An attacker drained 124.5 million unclaimed HEMI tokens from Hemi's Genesis Drop on September 7, exploiting a reentrancy vulnerability in the MerkleBox smart contract at 03:36:47 UTC.
Hemi's post-mortem, published September 8, confirmed the contract processed the creation of token locks before updating accounted balances, enabling the attacker to withdraw funds well above what was configured for their claims group. The flaw follows a classic reentrancy pattern where state updates lag behind external calls, a vulnerability class that has historically accounted for some of the largest losses in decentralized finance.
The attacker funded the operation with a 2 million token flash loan from Sushiswap's HEMI/USDT pool, executed the exploit atomically through an orchestrator contract, and repaid the loan within the same transaction. The stolen tokens were immediately liquidated on DEXes within the Hemi network, generating approximately $255,000 in stablecoins. Those funds were bridged to Ethereum, Arbitrum, and BSC via LayerZero and converted mostly to ETH, a laundering path that complicates recovery efforts.
Hemi received the alert from security firm Hypernative at approximately 05:42 UTC and identified the root cause in under an hour. The affected contract is immutable with a zero balance, posing no additional risk. The rest of Hemi's infrastructure was not affected, though the investigation into the attacker's identity and fund recovery remains open.
The exploit underscores a broader concern for token claim and airdrop implementations across the crypto sector. Genesis Drop contracts are typically deployed once and left immutable, meaning a single design oversight can permanently expose unclaimed supply. The Hemi incident demonstrates that even protocols with otherwise sound infrastructure can carry latent risk in peripheral contracts, and the sector-wide pattern of rushing airdrop deployments to meet launch timelines may leave similar vulnerabilities undiscovered.
For HEMI token holders, the immediate financial impact is limited to the drained unclaimed supply rather than user-held balances. However, the reputational cost could be more significant. Security incidents at the protocol level tend to depress token valuations as confidence erodes, and Hemi's response — including whether it can trace and recover the stolen funds — will determine how quickly the market moves past the event. The team has not yet disclosed whether any remediation or compensation plan is under consideration for affected claim groups.