A small group of Core blockchain validators found a way to extract more block rewards than the protocol was designed to issue, and now the entire network is getting an emergency hard fork to fix the damage.
Core DAO, the organization behind the Layer 1 blockchain, confirmed the incident and labeled the validators’ behavior as malicious. The project says user assets, network security, and custody systems remain unaffected, but the situation has already spooked exchanges into taking precautionary measures.
What happened and what’s being done
Core’s blockchain runs on a hybrid consensus mechanism called Satoshi Plus. It blends elements of Bitcoin’s delegated proof-of-work with delegated proof-of-stake, creating a system where up to 90% of newly minted CORE tokens flow to selected validators based on a complex scoring formula.
That scoring system, it turns out, had a flaw. A limited number of validators figured out how to exploit the reward distribution mechanism to claim tokens beyond the protocol’s intended issuance schedule.
Core DAO initially identified only a small number of actors involved. After further investigation, the project reclassified their behavior as explicitly malicious rather than an accidental windfall.
The fix comes in the form of an emergency hard fork, which Core DAO is coordinating directly with its validator set. Crucially, this is a forward-only upgrade. No transactions will be reversed, no blocks will be rolled back, and the network’s existing state stays intact. The upgrade is designed purely to patch the reward distribution vulnerability and prevent future exploitation.
Exchange responses and market fallout
Coinbase paused CORE sends and receives on August 31, 2026, though trading of the token continued on the platform. LBank went further, suspending deposits entirely, citing project requirements.
The core concern is oversupply. CORE has a hard cap of 2.1 billion tokens, with roughly 40% of that total allocated to node mining rewards distributed over an 81-year emission schedule. If validators managed to extract a meaningful number of tokens beyond protocol limits, that carefully designed supply curve starts to look less like a feature and more like a suggestion.
The exact volume of excess tokens minted during the exploit remains unclear. Until Core DAO publishes a full accounting of how many extra tokens entered circulation, traders are essentially flying blind on the token’s actual supply dynamics.
The broader risk picture
Core’s Satoshi Plus consensus combines delegated proof-of-work and delegated proof-of-stake into a single scoring mechanism that distributes up to 90% of new token supply to selected validators. The system’s complexity creates a larger attack surface than simpler consensus designs.
For CORE holders, the immediate priority is watching for two things. First, the postmortem investigation needs to produce a precise accounting of excess tokens. If the number is small relative to circulating supply, the damage to tokenomics may be manageable. If it’s large, the project’s value proposition around controlled, long-term issuance takes a serious hit.
Second, the execution of the hard fork itself matters. A smooth upgrade that patches the vulnerability without disrupting network operations would demonstrate operational competence.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

58 minutes ago
21








English (US) ·