{"investigation":{"slug":"hemi-genesis-drop-merklebox-exploit","entity_name":"Hemi (Genesis Drop / MerkleBox Exploit)","trust_score":38,"severity_base":null,"score_modifier":0,"confidence":0.85,"status":"published","content_type":"investigation","summary":"Hemi is a modular Layer-2 blockchain protocol designed to bridge Bitcoin and Ethereum into a single supernetwork, co-founded by former Bitcoin core developer Jeff Garzik and Max Sanchez. On September 7, 2026, an attacker exploited a reentrancy vulnerability in the MerkleBox smart contract used for Hemi's Genesis Drop token distribution, draining approximately 124.5 million unclaimed HEMI tokens, which were liquidated for roughly $255,000 in stablecoins. The exploit was isolated to the Genesis Drop claim contract; the core Hemi network, HEMI and veHEMI tokens, and bridge infrastructure were not affected.","sections":[{"content":"Hemi is a modular Layer-2 blockchain that embeds a full Bitcoin node inside an Ethereum-compatible environment via the Hemi Virtual Machine (hVM), using a Proof-of-Proof consensus mechanism to inherit Bitcoin-level finality. The protocol is built on the OP Stack and is designed to allow developers to build DeFi applications that natively use Bitcoin without relying on wrapped tokens or external bridges. Hemi's mainnet launched in March 2025. The HEMI token is used for protocol governance and, via a veHEMI staking system, entitles long-term holders to a share of network fees. The project was co-founded by Jeff Garzik, a former Bitcoin Core developer, and Max Sanchez, the inventor of the Proof-of-Proof consensus protocol.","heading":"Protocol Overview","sources":[{"url":"https://hemi.xyz/blog/introducing-hemi-a-new-vision-for-layer-2-on-bitcoin-and-ethereum/","name":"Hemi: Introducing a New Vision For Layer-2 on Bitcoin and Ethereum","type":"official","credibility":1},{"url":"https://cryptobriefing.com/hemi-launching-mainnet-on-march-12-uniting-the-bitcoin-and-ethereum-ecosystems-into-a-single-supernetwork/","name":"Hemi launching mainnet on March 12 — Crypto Briefing","type":"news_article","credibility":2}],"severity":"low"},{"content":"At 03:36:47 UTC on September 7, 2026, an attacker executed a reentrancy exploit against the MerkleBox smart contract governing Hemi's Genesis Drop token distribution. According to Hemi's official postmortem, the contract contained two compounding design flaws: it created token lockups before updating claimable balance accounting, and it allowed any party to configure claim groups with custom lockup contract implementations. The attacker exploited the second flaw by registering a malicious claim group backed by a fake lockup contract under their control. When the claim() function was called, the fake lockup contract called back into MerkleBox before accounting updates completed, enabling recursive withdrawals against stale balance data. The attacker deployed three exploitation contracts at 03:35:23 UTC and executed the exploit atomically via an orchestrator contract at 03:36:47 UTC, making 63 recursive calls within a single transaction. A flash loan of 2 million HEMI tokens was borrowed from the HEMI/USDT pool on SushiSwap to satisfy the staking threshold required to register a claim group; the loan was repaid atomically within the same transaction. The contract lacked OpenZeppelin's ReentrancyGuard protection or a proper checks-effects-interactions pattern. The exploit drained approximately 124.5 million unclaimed HEMI tokens — the full unclaimed balance of the Genesis Drop contract.","heading":"Genesis Drop MerkleBox Exploit — Technical Details","sources":[{"url":"https://www.binance.com/en/square/post/364674341986242","name":"Hemi Genesis Drop Post-Mortem (via Binance Square relay)","type":"official","credibility":1},{"url":"https://www.kucoin.com/news/flash/hemi-genesis-drop-hit-by-reentrancy-attack-124-5m-tokens-stolen","name":"Hemi Genesis Drop Hit by Reentrancy Attack, 124.5M Tokens Stolen — KuCoin","type":"news_article","credibility":2},{"url":"https://cisoai.au/brief/reentrancy-bug-in-hemis-genesis","name":"Reentrancy Bug in Hemi's Genesis Drop — CISO AI","type":"research","credibility":2},{"url":"https://shattered.io/hemi-genesis-drop-reentrancy-exploit-2026/","name":"Hemi