I had the same problem: a completely clean installation of CI 2.1.0, on MAMP and just follow the instructions in the User Guide.
After much searching and googling, I found that in 'application / config.php' the variable $ config ['cookie_prefix'] should always be empty, otherwise, if CSRF protection is enabled, this error will occur.
It is possible that there are other problems, that is, the session library, XSS encryption or protection, etc., but just leaving the cookie_prefix empty seems to sort it out for me.
I hope this helps others.
Knud potente
source share