Superfluid Hack

TOTAL LOST $20.0M
High CTX Exploit / Other polygon

Summarize with AI

Affected Chain polygon Incident surface
Recovered - No recovery reported
All-Time Rank #229 By amount stolen
Auditors 1 Prior security audit

Incident Overview

Superfluid protocol was exploited which lead to a loss of project funds for roughly 20,000,000 $USD.

Superfluid is a streaming protocol for real-time crypto transfers. On February 8, 2022, an attacker exploited Superfluid’s host contract by passing in faulty calldata, which allowed them to create distribution indexes spoofing several different accounts that held Super-tokens. This vulnerability enabled the attacker to move funds from Superfluid user wallets to exchanges on Polygon and swap them to ETH. The funds currently sit in the attacker’s wallet.

In total, 11,008 MATIC, 1,507,931 MOCA, 28 ETH, 39,357 sdam3CRV, 19,387,874 QI, 44,581 SDT, 23,653 STACK, and 562,834 USDC were stolen by the attacker. At the time of writing, over 2,700 ETH is sitting in the attacker’s wallet, as well as 500,000 MOCA.

callAgreement() function was exploited by replacing the bytes memory callData parameter. This parameter contains ctx value which can be decoded to get such properties: timestamp, msgSender, agreementSelector, userData, appAllowanceGranted, appAllowanceWanted, appAllowanceUsed, appAddress, appAllowanceToken. Ctx was replaced with the fake one, so the attacker was able to drain all SuperToken contract funds.

Attacker address:

https://polygonscan.com/address/0x1574f7f4…53c090

Malicious transaction:

https://polygonscan.com/tx/0x396b6ee9…ab4d67

Malicious contract:

https://polygonscan.com/address/0x32d47ba0…8da6d4

Claim transaction:

https://polygonscan.com/tx/0xdee86cae…dd6af6

Incident Report

Protocol / Project Superfluid
Date of Incident
Affected Chain(s) polygon
Attack Technique CTX Exploit / Other
Classification Protocol Logic / Other
Primary Source View Post-Mortem

Protocol Information

Protocol Type Payments
Affected Token SuperQI
Smart Contract Language Solidity
Official Website www.superfluid.finance/
Protocol Twitter/X @Superfluid_HQ
Team Anonymous
Source Code Verified On-Chain

Market Context at Time of Hack

Token Categories
BNB Chain Ecosystem

What the Attacker Needed to Succeed

Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.

Technical Knowledge Deep understanding of ctx exploit / other and Solidity and EVM internals
Capital Required Seed capital to cover gas and initial position setup
On-Chain Access Ability to interact with polygon smart contracts and deploy a custom exploit contract
Protocol Analysis Identification of the exploitable vulnerability in Superfluid's contract logic - root cause: protocol logic / other
Execution Speed Precise transaction ordering and timing to exploit the vulnerability within a single atomic block
Obfuscation Plan A strategy to launder and move stolen funds - typically through mixers, cross-chain bridges, or decentralized DEX swaps to resist tracing

What Auditors Should Check

Could this have been caught in audit? Likely — with a thorough CTX Exploit / Other audit checklist and test coverage
Audited by Audit Report 1 — still lost $20.0M. Prior audits don't guarantee safety, especially after post-audit code changes.

If you're auditing a protocol with similar architecture to Superfluid, these are the critical security checks that could have prevented this incident (February 2022).

  • Verify all logic paths related to CTX Exploit / Other are guarded by proper access controls and input validation
  • Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs

Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.

Free Trial

Security Audit History

Sources & References

Learn to Prevent the Next Superfluid

The Superfluid hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.

Recreate exploit patterns safely Free Trial