Core DAO is planning an emergency hard fork after a small group of validators found a way to extract more block rewards than its Satoshi Plus consensus mechanism was designed to issue.
The incident, disclosed on August 31, has already triggered precautionary measures from two major exchanges and raised fresh questions about the security of complex hybrid consensus designs in the layer 1 blockchain space.
Coinbase opened an incident at 04:41 UTC on August 31, pausing CORE sends and receives roughly 40 minutes before Core DAO issued its own public statement at 05:24 UTC. LBank suspended deposits around 05:00 UTC, citing project requirements. By 17:38 UTC, Coinbase status feed still listed the incident as under investigation. Trading of the token continued on both platforms, and Coinbase said buys, sells, conversions and fiat transactions were unaffected. The fact that Coinbase identified the problem before Core DAO disclosed it suggests the exchange caught the anomaly through its own on-chain monitoring systems, possibly before the project was even fully aware of the scope of the security vulnerability.
How the exploit worked
Core DAO runs a hybrid consensus mechanism called Satoshi Plus, which combines Bitcoin delegated proof-of-work with delegated proof-of-stake. The system uses a three-pillar scoring formula: Bitcoin miners delegate hash power to Core validators, Bitcoin holders lock BTC via timelock transactions to vote for validators, and CORE token holders participate through delegated proof-of-stake. Up to 90 percent of newly minted CORE tokens flow to selected validators based on this combined score.
A limited number of validators identified a flaw in the reward distribution mechanism. They exploited the scoring system to claim tokens beyond the protocol intended issuance schedule. Core DAO initially described the actors as a small group whose behavior appeared accidental, then reclassified it as explicitly malicious after further on-chain investigation. The shift in language suggests the project found evidence of deliberate manipulation rather than a simple bug exploitation.
The project said user assets, network security, and custody systems remain unaffected. It did not disclose the amount of excess CORE minted, the specific validators involved, the reward rounds affected, or the technical root cause. Core DAO promised a full postmortem once the issue is contained. The absence of concrete details has frustrated observers, who argue that transparency is critical when token supply itself is in question.
Supply uncertainty spooks exchanges
CORE has a hard cap of 2.1 billion tokens. Roughly 40 percent of that total, about 840 million tokens, is allocated to node mining rewards distributed over an 81-year emission schedule. If validators extracted a meaningful number of tokens beyond protocol limits, that carefully designed supply curve comes into question.
The exact volume of excess tokens remains unclear. Until Core DAO publishes a full accounting of how many extra tokens entered circulation, traders have no reliable picture of the token actual supply dynamics. The core concern, as CryptoSlate noted, is whether the anomaly accelerated rewards already scheduled for later distribution or added issuance entirely outside the project planned path. The difference matters: accelerated rewards would simply pull forward existing supply, while unauthorized issuance would represent genuine inflation above the hard cap.
The speed of the exchange reaction, combined with Core initial reluctance to call the behavior malicious, has raised questions about how long the exploit may have been running before it was caught. On-chain data analysts have begun examining validator reward patterns, but no independent accounting has been published yet. The incident comes at a sensitive time for the project, which has been promoting its Bitcoin staking features as a way to attract institutional capital and expand its ecosystem beyond its existing retail user base.
Forward-only fix, no rollback
Core DAO is coordinating the emergency hard fork directly with its validator set. The upgrade is forward-only: no transactions will be reversed, no blocks will be rolled back, and the network existing state stays intact. The fix patches only the reward distribution vulnerability to prevent future exploitation.
The approach mirrors similar emergency responses in other proof-of-stake networks, where rollback proposals have proven divisive. By avoiding a chain reorganization, Core DAO reduces the risk of splitting its validator community. But the decision leaves the question of excess tokens already in circulation unresolved, and there is no indication yet how the project plans to address tokens that should not exist under the original emission schedule.
The complexity of Satoshi Plus is itself part of the problem. The three-pillar scoring system, which blends Bitcoin mining power, timelocked BTC, and CORE staking into a single validator ranking, creates a larger attack surface than simpler consensus designs. Each pillar adds variables that must interact correctly, and the exploit exposed how a gap in one component can cascade through the whole system. Other networks using hybrid consensus, including those that blend proof-of-work with proof-of-stake, face similar structural risks when reward mechanisms grow more complex and interconnected across multiple staking layers.
For CORE holders, the immediate risk is not a price crash but an information vacuum. Without knowing how many excess tokens exist, the market cannot accurately price the supply shock. The postmortem, when it arrives, will determine whether this is a minor accounting issue or a fundamental credibility problem for the network. Either way, the incident highlights a recurring tension in complex consensus design: more sophisticated reward mechanisms create more surface area for exploiters, and the cost of that complexity often becomes visible only after something goes wrong.

discussion