# "post-mortem" (exploit OR hack) — X 热门讨论 (2026-09-19 21:33 UTC)
## @Ntisolomon_1 (Young Crypto) · 09-06 07:44 · ♥57 ↻14 💬4 🚨 CORE DAO POST-MORTEM: THE FACTS MATTER.
The full post-mortem on the recent reward-accounting exploit is out.
Here’s what every $CORE holder should understand 👇
✅ 255M CORE in rewards were accelerated from future emissions. ✅ The 2.1B maximum supply was NEVER violated. ✅ 186.15M CORE was permanently removed from supply. ✅ 69M CORE was moved by attackers before the upgrade; recovery efforts are ongoing. ✅ NO user or staker funds were lost. ✅ Legitimate validator earnings were preserved. ✅ The vulnerability was permanently closed through CoreRewardFix. ✅ Staking rewards are back online. ✅The network upgraded without downtime.
Most importantly, this wasn’t about creating unlimited CORE out of thin air. It was a reward-accounting flaw that pulled scheduled future emissions forward.
The response matters: identify → contain → fix → reconcile → harden.
Now the network is running with additional safeguards, and the entire reconciliation is publicly verifiable on-chain.
FUD can spread fast.
Facts move slower, but they matter more. https://x.com/Ntisolomon_1/status/2096504740339188146
## @MasoudUmar (Mas'oud 🔸) · 09-06 07:56 · ♥53 ↻11 💬4 What stands out to me about @Coredao_Org Post mortem is not only the exploit, but how the network responded afterward.
The vulnerability was identified and contained, a coordinated upgrade went live without network downtime, the excess issuance was reconciled on-chain, and legitimate
validator earnings were protected. Incidents can happen in complex protocols. What matters is how quickly and transparently they are contained, fixed, and verified. $CORE If it's not $Core then what's? 🥰🙏 https://x.com/MasoudUmar/status/2096507775882875318
## @Gidasmike (Gidas | ⬢ CoreDAO🟠) · 09-02 13:43 · ♥41 ↻9 💬0 Stay calm, Coretoshi 🟦
This is a temporary suspension of staking rewards while @Coredao_Org works on the permanent fix following the validator reward issue.
The important part: user funds remain safe, the exploit has been contained, and malicious validators can no longer collect excess rewards.
0% APY for now is not the end of staking—it’s a precaution while the network prepares the upgrade.
Let the team cook. 🫡 We’ll wait for emissions to resume and the full post-mortem.
@Coredao_Org @b14g_network > 引用 @BSCNews: Core DAO's biggest DeFi platform release update on staking
@Coredao_Org suspended staking reward emissions yesterday after a recent malicious validator attack.
This suspension applies to all Core staking, including b14g, dualCORE, stCORE, and direct validator staking.
In the meantime, users may experience 0% APY with no additional rewards.
According to @b14g_network, users' funds are 100% secure. b14g users need not take any action in regard to their b14g funds.
The problem has been resolved, and malicious validators can no longer collect extra rewards.
b14g will keep users updated on any further developments until emissions start again. https://x.com/Gidasmike/status/2095145548495888426