When I get rewards I tend to look at the amount first and then decide what makes sense for my setup. I think it's better to be consistent rather than keep changing my strategy. @basis_pro
On September 5, Core DAO published its post-mortem on the reward-accounting exploit that ran from August 28 to 31. Roughly 255M CORE of rewards were issued ahead of schedule.
The cap held. In Core's words, the exploit "did not create any CORE beyond the protocol's limits; the 2.1B maximum supply was never violated." What it did was accelerate rewards the emission schedule would otherwise have released later. What broke was when.
That makes the damage an unusual shape. No user or staking account was drained — Core states that no user or staker funds were lost and that delegated stake was never at risk. What existed instead was surplus, sitting in balances, and it arrived through the ordinary path: the extra rewards "appeared both in attacker-controlled addresses and, unintentionally, in the reward addresses of honest validators who simply received an inflated payout they did not cause."
That made the on-chain reconciliation an arithmetic problem before it was a balance-editing problem. Before any affected balance could be corrected, Core needed a rule for what that balance should have been at the upgrade block.
It used two. Attacker-controlled reward pools were set to zero. For affected honest validators, it defined a fair-earnings floor — the pre-incident balance plus three rounds of that validator's own normal reward — left balances at or below it untouched, and removed only the excess above. Together the reconciliation took 186,153,491 CORE out of supply by direct state reduction. A further ~69M had been moved before the upgrade and sits outside what an on-chain reconciliation can reach; Core says it is pursuing that with law enforcement.
Core says the reconciliation can be checked independently against chain state at the upgrade block, and that the reward paths were subsequently reviewed by Halborn. That part matters as much as the fix. A correction that affected users and independent observers cannot verify is only a second assertion about the balances.
A supply cap is a promise about how much will ever exist. It says nothing about how much should exist yet. Restoring the second one requires knowing a number the cap never had to track.
Sources:
https://t.co/TMhZdwRHaQ
#DeepSafe #CRVA #Web3Security
Cronos halted on Sunday after an exploit on Tectonic. On Monday it said block production had resumed and that the chain state had been restored to before the exploit. It called that a validator-consensus emergency action. Tectonic said it would reopen in phases once its own checks clear, beginning with withdrawals and repayments while deposits and borrowing stay paused. Neither team has confirmed a loss figure, and both say a full post-mortem is coming.
Cronos resumed from block 90,896,189. The Defiant puts that 10,961 blocks behind the branch users had already watched confirm, roughly one hour and 54 minutes of chain history. On the new canonical chain, the attacker's Cronos-side gains no longer exist. The portion that had already crossed to Ethereum does. PeckShield and Lookonchain both tracked about 2,592 ETH, worth roughly $6.29M at the time, that reached Ethereum before block production stopped.
One exploit, three outcomes. What reached Ethereum stayed beyond the rollback's reach. The attacker's Cronos-side gains were removed from the canonical state. And so were the trades, transfers and liquidations of people with no connection to the exploit — confirmations they had already watched land inside that window.
The rollback did not separate exploit transactions from ordinary ones. It separated only what Cronos validators could rewind from what they could not. As of September 1, neither team has published an accounting of how those unrelated transactions will be handled, or whether any of them can be replayed.
This is not an argument that the rollback was right or wrong, and it is not a claim about decentralisation. The narrower point is what this remedy requires and how far it reaches. It requires validator consensus. It reaches only the chain those validators run. And it invalidates every prior confirmation inside the history it replaces, no matter whose transaction it was.
CRVA does not remove the need for emergency controls, and it would not have prevented the flaw inside Tectonic. The narrower distinction is the unit of refusal. Where an applicable check already sits in the execution path and its result is enforced, one request can be refused without an ad hoc validator intervention that replaces unrelated chain history.
The chain is back. The exploit's Cronos transactions are out of the canonical state. What is still open is everything the rollback could not reach, and everything else it reached on the way.
Sources:
https://t.co/fgxVSZif8s
#DeepSafe #CRVA #Web3Security
I like that Auto Earn removes one small task from my plate. This can all happen automatically without me having to keep up with it, rather than checking the rewards and restaking manually every week. @basis__pro
September was supposed to break Bitcoin. Instead, US spot ETFs pulled in $3.8B over three weeks, the strongest streak of 2026. But the year is still $1B under water. What the flow ledger actually says: https://t.co/8LoL7qaC9A
@basis__pro Nice QoL win: rewards auto-restake every Monday with zero lock or booster reset. Default-on, easy to adjust, plus a security buffer. Pure hands-off compounding.
Auto Earn is live. Unclaimed staking rewards now restake automatically every Monday at 00:00 UTC, with no term reset and no change to maturity or booster. On by default, adjustable in account settings. https://t.co/wgeTjK7bbk
I first attempted the withdrawal process with a smaller amount. That helped me understand how the unstake and withdrawal steps worked before I considered moving a larger position. @basis_pro
🤝 BASIS × @XDCNetwork
Two infrastructures. One vision for the future of on-chain finance. 🚀
We’re excited to announce our partnership with XDC Network, an EVM-compatible Layer-1 powering payments, trade finance, and real-world asset solutions.
By bringing together BASIS’s institutional-grade crypto arbitrage and staking platform with XDC Network’s high-throughput blockchain infrastructure, we’re opening the door to new opportunities across crypto yield, real-world assets, and digital finance.
As the on-chain economy continues to evolve, we’re exploring what’s possible when efficient yield meets real-world financial infrastructure.
🔥 The journey starts here. More to come.
I initially looked at stBTC but in the end I went with stETH because it fit my existing holdings better. I like to keep my BASIS allocation in line with assets I already understand. @basis_pro
I don’t redeem rewards every time I open BASIS. I usually wait until I have a decent amount then claim it and decide if I want to re-stake it or keep it liquid. @basis__pro
I made a smaller deposit initially as I wanted to see how all this worked in practice. Once I got used to the platform, I felt more comfortable about taking a larger position. @basis__pro#BASIS
The weekly DRR movement doesn’t really affect what I do with my stake. I see it but I don't want to react to every little thing. I prefer to keep the setup simple and let it run. @basis__pro
For boosters, I prefer keeping things simple. I check the rate occasionally, but I’m not opening BASIS every day just to see if the number moved. If the setup still makes sense, I let it run. @basis__pro