Hemi Genesis Drop Suffers Reentrancy Exploit; 124.5M Tokens Stolen

AI Market Summary
Hemi disclosed a post-incident report detailing a reentrancy exploit in its MerkleBox contract during the Genesis Drop, enabling theft of ~124.5M unclaimed tokens. The attacker used a flash loan, liquidated tokens on Hemi DEXs into ~$255k stablecoins, then bridged funds via LayerZero to Ethereum/Arbitrum/BSC and largely converted to ETH. While the compromised contract is now drained and isolated, the event raises near-term confidence and liquidity risks.
Impact level
● Medium
Affected assets
HEMI/USDT-9.14%
AI Insight · HEMI/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Hemi has published a post-incident report on an exploit that targeted its Genesis Drop on Sept. 7. According to the report, an attacker exploited a vulnerability in Hemi's MerkleBox smart contract at 03:36:47 UTC, stealing about 124.5 million unclaimed tokens. Hemi said the issue was a reentrancy flaw: the contract created token locks before updating account balances, allowing the attacker to withdraw amounts well above the limits of their designated claim group. The attacker reportedly used a 2 million HEMI flash loan from the HEMI/USDT pool on SushiSwap, executing the exploit atomically and repaying the loan within the same transaction. The stolen tokens were then sold on DEXs within the Hemi network for roughly $255,000 in stablecoins. The proceeds were bridged via LayerZero to Ethereum, Arbitrum and BSC, with most later converted into ETH. Hemi said it received an alert from Hypernative at 05:42 UTC and identified the root cause in under an hour. The affected contract is immutable and now holds a zero balance, and the team stated that the rest of Hemi's infrastructure was not impacted. Investigations into the attacker's identity and recovery efforts are ongoing. (Source: Foresight News)