Core DAO Prepares Emergency Hard Fork After Validator Reward Exploit
Key Takeaways
- •Core DAO is preparing an emergency hard fork after validators accrued more CORE rewards than the protocol intended.
- •The project says the issue has been contained and that malicious validators can no longer claim excess rewards.
- •The upgrade will be forward-only, so previously confirmed transactions will not be reversed.
- •Core has not disclosed how much additional CORE was issued, how long the exploit lasted, or whether any excess tokens entered circulation.
- •Exchanges including Coinbase, Bithumb, and CoinOne restricted CORE transfers during the incident.

Core DAO is preparing an emergency hard fork after a small group of validators were able to accrue CORE rewards above the level intended by the protocol, exposing a different class of blockchain vulnerability: validators exploiting the network’s own issuance mechanism.
Core says the issue has been contained and that malicious validators can no longer claim excess rewards. The upgrade will be forward-only, meaning previously confirmed transactions will not be reversed.
The immediate concern is supply.
Core has not disclosed how much additional CORE was issued, how long the exploit lasted, or whether any of the excess tokens entered circulation. Exchanges including Coinbase, Bithumb, and CoinOne restricted CORE transfers amid the incident, underscoring how quickly protocol-level issues can spill into market operations even when the underlying chain remains live.
That makes this more than a routine software bug.
Validators sit at the heart of proof-of-stake networks, where they help determine blocks and receive protocol rewards. Core’s own documentation says validator rewards include newly minted CORE, with 90% of the reward allocation going to validators and their delegators.
Two Addresses Control Over 45% of Ethereum Validator Nodes Post Merge
Two Addresses Control Over 45% of Ethereum Validator Nodes Post Merge
The precedent is the bigger story.
This is not the first time validator infrastructure has been exploited to create unintended economic outcomes. Shardeum previously disclosed a validator-software flaw that improperly credited about 500,000 SHM after an attacker manipulated certificate-validation logic.
Core therefore highlights a broader security risk for blockchain networks: a vulnerability does not need to compromise user wallets or reverse transactions to threaten network economics. If validators can influence issuance, rewards, or consensus accounting, they can potentially alter the monetary policy encoded in the protocol itself.
CASE STUDY | Bitcoin Payment Infrastructure Hit by Exploit Targeting Lightning Nodes
CASE STUDY | Bitcoin Payment Infrastructure Hit by Exploit Targeting Lightning Nodes
The eventual Core post-mortem will be important. Until the project discloses the root cause and the amount of excess CORE created, the full scale of the vulnerability, and how easily similar reward mechanisms could be exploited elsewhere, remains unclear. For other proof-of-stake systems, the episode is a reminder that reward logic and validator accounting are not just technical details; they are part of the chain’s economic core and can become a focal point for incident response.
The key unanswered question for the industry is therefore not just “Can validators steal funds?” but “Can a validator exploit protocol accounting to mint or claim assets the network never intended to issue?”
CASE STUDY | Cronos Blockchain Halts After an Exploit on its Largest Lending Protocol
CASE STUDY | Cronos Blockchain Halts After an Exploit on its Largest Lending Protocol