
Key facts
- Core DAO is planning an emergency hard fork after validators drew excess CORE rewards.
- The project says the incident is contained and that malicious validators can no longer claim additional rewards.
- The fork will be a forward upgrade and will not roll back the network or reverse confirmed transactions.
- Core has not disclosed the amount of excess CORE issued, how long the activity lasted, or whether any extra tokens entered circulation.
- Several exchanges, including Coinbase, Bithumb, Coinone, Bitget, and LBank, restricted CORE transfers following the event.
Core DAO is coordinating an emergency hard fork after validators successfully claimed more CORE rewards than the blockchain’s issuance policy intended. In a public update, Core said the incident had been contained and that “malicious validators” could no longer draw excess rewards. The project emphasized that the upcoming fork would be a forward upgrade and would not roll back the network or reverse any previously confirmed transactions.
The development follows an earlier status update in which Core said a small number of validators had accrued rewards significantly above the protocol’s intended issuance. At that time, Core stressed that the issue was confined to reward issuance and that user assets remained safe. The team also said it would publish a technical postmortem after completing its investigation.
Exchange response and market impact
Several cryptocurrency trading platforms moved quickly to limit CORE activity after the incident became public. Coinbase paused CORE sends and receives on the Core network, citing potential network instability or security concerns. South Korean exchanges Bithumb and Coinone suspended deposits and withdrawals, with statements pointing to suspected or confirmed security issues. Bitget also temporarily halted CORE deposits and withdrawals, saying it needed to perform wallet maintenance. LBank suspended deposits, explaining that the project’s requirements necessitated the action.
These exchange actions were precautionary rather than an indication of user fund losses. Core repeatedly stated that user assets were safe and that the abnormal behavior affected only the reward distribution process. Still, the restrictions highlight how quickly centralized platforms respond to on-chain anomalies, especially when validators are involved.
Unanswered questions
Core has not yet revealed several important details about the exploit. The project has not said how much CORE was issued beyond the protocol’s intended schedule, how long the validators were able to exploit the mechanism, or whether any of the excess tokens were transferred to exchanges or entered broader circulation. It also has not explained the root vulnerability that allowed validators to obtain rewards above the intended rate.
The lack of immediate disclosure is not unusual for incident responses, as teams often wait until a full postmortem is prepared before sharing technical specifics. However, validators, token holders, and exchange security teams will likely want precise answers before normal CORE operations fully resume. The promised postmortem will be critical for restoring trust and for helping other blockchain projects avoid similar flaws in their reward accounting logic.
Understanding hard forks and emergency upgrades
A hard fork is a permanent change to a blockchain’s protocol that makes previously invalid blocks valid, or vice versa. Nodes running the new rules must upgrade, and the network may split if some participants refuse to accept the changes. Emergency hard forks are often deployed when a critical vulnerability, exploit, or network rule violation threatens the integrity of the chain or user funds.
Core’s decision to call its intervention a “forward upgrade” is meant to signal that the chain will not undergo a rollback. A rollback would mean reverting the blockchain to an earlier state, potentially undoing confirmed transactions. That approach is controversial because it can disrupt applications, bridges, and users who relied on finality. By contrast, a forward upgrade typically introduces new rules that prevent further exploitation while preserving the chain’s existing history.
Core’s approach is similar to several recent emergency actions in the crypto industry. In August 2026, Cronos executed a rollback to reverse transfers tied to a $120 million Tectonic exploit. The rollback erased $111 million of the transferred funds, restoring balances to their pre-exploit state. That decision generated intense debate because rollbacks can conflict with the principle of immutability. Polygon also disclosed security flaws that were fixed in recent hard forks, showing that even established networks occasionally require urgent upgrades.
BNB Chain, the ecosystem associated with the world’s largest cryptocurrency exchange by token market cap, activated the Pasteur hard fork to strengthen bridge security. Bridges are frequent targets for attackers because they often hold large amounts of lock collateral. Hard forks cannot prevent every exploit, but they can close specific vulnerabilities once discovered.
What is Core DAO?
Core DAO is a blockchain project built to combine the security attributes of Bitcoin with smart contract functionality. The network is known for its Satoshi Plus consensus mechanism, which uses delegated Bitcoin mining hash power and delegated proof of stake to secure the chain. This design aims to bring Bitcoin-aligned incentives to an Ethereum-compatible environment, allowing developers to deploy smart contracts and decentralized applications.
The project’s native token, CORE, is used for staking, governance, and paying network fees. Like many proof-of-stake-inspired systems, Core depends on validators to produce blocks and secure the network. Validators are typically rewarded from an issuance schedule controlled by protocol parameters. When those parameters fail to constrain payouts, as appears to have happened in this incident, the token’s economic model can be weakened.
Core’s positioning as a Bitcoin-anchored layer-1 has drawn attention from both Bitcoin maximalists and decentralized finance enthusiasts. However, the project has also faced the broader challenge shared by all emerging blockchains: ensuring that complex economic incentives function correctly under adversarial conditions. Reward issuance exploits can undermine confidence in a network’s monetary policy and in the reliability of its validator set.
