Hemi Releases Post‑mortem On Genesis Drop Exploit That Drained 124.5 Million Tokens

NewsTue, 08 Sep 2026 20:45:04 UTC2 hours ago

A hacker exploited the MerkleBox smart contract from Hemi‘s Genesis Drop on September 7, 2026 at 03:36:47 UTC, draining approximately 124.5 million tokens that remained unclaimed.

The exploit relied on a reentrancy vulnerability: the contract processed the creation of token locks before updating the accounted balances, which allowed the attacker to withdraw funds well above what was configured for their claims group.

The attacker funded the attack with a flash loan of 2 million tokens from Sushiswap‘s HEMI/USDT pool, executed the exploit atomically through an orchestrator contract and repaid the loan within the same transaction.

The stolen tokens were immediately liquidated on DEXes within the Hemi network itself, generating approximately $255,000 in stablecoins. Those funds were then bridged to Ethereum, Arbitrum, BSC and other networks via LayerZero, and converted mostly to ETH.

The team received the alert from Hypernative around 05:42 UTC and identified the root cause less than an hour later. The affected contract is immutable, its balance is currently zero and poses no additional risk. The rest of Hemi’s infrastructure was not affected. The investigation into the attacker’s identity and the recovery of funds remains open.

… Continue reading the full article at the original source below.

Read from Source · crypto-economy.com ↗
This content is automatically aggregated. Full credit goes to the original publisher (crypto-economy.com).

Related