Reentrancy Bug Drains 124.5M Tokens for $255K — Shattered.io","type":"research","credibility":2}],"severity":"critical"},{"content":"Between 03:43:59 UTC and 03:56:23 UTC on September 7, 2026, the attacker bridged stolen assets across multiple chains via LayerZero. Approximately 80.15 million tokens were sold on Hemi's own decentralized exchange for roughly 158,200 USDT, and approximately 41.4 million tokens were sold for approximately 84,900 USDC, yielding total stablecoin proceeds of approximately $255,000 (approximately $151,524.70 USDT and $103,422.62 USDC per the official postmortem). The assets were bridged to Ethereum, Arbitrum, and BNB Smart Chain, where they were largely converted to ETH. According to reports, no stolen HEMI tokens remained under attacker control after conversion; all funds had been converted to ETH on Ethereum. Recovery of the funds remained under investigation as of the date of the postmortem.","heading":"Fund Exfiltration and Cross-Chain Movement","sources":[{"url":"https://www.binance.com/en/square/post/364674341986242","name":"Hemi Genesis Drop Post-Mortem (via Binance Square relay)","type":"official","credibility":1},{"url":"https://crypto.news/upbit-drops-hemi-after-exploit-lists-cp-and-useless/","name":"Upbit drops HEMI after exploit, lists CP and USELESS — Crypto.news","type":"news_article","credibility":2},{"url":"https://www.kucoin.com/news/flash/hemi-genesis-drop-hit-by-reentrancy-attack-124-5m-tokens-stolen","name":"Hemi Genesis Drop Hit by Reentrancy Attack — KuCoin","type":"news_article","credibility":2}],"severity":"high"},{"content":"Upbit, a major South Korean cryptocurrency exchange, cancelled a planned HEMI listing approximately 18 minutes before its scheduled 9:30 p.m. KST opening on September 8, 2026, citing a security vulnerability that had been exploited the previous day and apparent token theft. Upbit stated it would strengthen its pre-listing review procedures in response to the incident. On September 9, 2026, Bithumb, another major South Korean exchange, designated HEMI as a trading warning asset and suspended HEMI deposits at 11:50 KST, citing the smart contract vulnerability in the Genesis Drop claim contract, the resulting abnormal outflow of tokens, and what Bithumb described as a failure to disclose relevant information in a timely manner. Bithumb indicated it would evaluate the project team's handling of subsequent information disclosure before taking further action.","heading":"Exchange Response — Upbit Listing Cancellation and Bithumb Warning","sources":[{"url":"https://crypto.news/upbit-drops-hemi-after-exploit-lists-cp-and-useless/","name":"Upbit drops HEMI after exploit, lists CP and USELESS — Crypto.news","type":"news_article","credibility":2},{"url":"https://panews.io/articles/01a08419-e5ca-710f-aa07-89e24deecdac","name":"Bithumb Designates Hemi (HEMI) as a Trading Warning Asset — PANews","type":"news_article","credibility":2},{"url":"https://en.cryptonomist.ch/2026/09/09/upbit-hemi-exploit-token-theft/","name":"Upbit HEMI Exploit Impacts Token Launch and Security — Cryptonomist","type":"news_article","credibility":2}],"severity":"high"},{"content":"The Hemi team was alerted to the exploit by Hypernative, a smart contract security monitoring platform, at approximately 05:42 UTC on September 7, 2026 — roughly two hours after the attack. The team began its investigation at 05:46 UTC and identified the root cause by 06:11 UTC. Partner outreach was initiated at 06:20 UTC, and SEAL 911 was contacted at 07:57 UTC. According to the official postmortem, the team traced stolen tokens across blockchain networks, filed an incident report with SEAL 911, and communicated with exchanges and partners to arrange address monitoring and blacklisting. The compromised MerkleBox contract is immutable and cannot be patched or upgraded; it holds a zero balance and poses no ongoing risk to the protocol. Hemi confirmed in its postmortem that the HEMI token, veHEMI, the Hemi Virtual Machine, other smart contracts, native Tunnels, and third-party bridging systems were unaffected by the exploit. Investigation into attacker identity and asset recovery remained ongoing at the time of publication.","heading":"Team Detection and Incident