Here's what I'm thinking. This is just a theory.
When a pvp fight is won, the client sends a request code to the server. The server recieves this request code, runs a validation check, and sends a response code back to the client that is either OK or CVE.
The reason why we only get CVE sometimes and not all the time is because this validation check has a time-out function of probably just a few seconds. If the server is too busy to run the validation check, it will just send an OK code without actually verifying the client response, in order to lighten the CPU load/bandwith use. That might explain why sometimes we can win fights with hacks - the server was too taxed to process the request, and just sends an OK code without checking.
This validation check is something that can be turned on and off, in order for them to save bandwidth and CPU usage as needed, which could explain why it's only a relevant issue occasionally.
It would also somewhat confirm some of mine, and other's, findings on how the amount of CVE seems to change through the day. During some hours we get CVE constantly, while other hours of the day we can get multiple fights through without CVE.
But again, just a theory.