Hemi Releases Post‑mortem On Genesis Drop Exploit That Drained 124.5 Million Tokens

Hemi Releases Post‑mortem On Genesis Drop Exploit That Drained 124.5 Million Tokens
Table of Contents

A hacker exploited the MerkleBox smart contract from Hemi‘s Genesis Drop on September 7, 2026 at 03:36:47 UTC, draining approximately 124.5 million tokens that remained unclaimed.

The exploit relied on a reentrancy vulnerability: the contract processed the creation of token locks before updating the accounted balances, which allowed the attacker to withdraw funds well above what was configured for their claims group.

The attacker funded the attack with a flash loan of 2 million tokens from Sushiswap‘s HEMI/USDT pool, executed the exploit atomically through an orchestrator contract and repaid the loan within the same transaction.

The stolen tokens were immediately liquidated on DEXes within the Hemi network itself, generating approximately $255,000 in stablecoins. Those funds were then bridged to Ethereum, Arbitrum, BSC and other networks via LayerZero, and converted mostly to ETH.

The team received the alert from Hypernative around 05:42 UTC and identified the root cause less than an hour later. The affected contract is immutable, its balance is currently zero and poses no additional risk. The rest of Hemi’s infrastructure was not affected. The investigation into the attacker’s identity and the recovery of funds remains open.

Source: https://hemi.xyz./blog/genesis-drop-exploit-september-7-2026-post-mortem


Disclaimer: Crypto Economy Flash News are based on verified public and official sources. Their purpose is to provide fast, factual updates about relevant events in the crypto and blockchain ecosystem.

This information does not constitute financial advice or investment recommendation. Readers are encouraged to verify all details through official project channels before making any related decisions.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews