ME News reports that on September 9 (UTC+8), Hemi released a post-incident analysis report regarding the vulnerability exploit on the Genesis Drop on September 7. The report reveals that at 03:36:47 UTC on September 7, the attacker exploited a vulnerability in Hemi’s MerkleBox smart contract during the Genesis Drop, stealing approximately 124.5 million unclaimed tokens. The vulnerability stemmed from a reentrancy attack: the contract processed the creation of token locks before updating account balances, enabling the attacker to withdraw funds far exceeding their allocated claim group limits. The attacker initiated the attack using a flash loan of 2 million HEMI tokens from the HEMI/USDT pool on SushiSwap, orchestrating the exploit to execute atomically and repay the loan within the same transaction. The stolen tokens were immediately liquidated on decentralized exchanges (DEXs) within the Hemi network, generating approximately $255,000 in stablecoins. These funds were subsequently bridged via LayerZero to networks such as Ethereum, Arbitrum, and BSC, with most converted into ETH. The Hemi team received an alert from Hypernative at 05:42 UTC and identified the root cause within under an hour. The compromised contract is immutable and currently has a zero balance, posing no further risk. Hemi’s remaining infrastructure was unaffected. Investigations into the attacker’s identity and efforts to recover the stolen funds are ongoing. (Source: Foresight News)
Hemi Genesis Drop Hit by Reentrancy Attack, 124.5M Tokens Stolen
KuCoinFlashShare
On September 9, Hemi confirmed that its Genesis Drop was compromised by a reentrancy attack on September 7, resulting in the theft of 124.5 million HEMI tokens. Attackers exploited a vulnerability in the MerkleBox smart contract by creating token locks before updating balances, enabling excessive withdrawals. A 2 million HEMI flash loan from SushiSwap was used and repaid within the same transaction. The stolen tokens were swiftly liquidated on Hemi’s DEX for $255,000 in stablecoins and bridged via LayerZero to Ethereum, Arbitrum, and BSC, where they were largely converted to ETH. The smart contract is now depleted and immutable. The team is actively investigating potential recovery options, including tracking wrapped tokens derived from the stolen assets.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.