On September 5, Core DAO published its post-mortem on the reward-accounting exploit that ran from August 28 to 31. Roughly 255M CORE of rewards were issued ahead of schedule.
The cap held. In Core's words, the exploit "did not create any CORE beyond the protocol's limits; the 2.1B maximum supply was never violated." What it did was accelerate rewards the emission schedule would otherwise have released later. What broke was when.
That makes the damage an unusual shape. No user or staking account was drained — Core states that no user or staker funds were lost and that delegated stake was never at risk. What existed instead was surplus, sitting in balances, and it arrived through the ordinary path: the extra rewards "appeared both in attacker-controlled addresses and, unintentionally, in the reward addresses of honest validators who simply received an inflated payout they did not cause."
That made the on-chain reconciliation an arithmetic problem before it was a balance-editing problem. Before any affected balance could be corrected, Core needed a rule for what that balance should have been at the upgrade block.
It used two. Attacker-controlled reward pools were set to zero. For affected honest validators, it defined a fair-earnings floor — the pre-incident balance plus three rounds of that validator's own normal reward — left balances at or below it untouched, and removed only the excess above. Together the reconciliation took 186,153,491 CORE out of supply by direct state reduction. A further ~69M had been moved before the upgrade and sits outside what an on-chain reconciliation can reach; Core says it is pursuing that with law enforcement.
Core says the reconciliation can be checked independently against chain state at the upgrade block, and that the reward paths were subsequently reviewed by Halborn. That part matters as much as the fix. A correction that affected users and independent observers cannot verify is only a second assertion about the balances.
A supply cap is a promise about how much will ever exist. It says nothing about how much should exist yet. Restoring the second one requires knowing a number the cap never had to track.
Sources:
https://t.co/TMhZdwRHaQ
#DeepSafe #CRVA #Web3Security
A supply cap only answers “how much can ever exist.”
It never answers “how much should exist today.”Core didn’t mint past 2.1B.
It released 255M too early.That is a different bug, and a harder cleanup.
On September 5, Core DAO published its post-mortem on the reward-accounting exploit that ran from August 28 to 31. Roughly 255M CORE of rewards were issued ahead of schedule.
The cap held. In Core's words, the exploit "did not create any CORE beyond the protocol's limits; the 2.1B maximum supply was never violated." What it did was accelerate rewards the emission schedule would otherwise have released later. What broke was when.
That makes the damage an unusual shape. No user or staking account was drained — Core states that no user or staker funds were lost and that delegated stake was never at risk. What existed instead was surplus, sitting in balances, and it arrived through the ordinary path: the extra rewards "appeared both in attacker-controlled addresses and, unintentionally, in the reward addresses of honest validators who simply received an inflated payout they did not cause."
That made the on-chain reconciliation an arithmetic problem before it was a balance-editing problem. Before any affected balance could be corrected, Core needed a rule for what that balance should have been at the upgrade block.
It used two. Attacker-controlled reward pools were set to zero. For affected honest validators, it defined a fair-earnings floor — the pre-incident balance plus three rounds of that validator's own normal reward — left balances at or below it untouched, and removed only the excess above. Together the reconciliation took 186,153,491 CORE out of supply by direct state reduction. A further ~69M had been moved before the upgrade and sits outside what an on-chain reconciliation can reach; Core says it is pursuing that with law enforcement.
Core says the reconciliation can be checked independently against chain state at the upgrade block, and that the reward paths were subsequently reviewed by Halborn. That part matters as much as the fix. A correction that affected users and independent observers cannot verify is only a second assertion about the balances.
A supply cap is a promise about how much will ever exist. It says nothing about how much should exist yet. Restoring the second one requires knowing a number the cap never had to track.
Sources:
https://t.co/TMhZdwRHaQ
#DeepSafe #CRVA #Web3Security
Fixed validator sets give attackers time to prepare. @DeepSafe_AI draws a new verifier group for each request, so the check is not sitting in the same hands every time. A public registry can store the result. It still cannot invent independence. #DeepSafe
Verification that always uses the same checker is just a delayed single point of failure. @DeepSafe_AI
randomizes who verifies each request, so trust is not parked with a fixed set. On-chain records still need a real check behind them. #DeepSafe
On-chain does not mean verified. It means written. Who got asked, and whether that set was fixed long enough to game, is the actual question. That is the layer @DeepSafe_AI
is building.
#DeepSafe
A rollback can erase the attacker on Cronos. It cannot touch the ETH that already left, and it does not spare ordinary txs in that window.The fix sorted by what validators could rewind, not by who was guilty.That’s the point: refuse one bad request, don’t rewrite everyone else’s confirmation.
@DeepSafe_AI The cap held, but the schedule did not. Core rebuilt a fair balance after rewards already landed. That gap is the point: check the request before it becomes state.
Cronos halted on Sunday after an exploit on Tectonic. On Monday it said block production had resumed and that the chain state had been restored to before the exploit. It called that a validator-consensus emergency action. Tectonic said it would reopen in phases once its own checks clear, beginning with withdrawals and repayments while deposits and borrowing stay paused. Neither team has confirmed a loss figure, and both say a full post-mortem is coming.
Cronos resumed from block 90,896,189. The Defiant puts that 10,961 blocks behind the branch users had already watched confirm, roughly one hour and 54 minutes of chain history. On the new canonical chain, the attacker's Cronos-side gains no longer exist. The portion that had already crossed to Ethereum does. PeckShield and Lookonchain both tracked about 2,592 ETH, worth roughly $6.29M at the time, that reached Ethereum before block production stopped.
One exploit, three outcomes. What reached Ethereum stayed beyond the rollback's reach. The attacker's Cronos-side gains were removed from the canonical state. And so were the trades, transfers and liquidations of people with no connection to the exploit — confirmations they had already watched land inside that window.
The rollback did not separate exploit transactions from ordinary ones. It separated only what Cronos validators could rewind from what they could not. As of September 1, neither team has published an accounting of how those unrelated transactions will be handled, or whether any of them can be replayed.
This is not an argument that the rollback was right or wrong, and it is not a claim about decentralisation. The narrower point is what this remedy requires and how far it reaches. It requires validator consensus. It reaches only the chain those validators run. And it invalidates every prior confirmation inside the history it replaces, no matter whose transaction it was.
CRVA does not remove the need for emergency controls, and it would not have prevented the flaw inside Tectonic. The narrower distinction is the unit of refusal. Where an applicable check already sits in the execution path and its result is enforced, one request can be refused without an ad hoc validator intervention that replaces unrelated chain history.
The chain is back. The exploit's Cronos transactions are out of the canonical state. What is still open is everything the rollback could not reach, and everything else it reached on the way.
Sources:
https://t.co/fgxVSZif8s
#DeepSafe #CRVA #Web3Security
MINT ANNOUNCEMENT
Thursday, September 3 · 6 PM UTC
Supply: 3333
Phases: GTD + WL only
Mint price: FREE
Final quest: grab your unique PFP and get ready to mint on zcash:native - full details on the site:
🔒 https://t.co/oO3ulRAREo
Complete before access closes.
RunePool brings liquidity, execution, and settlement into one unified layer for AI Agents. ⚡️
From strategy generation to real, continuous on-chain yield.
Developers start BUILDING ⚙️
Participants start EARNING 💰
https://t.co/Q2VTKM3ZQP
Powering the Agent Economy.
📢 Funding Announcement
RunePool has completed a $1M Series A round backed by @BlockX_VC, @TitanFdnUSA, and notable Web3 investors.
Together, we're building the infrastructure powering the next generation of autonomous economies.