
Core DAO hardfork fixes a validator reward vulnerability and burns over 150M CORE, with no transactions rolled back or user funds lost.
Author: Kritika Gupta
3rd September 2026- Core DAO has activated the v1.0.26 hardfork on mainnet, closing a reward issuance vulnerability that allowed a group of validators to claim excess CORE. The upgrade burned more than 150 million CORE of excess issuance. Core said it preserved transactions and protected user funds. Meanwhile, staking rewards should normalize within 48 hours, although a technical post-mortem remains pending.
High Signal Summary For A Quick Glance
Gidas | ⬢ CoreDAO🟠
@Gidasmike
@Coredao_Org This is a solid resolution from the Core team. 🔥 No rollback, no user funds lost, the vulnerability is closed, and 150M+ excess $CORE has been permanently burned. Now we wait for staking rewards to normalize and the full post-mortem. Transparency + execution is what matters. 👏 https://t.co/LzaarLaKNL

The v1.0.26 hardfork is now live on Core mainnet and the reward issuance issue is resolved. The upgrade closed the vulnerability and burned 150M+ CORE of excess issuance, removing it from supply permanently. No transactions were rolled back and no user funds were lost. We https://t.co/Gi7hGWa7Nz
04:13 PM·Sep 3, 2026
I'm so PED
@AmsonPed
@Coredao_Org What other vulnerabilities would probing minds exploit next? And how many of these vulnerabilities are there really? Well... You don't even have the answers yourselves seeing how you were apparently caught unawares on this one. Keep building! (castles in the air)
The v1.0.26 hardfork is now live on Core mainnet and the reward issuance issue is resolved. The upgrade closed the vulnerability and burned 150M+ CORE of excess issuance, removing it from supply permanently. No transactions were rolled back and no user funds were lost. We https://t.co/Gi7hGWa7Nz
02:57 PM·Sep 3, 2026
Terrarmy 🐋
@terra_army
@Coredao_Org A hardfork that fixes the issuance issue, permanently removes 150M+ excess CORE, and protects user funds , without rolling back transactions is a strong response. Transparency + fast action = how trust is built.
The v1.0.26 hardfork is now live on Core mainnet and the reward issuance issue is resolved. The upgrade closed the vulnerability and burned 150M+ CORE of excess issuance, removing it from supply permanently. No transactions were rolled back and no user funds were lost. We https://t.co/Gi7hGWa7Nz
02:55 PM·Sep 3, 2026
Steady attention without excessive speculation.
Core operators identified validator rewards in late August 2026. Certain validators were receiving block rewards above the issuance schedule under Core’s Satoshi Plus consensus. However, Core said the flaw affected reward distribution only, not network security or asset custody.
Core disclosed the issue on August 31 and confirmed containment on September 1. Consequently, affected validators could no longer claim excess rewards. The team then coordinated a forward-only emergency hardfork instead of rolling back the chain. Core released v1.0.26 on September 2 and activated it at 13:00 UTC on September 3.
Core confirmed that the upgrade had closed the flaw and burned 150M+ excess CORE. At prices near $0.020 to $0.021, the burn represented roughly $3 million to $3.15 million. Importantly, Core has not published a burn transaction hash, affected validator addresses or synchronized supply snapshots. Therefore, the official announcement remains the primary evidence for the burn claim.
Several exchanges, including Coinbase, Bithumb, Coinone, Bitget and LBank, temporarily restricted CORE transfers during the investigation. Still, the network continued processing transactions without a rollback. The response reduced operational risk, but the missing technical details leave questions about when exploitation began and whether validators sold any excess tokens.
Core expects validator and delegator rewards to return to normal parameters within 48 hours. Because v1.0.26 changed consensus-level reward logic, validators must run the updated software to remain aligned with the network.
The hardfork preserved historical blocks and account balances. As a result, users avoided the disruption and legal uncertainty that a rollback could create. Nevertheless, Core must explain how the vulnerability bypassed reward limits and what monitoring failed to detect it earlier.
CORE supply before and after the 150M+ token burn
CORE has a maximum supply of 2.1 billion tokens and follows an emission schedule lasting roughly 81 years, with annual reward reductions near 3.61%. Burning the excess issuance prevents those tokens from creating permanent additional inflation.
The 150M+ burn equals at least 7.14% of CORE’s stated maximum supply. However, this does not mean the maximum cap declined. Instead, Core removed tokens that the protocol had issued outside its intended schedule. Exact pre-burn and post-burn supply figures remain unverified.
Core DAO reward vulnerability and recovery timeline
A flaw allows certain validators to receive rewards above Core’s intended issuance schedule. Its introduction date remains unknown.
Core confirms that the root cause was identified, mitigations were underway and user assets remained safe.
Malicious validators accumulate excess rewards, although the exact issuance period and associated addresses remain undisclosed.
Core confirms that validators can no longer claim excess rewards and begins coordinating an emergency forward hardfork.
The upgrade is published on GitHub with mainnet activation scheduled for September 3 at 13:00 UTC.
The v1.0.26 upgrade closes the reward-issuance vulnerability without rolling back previous transactions.
Core states that the excess issuance was permanently removed from supply, but no burn transaction hash was published.
Core is expected to disclose the root cause, affected validators, issuance records, burn evidence and audit findings.
Core has promised a technical post-mortem covering the root cause, containment timeline, burn amount and added safeguards. For investors and validators, that report now matters more than the headline burn. It should include transaction evidence, affected addresses, exploit duration and independent audit findings.
Until then, the hardfork resolves the immediate vulnerability, but transparency will determine whether Core fully restores confidence in its issuance controls and validator oversight.
Our Crypto Talk is committed to unbiased, transparent, and true reporting to the best of our knowledge. This news article aims to provide accurate information in a timely manner. However, we advise the readers to verify facts independently and consult a professional before making any decisions based on the content since our sources could be wrong too. Check our Terms and conditions for more info.