Why validator reward exploits matter
Validators are responsible for transaction settlement and consensus. When validators can claim more rewards than the protocol intends, it signals a flaw in the consensus layer’s accounting or distribution logic. In this case, the exploit appears to have affected only reward issuance, allowing certain validators to accumulate excessive CORE. If such a flaw were expanded or repeated, it could create inflationary pressure and distort the network’s economic balance.
Because blockchain rewards are often paid automatically through smart contracts or consensus state transitions, developers must carefully guard against arithmetic errors, overflow issues, and edge cases in reward calculations. A single overlooked condition can sometimes let a validator claim rewards repeatedly or in amounts disproportional to their stake. The fact that Core called the validators “malicious” suggests the team believes the excess withdrawals were intentional rather than accidental.
Security researchers frequently warn that incentive-layer vulnerabilities are among the most damaging because they directly affect the token supply. Exploits that drain user funds are easier to detect and often trigger immediate emergency responses. Reward accounting flaws can be subtler, and by the time they are discovered, the excess issuance may already be significant. Core’s disclosure did not include a dollar figure, but the decision to coordinate an emergency hard fork suggests that the issue was serious enough to warrant a network-level intervention.
Reactions from the broader crypto community
The incident has drawn attention across the crypto community, particularly among those who follow validator behavior and network governance. Some observers noted that Core’s quick disclosure and planned hard fork reflect an increasingly common playbook for handling on-chain vulnerabilities: acknowledge the issue, contain it, reassure users about asset safety, and announce a governance upgrade. Others are more cautious, noting that the absence of a full technical postmortem makes it difficult to gauge the severity of the exploit.
Exchange decisions to suspend CORE activity are likely to remain in place until Core provides more clarity. In previous incidents involving chain-level issues, exchanges have waited for network stability confirmation before reopening deposits and withdrawals. Users holding CORE may face temporary delays, but those delays are typically designed to prevent additional losses or confusion during the upgrade window.
The Core DAO team has not provided an exact timeline for the hard fork. The project said only that it is coordinating the upgrade and that it would share further updates as information becomes available. It also promised a technical postmortem, which is expected to include the root cause analysis, the timeframe of the exploit, and the steps being taken to ensure that the same bug does not reappear after the fork.
History of core network security and governance
Core DAO has positioned itself as a community-driven project, with core development teams and a token-holder governance process. While the network has grown since its launch, it remains in a competitive landscape filled with Ethereum layer-2 networks, alternative layer-1s, and Bitcoin sidechains. Maintaining robust security and predictable issuance is essential for attracting long-term liquidity and institutional participation.
This is not the first time a blockchain has had to fork after a validator-related anomaly. In past incidents, networks have faced situations where validators received rewards for empty blocks, incorrect proposer rewards, or staking parameters that did not match real-world conditions. Each incident teaches the broader industry to audit consensus math more deeply and to implement circuit breakers that pause reward distribution when unusual patterns are detected.
The Core team’s decision to avoid a rollback may help preserve user confidence in the immutability of confirmed transactions. Rollbacks, even when designed to restore stolen funds, can create significant downstream problems for decentralized applications, bridges, and users who executed legitimate trades after the exploit. By choosing a forward upgrade, Core is signaling that it wants to stop the bleeding without rewriting history.
Still, the hard fork itself may create temporary divisions in the network if some validators or node operators refuse to upgrade. In forward upgrades, the chain typically retains one valid history if the majority of hash power and stake follows the new rules. Core will likely encourage all node operators to upgrade promptly to ensure a smooth transition and avoid network splits.
What to watch in the coming days
Market participants will be watching several factors in the aftermath of the incident. First, they will want to know the exact amount of excess CORE that was generated. If the number is large relative to the network’s total supply, it could create sell pressure or force the project to consider additional burn mechanisms. Second, they will be watching the technical postmortem for details on whether the vulnerability involved a known bug that should have been caught in an audit. Third, they will watch exchange announcements to see when CORE deposits and withdrawals are reopened.
Core’s emergency hard fork will also be tested against its stated goal of remaining fully decentralized. A response coordinated by the core team and validators can be viewed as practical risk management, but it also reminds users that even decentralized networks rely on coordinated development teams during emergencies. The broader crypto industry has accepted this reality in recent years, with many projects implementing governance emergency procedures that allow for swift action when critical vulnerabilities arise.
In the meantime, Core advises users to remain calm and to monitor official channels for updates. Until the postmortem is released, independent researchers may attempt to recreate the conditions that led to the excess reward claims. If they can identify the root cause before Core does, that could raise ethical concerns about responsible disclosure. Core’s own postmortem should help clear the air.
The hard fork represents a defining moment for Core DAO. The project has the opportunity to demonstrate transparency, technical competence, and a commitment to its user base. If the postmortem is detailed and the fork executes smoothly, Core could emerge from this incident with stronger credibility. If questions remain unanswered, however, the community may struggle to regain full confidence in the network’s reward mechanism.
All eyes are now on Core’s next announcement. The project has acknowledged the incident, reassured users, and promised a path forward. The emergency hard fork is not expected to be the final chapter, as the team will need to rebuild trust and prove that the governance and technical safeguards behind the upgrade are robust enough to prevent a repeat event.
Source:Cointelegraph News
