Exchange Pulls Token Listing After Reentrancy Exploit Drains $255,000 in Crypto
South Korean crypto exchange Upbit cancelled the scheduled debut of HEMI trading just 18 minutes before launch after identifying evidence that the token had been stolen through a smart contract exploit. The exchange had planned to list HEMI alongside Useless Coin, but withdrew HEMI support while continuing with other listings including Cluster Protocol.
According to Hemi's own post-mortem, an attacker exploited a reentrancy flaw in a modified contract used for its legacy Genesis Drop claims. The vulnerability allowed the attacker to set up a malicious claim configuration and repeatedly trigger the claim function before the contract's balance tracking updated, using a flash loan to repeat the process dozens of times in quick succession. This let the attacker extract roughly 124.5 million unclaimed tokens, which were then sold across several blockchains for about $255,000 in stablecoins before being converted into Ether.
Hemi says the breach was contained to the single claim contract involved, and that its main token, virtual machine, and bridging infrastructure were unaffected, though this is based on the project's own internal review. The incident highlights how reentrancy bugs, a well known but still common class of smart contract vulnerability, continue to be exploited even in newer or modified contract designs.