SafeDollar's SDO Stablecoin Collapses to Zero After $250K Infinite-Mint Exploit
SafeDollar, a stablecoin protocol running on Polygon, saw its SDO token collapse to $0 after an attacker exploited an infinite-mint bug in the project's reward mechanism, walking away with roughly $250,000 (later specified as about $248,000). It was the second exploit the protocol suffered within the same week, following an earlier incident that had already prompted a postmortem post from the team thanking users for their continued support and describing the first hack as a challenge they intended to work through. The case landed at position 36 on rekt.news's leaderboard.

Polygon's user base had grown substantially in the preceding months, partly as users sought relief from Ethereum congestion and partly to escape a string of exploits on Binance Smart Chain protocols. That migration did not eliminate the underlying risk, and SafeDollar's second incident in a week demonstrated as much — echoing a question raised less than two weeks earlier about whether algorithmic stablecoins are inherently prone to this kind of failure.
The exploit centered on manipulating the protocol's internal accSdoPerShare accounting variable. The attacker first made a deposit into one of SafeDollar's Safe Farms. The farm's incentivized token, PLX, charges a transfer fee that is supposed to be paid by the withdrawing user — but a flaw in the contract meant that during withdrawals, this fee was instead deducted from the rewarder contract's own PLX balance.
By repeatedly depositing and withdrawing in a loop across 101 transactions, the attacker gradually drained the pool's PLX balance, which in turn inflated the accSdoPerShare value to an extreme 1,142,913,215,739,484,400 SDO owed per PLX deposited.
With the accounting sufficiently skewed, the attacker executed a final transaction claiming rewards on their original deposit, receiving a total of 831,309,277,244,108,000 SDO. They immediately sold this position, crashing SDO's price to $0.00 in the process. Because the pool's remaining exit liquidity was limited, the attacker was only able to extract 202,000 USDC and 46,000 USDT despite technically holding a vastly larger nominal quantity of SDO.
The result is a hack far smaller in dollar terms than many others on the leaderboard — closer to $248,000 than $248 million — but one that follows a familiar pattern: a protocol replicating existing DeFi code without adequately reviewing it for edge cases.

Get new scam files the moment we publish them — usually 2–3 emails a week.