Core DAO is coordinating an emergency hard fork after a small number of validators claimed more CORE rewards than the protocol intended to issue. The project said the incident is contained and that malicious validators can no longer draw extra rewards. It also said the planned fork is a forward upgrade, meaning it will not roll back the network or reverse previously confirmed transactions.
The update came after Core acknowledged potential reward irregularities and said user assets were not affected. According to the project, the issue was limited to reward issuance rather than the security of user funds. Core said it will publish a technical postmortem after the upgrade and follow-up analysis are complete.
What happened on the Core network
Core DAO operates an Ethereum-compatible layer-1 network that connects with Bitcoin miners through its Satoshi Plus consensus model. The network uses CORE as its native token. Validators receive newly issued tokens as a reward for processing transactions and maintaining network liveness. These rewards are normally controlled by rules embedded in the blockchain code so that supply issuance remains predictable.
According to Core's update, some validators were able to accumulate rewards significantly above the intended issuance. The protocol was supposed to cap how many new CORE tokens could be distributed in a given period, and the validators appear to have found a way to claim more. Core did not immediately describe the flaw in detail, but it acknowledged that the behavior was caused by validators acting contrary to the protocol rules.
The incident was first disclosed through a status update in which Core said it had identified unusual reward activity. That message was intended to inform users and exchanges before the problem could affect the market. By the time the update reached the public, several exchanges had already taken precautionary measures to limit CORE token movement.
Emergency hard fork explained
A hard fork is a change to the underlying protocol that is not compatible with older clients. After a hard fork, node operators, validators, and users must update their software if they want to continue following the network's rules. In this case, Core has said the fork is necessary to stop the validators from drawing additional rewards.
The distinction between a forward upgrade and a rollback is important. A rollback would delete or rewrite blocks that have already been processed, which can create instability and cause users to lose transactions they believed were final. Core has said it will not do that. Instead, the chain will continue from its existing block history, and the software change will be implemented from the moment the fork becomes active.
This type of emergency fork is common when a vulnerability has been discovered in a live blockchain. Projects often announce a block height at which the new rules will take effect. Validators and exchanges are asked to upgrade before that height so the network does not split into two chains. If a large number of participants do not upgrade, the network could split into competing versions.
How exchanges responded
Shortly after the issue became public, several exchanges moved to protect users by pausing CORE deposits and withdrawals. Coinbase paused token sends and receives on the Core network, citing the ongoing chain issue. Bithumb and Coinone suspended deposit and withdrawal services, saying they had detected suspected or confirmed security concerns. Bitget also halted CORE transfers due to wallet maintenance, while LBank said it was suspending deposits because of project requirements.
These actions are the standard first line of defense when a blockchain is planning an emergency fork. If tokens are moving freely across exchanges while code changes are being made, there is a risk that users will buy or sell tokens that become temporarily locked during the upgrade. Pausing withdrawals also gives the network time to identify the scale of the excess issuance before additional tokens are mixed with normal balances.
Exchange statements were not identical. Some cited security concerns directly, while others described maintenance or project-side requirements. This is a reflection of how quickly information was changing. Core did not claim that user funds were stolen or at risk, and the exchanges likely wanted to avoid triggering a panic while they gathered their own data.
Unanswered questions about the excess issuance
Core has not yet explained how many CORE tokens were claimed beyond the intended amount. It also has not said how long the validators were able to draw the extra rewards or whether those tokens were moved into exchanges or wallets. This creates uncertainty for traders and analysts who are trying to determine whether the excess supply could create selling pressure.
Source: Cointelegraph News