Industry News

Reentrancy Bug in Hemi's Genesis Drop Lets Attacker Drain 124.5 Million Tokens

Crypto Economy · 9 Sept 2026
Key Takeaway Businesses building or relying on smart contracts should ensure balance updates happen before external calls and commission independent audits and real-time monitoring to catch reentrancy flaws before they can be exploited.

Hemi has published a post-mortem detailing how an attacker exploited its MerkleBox smart contract on 7 September 2026, draining around 124.5 million unclaimed tokens from its Genesis Drop. The root cause was a reentrancy vulnerability: the contract created token locks before updating account balances, letting the attacker withdraw far more than they were entitled to.

The attacker used a flash loan of 2 million tokens from a Sushiswap liquidity pool to fund the exploit, executing it atomically through an orchestrator contract and repaying the loan in the same transaction. The stolen tokens were quickly sold on decentralised exchanges for about $255,000 in stablecoins, then bridged across multiple blockchains and converted mostly into ETH, making tracing harder.

Hemi says it was alerted by monitoring firm Hypernative around 05:42 UTC and identified the root cause within an hour. The affected contract is immutable, now has a zero balance and poses no further risk, and the rest of Hemi's infrastructure was unaffected. Investigation into the attacker's identity and fund recovery is ongoing.

smart contract exploit reentrancy vulnerability cryptocurrency security blockchain DeFi

Summarised by CISO AI from Crypto Economy. We link back to every original so you can read it yourself.