Upbit drops HEMI after exploit, lists CP and USELESS

South Korean crypto exchange Upbit listed Cluster Protocol and Useless Coin on Sept. 8 but canceled Hemi’s scheduled debut after identifying evidence of a token theft. Summary Upbit canceled HEMI trading after identifying token theft linked to a September 7 smart-contract exploit. The attacker drained approximately 124.5 million unclaimed HEMI and converted proceeds into stablecoins and Ether. CP began trading across Upbit’s KRW, BTC and USDT markets using deposits through Base exclusively. USELESS trading proceeded against BTC and USDT while Upbit abandoned HEMI before its scheduled opening. Hemi said its core tokens, network, tunnels and third-party bridges were unaffected by the exploit. Upbit initially announced that HEMI and USELESS trading would begin against Bitcoin and Tether at 9:30 p.m. Korea Standard Time. The exchange later updated its notice at 9:12 p.m., 18 minutes before the planned opening, to cancel HEMI support. The exchange said a security vulnerability had been exploited on the previous day and that HEMI tokens appeared to have been stolen. Upbit said it reviewed how the incident could affect trading before deciding not to open the markets. Upbit to List CP, HEMI and USELESS Across KRW, BTC and USDT Markets South Korea’s largest crypto exchange Upbit announced new listings for Cluster Protocol (CP), Hemi (HEMI) and Useless (USELESS). CP will be available in KRW, BTC and USDT pairs; Cluster Protocol is an AI… pic.twitter.com/HMx27Y3ObH — Wu Blockchain (@WuBlockchain) September 8, 2026 You might also like: NCT price surges 200% on Upbit KRW listing Upbit canceled HEMI trading after 124.5 million tokens were stolen Hemi confirmed that an attacker exploited its legacy Genesis Drop contract at 03:36 UTC on Sept. 7. The project’s post-mortem said approximately 124.5 million unclaimed HEMI tokens were removed. The attacker used a reentrancy vulnerability in a modified MerkleBox contract. According to Hemi, the contract created token lockups before updating the remaining claimable balance. It also allowed users to configure claim groups with custom lockup contracts. The attacker created a malicious claim group and repeatedly called the claim function before its accounting updated. The operation used a two-million-HEMI flash loan and recursively executed the claim process 63 times. Hemi said the attacker sold about 80.15 million HEMI for approximately 158,200 USDT and another 41.4 million for roughly 84,900 USDC. About 2.95 million HEMI were exchanged for 0.3442 hemiBTC. The sales ultimately generated about $255,000 in stablecoins. The attacker moved the funds across Ethereum, Arbitrum, BNB Chain, Optimism, Avalanche and Polygon before converting most of the proceeds into Ether. Hemi said the attack involved only the Genesis Drop claim contract. It said the HEMI and veHEMI tokens, Hemi Virtual Machine, native tunnels and third-party bridging systems were not affected. These are project statements based on its internal investigation.
عنوان اصلی (انگلیسی): Upbit drops HEMI after exploit, lists CP and USELESS
مشاهدهی خبر کامل در منبع ↗ بازگشت به Hemiاین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.