← Radar

Incident case file

Sign in to watch

Hemi Genesis Drop MerkleBox Reentrancy Exploit — $255K

Incident date Sep 6, 2026Last updated Sep 24, 2026

0 views

ContainedHemi L2Reentrancy exploit on airdrop claimCluster: HEMI-MERKLEBOX-2026-09

Estimated loss

$255K

Affected users

1
Group joining is coming soon.

Investigation

80%

Facts and investigation

Ledger

Attacker

Orchestrator contract 0x86b1EbFEbb0502D3d5915c920f90a61892501B69

Funds moved to

Approximately 124.5M unclaimed HEMI tokens were extracted via the fake lockup/claim-group mechanism; all stolen HEMI was reportedly liquidated with none remaining under attacker control as of the post-mortem.

Linked

MerkleBox contract: 0x9Ab3660ceE733332785cEa09D1a4Ff222F31aE54. Orchestrator: 0x86b1EbFEbb0502D3d5915c920f90a61892501B69. Fake lockup/claim-group creator: 0xB67A9E46BCB99D4f65dC6825500Ef5cc8d6Eb364. Deployment transaction: 0x8a7f710273b1e664151e8e2c2a8061ed5ba4c9a4dbfc6d57e51da6e072cab05c. Atomic exploit transaction: 0x37bef9ad9b69abf50da9634f692aeeefd93e681d217d1d14763307ce11fc7155.

Chronology

1 beat
  1. On September 7, 2026, between 03:35:23 and 03:36:47 UTC, an attacker exploited a reentrancy vulnerability in the MerkleBox contract used for Hemi's Genesis Drop airdrop claims. The attacker created a fake lockup/claim-group contract, flash-loaned 2M HEMI from SushiSwap, and used the reentrancy path to claim significantly more than their legitimate allocation before the contract's state was updated. Approximately 124.5M unclaimed HEMI tokens were extracted, valued at roughly $255,000 at the time. Hemi published an official post-mortem on September 8. Upbit subsequently delisted the affected token pairing as a precautionary measure.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)