Response","sources":[{"url":"https://www.binance.com/en/square/post/364674341986242","name":"Hemi Genesis Drop Post-Mortem (via Binance Square relay)","type":"official","credibility":1},{"url":"https://crypto-economy.com/hemi-releases-post-mortem-on-genesis-drop-exploit-that-drained-124-5-million-tokens/","name":"Hemi Releases Post-mortem on Genesis Drop Exploit — Crypto Economy","type":"news_article","credibility":2},{"url":"https://www.kucoin.com/news/flash/hemi-genesis-drop-hit-by-reentrancy-attack-124-5m-tokens-stolen","name":"Hemi Genesis Drop Hit by Reentrancy Attack — KuCoin","type":"news_article","credibility":2}],"severity":"medium"},{"content":"Hemi's official postmortem explicitly confirmed that the exploit was confined to the Genesis Drop MerkleBox claim contract and did not affect the broader protocol. The HEMI token contract, veHEMI staking, the Hemi Virtual Machine, native bridge Tunnels, and all other smart contracts remained unaffected. The MerkleBox contract itself now carries a zero balance and, because it is immutable, cannot be reopened or re-exploited. The stolen tokens represented unclaimed airdrop allocations rather than user deposits or protocol treasury funds. No user funds held in wallets, liquidity pools, or the core protocol were directly at risk from this exploit.","heading":"Scope Limitation and Containment Assessment","sources":[{"url":"https://www.binance.com/en/square/post/364674341986242","name":"Hemi Genesis Drop Post-Mortem (via Binance Square relay)","type":"official","credibility":1},{"url":"https://shattered.io/hemi-genesis-drop-reentrancy-exploit-2026/","name":"Hemi Reentrancy Bug Drains 124.5M Tokens for $255K — Shattered.io","type":"research","credibility":2}],"severity":"low"}],"timeline":[{"date":"2025-03-12","event":"Hemi mainnet launched, positioning the protocol as a Bitcoin-Ethereum supernetwork L2 built on the OP Stack.","source":"Crypto Briefing","source_url":"https://cryptobriefing.com/hemi-launching-mainnet-on-march-12-uniting-the-bitcoin-and-ethereum-ecosystems-into-a-single-supernetwork/"},{"date":"2026-09-07","event":"03:35:23 UTC — Attacker deployed three exploitation contracts on the Hemi network.","source":"Hemi Genesis Drop Post-Mortem (via Binance Square)","source_url":"https://www.binance.com/en/square/post/364674341986242"},{"date":"2026-09-07","event":"03:36:47 UTC — Attacker executed the reentrancy exploit against the MerkleBox Genesis Drop claim contract, draining approximately 124.5 million HEMI tokens via 63 recursive calls funded by a 2 million HEMI flash loan from SushiSwap.","source":"Hemi Genesis Drop Post-Mortem (via Binance Square)","source_url":"https://www.binance.com/en/square/post/364674341986242"},{"date":"2026-09-07","event":"03:43:59–03:56:23 UTC — Stolen tokens sold on Hemi's DEX for approximately $255,000 in stablecoins and bridged via LayerZero to Ethereum, Arbitrum, and BNB Smart Chain.","source":"Hemi Genesis Drop Post-Mortem (via Binance Square)","source_url":"https://www.binance.com/en/square/post/364674341986242"},{"date":"2026-09-07","event":"05:42 UTC — Hypernative security monitoring platform alerted the Hemi team to the exploit.","source":"KuCoin Flash News","source_url":"https://www.kucoin.com/news/flash/hemi-genesis-drop-hit-by-reentrancy-attack-124-5m-tokens-stolen"},{"date":"2026-09-07","event":"06:11 UTC — Hemi team identified the root cause of the exploit. Partner outreach began at 06:20 UTC; SEAL 911 contacted at 07:57 UTC.","source":"Hemi Genesis Drop Post-Mortem (via Binance Square)","source_url":"https://www.binance.com/en/square/post/364674341986242"},{"date":"2026-09-08","event":"Upbit cancelled its planned HEMI listing approximately 18 minutes before the scheduled 9:30 p.m. KST opening, citing the exploit and apparent token theft.","source":"Crypto.news","source_url":"https://crypto.news/upbit-drops-hemi-after-exploit-lists-cp-and-useless/"},{"date":"2026-09-09","event":"Bithumb designated HEMI as a trading warning asset and suspended HEMI deposits at 11:50 KST, citing the smart contract vulnerability, abnormal token outflow, and inadequate timely disclosure.","source":"PANews","source_url":"https://panews.io/articles/01a08419-e5ca-710f-aa07-89e24deecdac"},{"date":"2026-09-09","event":"Hemi published an