondary pressure on the token’s price and on users trying to exchange it.
For now, the responsible conclusion is that the Celo exploit is understood reasonably well, while the XDC loss is not.
That unanswered $20,857 may ultimately turn out to be a simple cross-chain consequence of the original attack. But until the transaction path is published, it remains the part of the incident that deserves the closest scrutiny.
Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms.
He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments.
Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

