Hemi released a post-incident (postmortem) report on the exploitation of «Genesis Drop» that occurred on September 7. According to the (Foresight News) newspaper, the attacker used a vulnerability in a smart contract of MerkleBox in «Genesis Drop» belonging to Hemi at 03:36:47 UTC on September 7 to steal approximately 124.5 million unclaimed tokens.