official postmortem confirming the exploit's scope, technical root cause, and ongoing recovery efforts.","source":"Crypto Economy","source_url":"https://crypto-economy.com/hemi-releases-post-mortem-on-genesis-drop-exploit-that-drained-124-5-million-tokens/"}],"sources_used":[{"url":"https://www.binance.com/en/square/post/364674341986242","name":"Hemi Genesis Drop Post-Mortem (relayed via Binance Square)","type":"official","archive_url":"https://web.archive.org/web/20260918180750/https://www.binance.com/en/square/post/364674341986242","credibility":1,"archive_timestamp":"2026-09-18T18:07:50+00:00"},{"url":"https://www.kucoin.com/news/flash/hemi-genesis-drop-hit-by-reentrancy-attack-124-5m-tokens-stolen","name":"Hemi Genesis Drop Hit by Reentrancy Attack, 124.5M Tokens Stolen — KuCoin Flash News","type":"news_article","archive_url":"https://web.archive.org/web/20260918181109/https://www.kucoin.com/news/flash/hemi-genesis-drop-hit-by-reentrancy-attack-124-5m-tokens-stolen","credibility":2,"archive_timestamp":"2026-09-18T18:11:09+00:00"},{"url":"https://crypto.news/upbit-drops-hemi-after-exploit-lists-cp-and-useless/","name":"Upbit drops HEMI after exploit, lists CP and USELESS — Crypto.news","type":"news_article","archive_url":"https://web.archive.org/web/20260918180410/https://crypto.news/upbit-drops-hemi-after-exploit-lists-cp-and-useless/","credibility":2,"archive_timestamp":"2026-09-18T18:04:10+00:00"},{"url":"https://en.cryptonomist.ch/2026/09/09/upbit-hemi-exploit-token-theft/","name":"Upbit HEMI Exploit Impacts Token Launch and Security — Cryptonomist","type":"news_article","archive_url":"http://web.archive.org/web/20260909130010/https://en.cryptonomist.ch/2026/09/09/upbit-hemi-exploit-token-theft/","credibility":2,"archive_timestamp":"2026-09-09T13:00:10+00:00"},{"url":"https://crypto-economy.com/hemi-releases-post-mortem-on-genesis-drop-exploit-that-drained-124-5-million-tokens/","name":"Hemi Releases Post-mortem on Genesis Drop Exploit — Crypto Economy","type":"news_article","archive_url":"http://web.archive.org/web/20260911162948/https://crypto-economy.com/hemi-releases-post-mortem-on-genesis-drop-exploit-that-drained-124-5-million-tokens/","credibility":2,"archive_timestamp":"2026-09-11T16:29:48+00:00"},{"url":"https://panews.io/articles/01a08419-e5ca-710f-aa07-89e24deecdac","name":"Bithumb Designates Hemi (HEMI) as a Trading Warning Asset — PANews","type":"news_article","archive_url":"https://web.archive.org/web/20260918180525/https://panews.io/articles/01a08419-e5ca-710f-aa07-89e24deecdac","credibility":2,"archive_timestamp":"2026-09-18T18:05:25+00:00"},{"url":"https://shattered.io/hemi-genesis-drop-reentrancy-exploit-2026/","name":"Hemi Reentrancy Bug Drains 124.5M Tokens for $255K — Shattered.io","type":"research","archive_url":"http://web.archive.org/web/20260912061101/https://shattered.io/hemi-genesis-drop-reentrancy-exploit-2026/","credibility":2,"archive_timestamp":"2026-09-12T06:11:01+00:00"},{"url":"https://cisoai.au/brief/reentrancy-bug-in-hemis-genesis","name":"Reentrancy Bug in Hemi's Genesis Drop — CISO AI","type":"research","archive_url":"https://web.archive.org/web/20260918180339/https://cisoai.au/brief/reentrancy-bug-in-hemis-genesis","credibility":2,"archive_timestamp":"2026-09-18T18:03:39+00:00"},{"url":"https://cryptobriefing.com/hemi-launching-mainnet-on-march-12-uniting-the-bitcoin-and-ethereum-ecosystems-into-a-single-supernetwork/","name":"Hemi launching mainnet on March 12 — Crypto Briefing","type":"news_article","archive_url":"https://web.archive.org/web/20260918180420/https://cryptobriefing.com/hemi-launching-mainnet-on-march-12-uniting-the-bitcoin-and-ethereum-ecosystems-into-a-single-supernetwork/","credibility":2,"archive_timestamp":"2026-09-18T18:04:20+00:00"},{"url":"https://grafa.com/en/news/crypto/upbit-drops-hemi-after-124-5m-token-exploit","name":"Upbit drops HEMI after 124.5M-token exploit — Grafa","type":"news_article","archive_url":"https://web.archive.org/web/20260918204606/https://grafa.com/en/news/crypto/upbit-drops-hemi-after-124-5m-token-exploit","credibility":2,"archive_timestamp":"2026-09-18T20:46:06+00:00"}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-09-18T17:12:03.156882+00:00","updated_at":"2026-09-18T20:46:46.840038+00:00"}}