Key Highlights
- Core DAO disclosed a reward-accounting exploit that released approximately 255 million CORE in validator rewards ahead of schedule between August 28 and August 31.
- The incident did not increase Core’s 2.1 billion maximum supply, but brought future validator emissions into circulation earlier than planned.
- About 186.153 million CORE was removed through the September 3 network reconciliation.
The Bitcoin-focused Layer-1 blockchain Core DAO has disclosed a reward-accounting exploit that caused approximately 255 million CORE in validator rewards to be released ahead of schedule between August 28 and August 31.
In a post on X on Saturday, Core said the issue affected the protocol’s mechanism for crediting block rewards. The exploit did not increase the network’s fixed 2.1 billion maximum supply, but caused rewards scheduled for future emissions to enter circulation earlier than intended.
Core deployed the CoreRewardFix upgrade on September 3 at 13:00 UTC. The upgrade included an on-chain reconciliation to remove the accelerated rewards while accounting for balances received by validators that Core said were not involved in the exploit.
How the reward exploit happened
According to Core’s post-mortem, validator block rewards are distributed through a protocol-internal mechanism with privileged access.
A flaw in that mechanism allowed reward crediting to be repeated under a specific account configuration. This caused some block rewards to be processed more than once, releasing CORE that was scheduled to enter circulation later.
Some of the additional rewards were credited to validators that Core said had not caused the exploit. The project did not publish a step-by-step reproduction of the flaw, although the corrective changes were included in its client release.
186M CORE removed, 69M remains outside reconciliation
About 186.153 million CORE remained in addresses covered by the on-chain reconciliation. Those balances were reduced through network state changes and removed from circulation.
Another roughly 69 million CORE had already been transferred to external wallets before the upgrade. Because those tokens had moved outside the addresses covered by the reconciliation, they could not be removed through the same process.
Core said the 69 million CORE had been dispersed across multiple external addresses and that its foundation is working with law enforcement and other parties to pursue recovery.
Core says user funds were not affected
Core said the incident was limited to validator reward accounting.
According to the post-mortem, delegated stake and user balances were not affected, and the network did not lose user or staker funds as a result of the exploit.
The issue instead affected the timing of protocol rewards, bringing future emissions into circulation earlier than planned.
Network upgrade adds reward safeguards
The CoreRewardFix upgrade introduced changes aimed at preventing the reward-accounting issue from recurring.
One safeguard adds a per-block check to prevent a block’s reward from being credited more than once.
The upgrade also rejects blocks where the coinbase account contains an EIP-7702 delegation, which Core identified as part of the configuration involved in the exploit.
Another rule rejects unexpected zero-gas transactions, while Core said legitimate protocol-level system transactions remain unaffected.
The changes were deployed through client version v1.0.26.
Validator balances were handled separately
Core’s reconciliation distinguishes between attacker-controlled addresses and validator reward addresses.
The project said attacker-controlled reward pools were set to zero.
For affected validator reward addresses, Core calculated a “fair-earnings floor” based on each validator’s pre-incident balance plus three rounds of its normal reward.
Balances at or below that threshold were left unchanged, while amounts above the threshold were removed through the reconciliation.
Core said the method was intended to account for validators that received inflated rewards without initiating the exploit.
Core incident comes after other network exploits
The incident came as other blockchain networks also dealt with separate security incidents.
On September 1, Injective completed an accelerated network upgrade following an isolated application exploit. Injective said the incident did not compromise its consensus layer or user funds.
A separate incident at Cronos involved an exploit affecting the Tectonic protocol. Validators halted block production while the network responded to the attack before resuming operations following a rollback.
The incidents involved different technical failures and should not be treated as the same type of exploit. They nevertheless resulted in network-level responses after software or application issues were identified.
Upgrade completed without network downtime
Core said the upgrade activated at block 38,376,795 on September 3.
According to the project, the upgrade proceeded without network downtime and the reconciliation was applied across nodes.
Core said the resulting balance adjustments are visible through on-chain data. The foundation also said blockchain security firm Halborn reviewed the reward-accounting and distribution mechanisms. The team plans to simplify parts of its reward-accounting system and conduct additional reviews of the associated checks.
The network-level reconciliation has been completed, while recovery efforts for CORE transferred to external wallets before the upgrade remain ongoing.
Also Read: Router Protocol To Shut Down by September 30 as Cross-Chain Bridging Economics Turn Negative
