Superfluid hack — February 2022
Incident facts
| Date of incident | |
|---|---|
| Target type | Infrastructure provider |
| Loss | $8,700,000Published estimates range $8,700,000 to $13,000,000Price at time of incident |
| Method | Access control flawSuperfluid's Host contract passes a serialised context object (ctx) to agreement contracts carrying the identity of the original caller; the agreements did not verify the ctx against the hash held by the Host, so a caller could append a forged ctx naming any address and, through the Instant Distribution Agreement, act on that address's Super token balance. |
| Chains | Polygon |
| Outcome | Unresolved |
What happened
On 8 February 2022, from 06:48 UTC, an attacker used a flaw in Superfluid's Host contract to move Super tokens out of other people's accounts on Polygon.
Superfluid passes a serialised context object, ctx, between its Host contract and its agreement contracts, and ctx carries the identity of the original caller. The agreements did not check the ctx they received against the hash the Host had stored, so a caller invoking callAgreement could append a forged ctx naming somebody else. When the calldata was deserialised the forged copy was the one retained. Using the Instant Distribution Agreement, the attacker created distributions on behalf of accounts they did not control and drained their balances.
Superfluid's post-mortem lists the assets taken as 11,008 MATIC, 1,507,931 MOCA, 28 ETH, 39,357 sdam3CRV, 19,387,874 QI, 44,581 SDT, 23,653 STACK and 562,834 USDC, and says over 2,700 ETH and 500,000 MOCA sat in the attacker's wallet afterwards. Most of the loss fell on QiDAO backers and team vesting allocations; Stake DAO, Stacker Ventures and Museum of Crypto Art tokens were also hit. QiDAO said its vaults and user funds were untouched.
Totals published for the incident vary widely and Superfluid's own report gives none. Hack trackers settled on about $8.7 million, close to the value of the ether the attacker was left holding, while SlowMist's analysis of the attacker's wallet, reported by Cointelegraph and repeated by Halborn, put the haul near $13 million on the tokens' pre-sale prices. Selling the stolen tokens moved prices sharply, with Cointelegraph reporting QI falling from $1.24 to $0.18 on QuickSwap, which is most of the gap between the two figures. Superfluid patched the contracts within about five and a half hours — an emergency block at 10:54 UTC and a full redeployment at 12:23 UTC — and within 18 hours recapitalised 80 per cent of affected addresses by direct USDC transfer, agreeing a longer-term plan for the rest. A $1 million bounty was offered for the return of the funds; no return has been reported.
Sources
- SuperfluidPrimary · retrieved 2026-08-01
- CointelegraphSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
- Web3 Is Going GreatSecondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/superfluid-blog/08-02-22-exploit-post-mortem-15ff9c97cdd
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Superfluid hack — February 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/superfluidhttps://itokenly.com/hacks/superfluidPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.