
Upbit drops HEMI after 124.5M-token exploit
- Upbit has cancelled Hemi (CRYPTO:HEMI) trading after a September 7 exploit stole about 124.5 million tokens.
- The attacker converted much of the stolen HEMI into about US$255,000 in stablecoins.
- Upbit has said it will strengthen pre-listing reviews after cancelling the scheduled launch.
Upbit has cancelled Hemi (CRYPTO:HEMI) trading after a September 7 smart-contract exploit removed about 124.5 million unclaimed HEMI tokens.
The attacker exploited a reentrancy vulnerability in Hemi’s legacy Genesis Drop contract and repeatedly triggered the claim process before its accounting updated.
The stolen tokens have been sold, generating about US$255,000 in stablecoins before the proceeds were moved across several blockchain networks and converted largely into Ether.
Hemi has said the exploit was limited to the Genesis Drop claim contract, leaving HEMI and veHEMI, the Hemi Virtual Machine, native tunnels and third-party bridges unaffected.
Upbit had planned to open HEMI trading alongside Cluster Protocol (CRYPTO:CP) and Useless Coin (CRYPTO:USELESS), but cancelled HEMI just 18 minutes before its scheduled launch.
Cluster Protocol and Useless Coin have proceeded to trading, with CP available across Upbit’s KRW, BTC and USDT markets and USELESS paired with BTC and USDT.
Upbit has not announced a new HEMI listing date, while Hemi has continued tracing the stolen funds and exploring recovery options with law enforcement and security firms.


