CASABLANCA, September 6, 2026
Core DAO says it removed 186.153 million CORE through an emergency network upgrade after a reward-accounting exploit released roughly 255 million tokens ahead of schedule, leaving about 69 million CORE outside the on-chain reconciliation as recovery work continues.
The issue ran from Aug. 28 through Aug. 31 and involved validator block rewards, according to the project’s Sept. 5 incident post-mortem. Core said future emissions entered circulation early, rather than new tokens being added above the network’s fixed 2.1 billion maximum supply.
CORE traded near $0.02144 at the Sept. 6 market check, down 2.1% over 24 hours and 9.3% over seven days, with a reported market capitalization of about $31.9 million and 24-hour volume of about $2.39 million, according to CoinGecko. Those moves do not establish that the remediation caused the price change.
Core deployed its CoreRewardFix upgrade at 13:00 UTC on Sept. 3. In its post-mortem, the project said the upgrade’s reconciliation “removed” 186.153 million CORE from balances still reachable by the network-level correction, while trying to preserve a fair-earnings floor for validators that received excess rewards without initiating the exploit.
The event is a distinct kind of supply incident from the Cosmos EVM flaw that drained assets across six chains. Core says no third-party user, staker, exchange or partner funds were affected, and it did not disclose a direct theft total, victim count, affected-wallet count, attacker identity or transaction-hash list.
Core
CORESource: CoinGecko Core market data, retrieved September 6, 2026. The Aug. 7 point is derived from the tracker’s 6.9% reported 30-day increase and its latest $0.02144 price; it is a high-level comparison, not an intraday price series.
CoreRewardFix removed 186.153 million CORE
Core said a flaw in the mechanism that credits validator block rewards allowed rewards to be processed more than once under a particular account configuration. The result was an acceleration of rewards scheduled to be distributed in the future.
The distinction is central to the reported 255 million CORE figure. The project says the exploit did not raise the maximum supply. It pulled rewards forward in time, which can still affect tradable supply and market expectations even if the ultimate cap remains unchanged.
The Sept. 3 reconciliation set attacker-controlled reward pools to zero, Core said. For other affected reward addresses, the network kept a calculated floor based on each validator’s pre-incident balance plus three normal reward rounds and removed balances above that level.
Core said the upgrade added a per-block guard intended to stop a reward from being credited twice. It also rejects blocks where the coinbase account contains an EIP-7702 delegation and unexpected zero-gas transactions, while leaving legitimate system transactions unaffected.
The response was forward-looking rather than a rollback. That separates it from the Cronos response to the Tectonic exploit, where the chain response involved a different protocol incident and network-level intervention.
About 69 million CORE remains outside reconciliation
About 69 million CORE had already been transferred to external wallets before the CoreRewardFix upgrade, the post-mortem said. The network could not remove those tokens with the same reconciliation because the balances no longer sat in the addresses covered by the remedy.
Core said the tokens were dispersed across multiple external addresses and that its foundation was working with law enforcement and other parties to pursue recovery. It did not identify the destination wallets, state how much had been sold or converted, publish a recovery deadline, or say whether any balances had been frozen.
That leaves a narrower but unresolved token-supply question after the 186.153 million CORE removal. The disclosed 69 million is not a new user-fund loss figure. It is the portion of prematurely released rewards that Core says sits beyond the upgrade’s direct reach.
Core’s public reward documentation says validators and their delegators receive block rewards and fees through its Satoshi Plus system, which includes Bitcoin, CORE and hash-power participation. The incident therefore reached a core issuance function rather than a consumer wallet product.
The protocol’s response resembles the risk-management rationale behind Polygon’s earlier client fixes, but the facts are materially different. Polygon reported no observed exploitation or fund loss, while Core has confirmed an accounting exploit and a completed balance reconciliation.
Core says user and staker balances were unaffected
Core says delegated stake and user balances were not affected and that the incident was confined to validator reward accounting. That statement means the project is not describing the 255 million CORE as a theft from ordinary wallet holders or stakers.
The project also said the upgrade was activated without network downtime at block 38,376,795. Earlier in the incident, exchange-network operations were a separate concern: Coinbase’s status page recorded a Core DAO network sends-and-receives incident, while its broader trading functions were not necessarily the same thing as on-chain transfers.
Core’s reported no-user-loss conclusion is the best available project evidence as of Sept. 6, but it is not an independently audited loss assessment. The protocol has not yet published a full technical reproduction, the complete address set, a final forensic report or the outcome of its recovery efforts.
The Crypto Fear and Greed Index stood at 73, or Greed, at the research check. The Bitcoin-focused gauge does not measure Core’s reward fix, the amount of unreconciled CORE or the likelihood of recovery.
Fear & Greed Index
September 6, 2026The next developments are whether Core identifies the external addresses, recovers any of the 69 million CORE, publishes fuller technical evidence and confirms whether exchange network restrictions have been lifted. Until then, the completed reconciliation resolves most of the disclosed premature issuance, but not all of it.
Stay up to date
Get the latest crypto insights delivered to your inbox
Primary sources and further reading
| Source | Title |
|---|---|
| | Core DAO incident post-mortem on X |
| | Core DAO consensus rewards documentation |
| | Coinbase Status: Core DAO network incident |
| | CoinGecko: Core market data |
| | Alternative.me: Crypto Fear and Greed Index |
Fact-checked by: Daily Crypto Briefs Fact-Check Desk
Related Articles
Frequently Asked Questions
How much CORE did the reward-accounting exploit release?
Core DAO says approximately 255 million CORE in future validator rewards entered circulation early between Aug. 28 and Aug. 31, 2026. The project says this accelerated scheduled issuance rather than increasing the token's 2.1 billion maximum supply.
How much CORE did Core DAO remove?
Core says its Sept. 3 CoreRewardFix reconciliation removed 186.153 million CORE from addresses still covered by the upgrade. About 69 million CORE had already moved to external wallets and was not removed through that on-chain action.
Were Core DAO users or stakers hacked?
Core says the issue was limited to validator reward accounting and did not affect delegated stake, user balances, exchange funds or partner funds. It did not disclose a direct theft amount, victim count or affected-wallet count.
What happens to the unreconciled CORE?
Core says the approximately 69 million CORE that moved outside the affected reward addresses remains subject to recovery efforts with law enforcement and other parties. The project did not publish the destination addresses, recovery timeline or a final outcome.



