Incident case file
Sign in to watchHemi Genesis Drop MerkleBox Reentrancy Exploit — $255K
0 views
Estimated loss
Affected users
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatOn September 7, 2026, between 03:35:23 and 03:36:47 UTC, an attacker exploited a reentrancy vulnerability in the MerkleBox contract used for Hemi's Genesis Drop airdrop claims. The attacker created a fake lockup/claim-group contract, flash-loaned 2M HEMI from SushiSwap, and used the reentrancy path to claim significantly more than their legitimate allocation before the contract's state was updated. Approximately 124.5M unclaimed HEMI tokens were extracted, valued at roughly $255,000 at the time. Hemi published an official post-mortem on September 8. Upbit subsequently delisted the affected token pairing as a precautionary measure.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)