STATEMENT FROM HEMI REGARDING THE RECENT INCIDENT

Summary:
On September 7, 2026, a reentrancy attack targeted the MerkleBox smart contract used by the Hemi platform for its initial distribution (Genesis Drop).
* How it happened: The attacker deployed malicious contracts by exploiting a security vulnerability and customizable lockup parameters within the contract. Using a flash loan, they repeatedly invoked the contract recursively, draining the funds before the balance accounting could update.
* Stolen/Affected Amount: Approximately 124.5 million HEMI tokens, which were resting unclaimed in the contract, were stolen.
* Fate of the Funds: The attacker immediately sold the stolen HEMI tokens into low-liquidity pools on Hemi's decentralized exchanges (DEXs), converting them into ~$255,000 in stablecoins (USDT/USDC). They then bridged these funds via LayerZero across multiple chains (Ethereum, Arbitrum, BSC, etc.) and converted most of them into ETH.
* Current Status & Mitigation: The exploit was isolated strictly to the legacy MerkleBox contract; Hemi's core systems, native bridges, HEMI, and veHEMI tokens remain unaffected. Because the contract's balance has been drained to zero, it poses no ongoing risk. The team identified the incident via Hypernative alerts, contacted SEAL 911 and partner exchanges to monitor and blacklist the attacker’s addresses, and the investigation remains ongoing.

#hacked #hemi #btc #eth #binance