Hemi released a postmortem report on the Genesis Drop exploit that occurred on September 7. According to Foresight News, the attacker used a MerkleBox smart contract vulnerability in Hemi's Genesis Drop at 03:36:47 UTC on September 7 to steal about 124.5 million unclaimed tokens.
The report said the flaw was caused by a reentrancy attack, in which the contract processed token lock creation before updating account balances, allowing the attacker to withdraw far more than the allocation in the claim group. The attacker used 2 million tokens from Sushiswap's HEMI/USDT pool as a flash loan, executed the attack through coordinated contracts in a single transaction, and repaid the loan within the same transaction.
The stolen tokens were immediately liquidated on decentralized exchanges within the Hemi network, generating about $255,000 in stablecoins. The funds were then bridged through LayerZero to Ethereum, Arbitrum, BSC, and other networks, and most were converted into ether.
Hemi said it received an alert from Hypernative at 05:42 UTC and identified the root cause in less than one hour. The affected contract is immutable and now has a zero balance, so it poses no further risk. Hemi's other infrastructure was not affected, and investigations into the attacker's identity and efforts to recover the funds are ongoing.