Hemi Genesis Drop Contract Exploited for 124.5 Million Tokens in Reentrancy Attack
AI مارکیٹ کا خلاصہ
Hemi disclosed a post-incident report detailing a reentrancy exploit in its MerkleBox contract during the Genesis Drop, enabling theft of ~124.5M unclaimed tokens. The attacker used a flash loan, liquidated tokens on Hemi DEXs into ~$255k stablecoins, then bridged funds via LayerZero to Ethereum/Arbitrum/BSC and largely converted to ETH. While the compromised contract is now drained and isolated, the event raises near-term confidence and liquidity risks.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
HEMI/USDT-10.23%
AI تجزیاتی سمجھ · HEMI/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Modular blockchain protocol Hemi suffered a smart contract reentrancy exploit during its Genesis Drop on Sept. 7, resulting in the unauthorized drain of 124.5 million unclaimed HEMI tokens, according to a post-incident report cited by Foresight News. The attacker breached the immutable MerkleBox contract at 03:36:47 UTC after securing a 2 million HEMI flash loan from SushiSwap, exploiting a state update flaw where token locks were executed prior to balance deductions. The stolen supply was liquidated across native decentralized exchanges for approximately $255,000 in stablecoins before being cross-chain bridged via LayerZero to Ethereum, Arbitrum, and BNB Chain, where proceeds were largely swapped into Ether. Security intelligence firm Hypernative alerted the protocol team at 05:42 UTC, with Hemi confirming that broader network infrastructure remains secure as forensic tracing continues.