TL;DR
- Core DAO is preparing a hard fork after a number of validators claimed more CORE rewards than intended, while Core says user assets remained safe.
- Coinbase, Bithumb, Coinone, Bitget and LBank restricted CORE transfers or deposits as exchanges responded cautiously to the incident and awaited greater network stability.
- Core has not disclosed the excess issuance amount, duration, circulation impact or underlying vulnerability, making its promised technical postmortem crucial for transparency.
Core DAO is preparing an emergency hard fork after a small number of validators claimed substantially more CORE rewards than the protocol intended to issue. The network said the incident has been contained and that “malicious validators” can no longer draw excess rewards. The critical reassurance is that Core says user assets remained safe and the problem was limited to reward issuance. The planned fork will move the network forward rather than roll it back, meaning previously confirmed transactions will not be reversed as developers work to close the underlying problem and stabilize validator behavior.
Update: the issue is contained and the malicious validators can no longer draw excess rewards.
We're now coordinating an emergency hardfork with validators to deploy the permanent fix. This is a forward upgrade, not a rollback.
Assets remain safe. Full post-mortem to follow. https://t.co/0sJOJf4Qco
— Core DAO 🔶 (@Coredao_Org) September 1, 2026
Core’s Hard Fork Aims To Preserve Finality While Closing The Reward Exploit
Several exchanges restricted CORE transfers around the incident, reflecting caution while the network response develops. Coinbase paused sends and receives on Core, while Bithumb and Coinone suspended deposits and withdrawals over suspected or confirmed security concerns. Bitget also halted CORE deposits and withdrawals, citing wallet maintenance, and LBank suspended deposits based on project requirements. The exchange reactions show that containment at the protocol level did not eliminate operational uncertainty for market infrastructure. These restrictions can remain relevant until exchanges are satisfied that the network upgrade and validator environment are stable enough to resume normal processing.

Details remain undisclosed. Core has not said how much additional CORE was issued, how long validators were able to accrue excessive rewards, or whether any of those tokens entered circulation. The project has also not explained the vulnerability that allowed the abnormal reward claims. That information gap makes the promised technical postmortem central to understanding the economic and security impact of the incident. Without figures on excess issuance or circulation, users and exchanges cannot yet quantify the supply effect, even though Core has stated that the issue was contained and user assets were not affected.
The hard fork is focused on preventing abuse rather than rewriting network history. Core said malicious validators can no longer obtain excessive rewards, while the forward upgrade is intended to reinforce containment without reversing confirmed transactions. The key test is whether the hard fork can restore confidence while preserving finality and clarifying how the reward mechanism failed. Until the postmortem is published, the incident remains unresolved from a transparency perspective, with exchanges, validators and users waiting for technical details on the vulnerability, the amount of excess CORE created and whether any additional tokens reached circulation.




