Reentrancy Bug in Hemi's Genesis Drop Lets Attacker Drain 124.5 Million Tokens
Hemi has published a post-mortem detailing how an attacker exploited its MerkleBox smart contract on 7 September 2026, draining around 124.5 million unclaimed tokens from its Genesis Drop. The root cause was a reentrancy vulnerability: the contract created token locks before updating account balances, letting the attacker withdraw far more than they were entitled to.
The attacker used a flash loan of 2 million tokens from a Sushiswap liquidity pool to fund the exploit, executing it atomically through an orchestrator contract and repaying the loan in the same transaction. The stolen tokens were quickly sold on decentralised exchanges for about $255,000 in stablecoins, then bridged across multiple blockchains and converted mostly into ETH, making tracing harder.
Hemi says it was alerted by monitoring firm Hypernative around 05:42 UTC and identified the root cause within an hour. The affected contract is immutable, now has a zero balance and poses no further risk, and the rest of Hemi's infrastructure was unaffected. Investigation into the attacker's identity and fund recovery is ongoing.