Industry News

Exchange Pulls Token Listing After Reentrancy Exploit Drains $255,000 in Crypto

Crypto news · 9 Sept 2026
Key Takeaway Businesses holding or transacting in crypto assets should treat exchange delistings or trading halts as an early warning sign and avoid interacting with affected tokens or contracts until an official post-mortem confirms the scope of any exploit.

South Korean crypto exchange Upbit cancelled the scheduled debut of HEMI trading just 18 minutes before launch after identifying evidence that the token had been stolen through a smart contract exploit. The exchange had planned to list HEMI alongside Useless Coin, but withdrew HEMI support while continuing with other listings including Cluster Protocol.

According to Hemi's own post-mortem, an attacker exploited a reentrancy flaw in a modified contract used for its legacy Genesis Drop claims. The vulnerability allowed the attacker to set up a malicious claim configuration and repeatedly trigger the claim function before the contract's balance tracking updated, using a flash loan to repeat the process dozens of times in quick succession. This let the attacker extract roughly 124.5 million unclaimed tokens, which were then sold across several blockchains for about $255,000 in stablecoins before being converted into Ether.

Hemi says the breach was contained to the single claim contract involved, and that its main token, virtual machine, and bridging infrastructure were unaffected, though this is based on the project's own internal review. The incident highlights how reentrancy bugs, a well known but still common class of smart contract vulnerability, continue to be exploited even in newer or modified contract designs.

cryptocurrency smart contract exploit reentrancy vulnerability

Summarised by CISO AI from Crypto news. We link back to every original so you can read it yourself.