CYNTRI AIAutonomous DeFi
🔍SEARCH
THE BODY COUNT
HACK DATABASE·

He Called the Same Function 63 Times and Took Home Almost Nothing

The reentrancy bug that destroyed The DAO in 2016 turned up on a Bitcoin layer-2 in 2026. The attacker drained 124.5 million tokens in one transaction and cleared roughly $255,000, because there was nobody to sell them to.

S
SYNTH·Hack Database
He Called the Same Function 63 Times and Took Home Almost Nothing - CMZ investigation
A decade-old bug class, 124.5 million tokens, and about $255,000 to show for it.

Reentrancy is the oldest famous bug in smart contracts. It killed The DAO in June 2016, took 3.6 million ETH with it, and split Ethereum into two chains that still both exist. Every audit checklist written since has it near the top. Every developer who has read anything about contract security knows the pattern: update your balances before you make an external call, or the caller can re-enter your function before you have recorded what you already paid them.

On September 7, 2026, at 03:36:47 UTC, somebody found it again on Hemi Network, a modular Bitcoin-Ethereum layer-2.

The target was a contract called MerkleBox, which handled distribution for Hemi's Genesis Drop. The attacker flash-loaned 2 million HEMI from a SushiSwap pool, then called the claim function recursively sixty-three times inside a single atomic transaction. The flaw was the textbook one: token locks were created before balances updated, so each re-entry saw a state that had not yet accounted for the previous claim. By the time the transaction settled, 124.5 million unclaimed HEMI tokens had left the contract.

CyntriAI
PREDICTIVE DEFI
Stop chasing yields across five chains.
Cyntri AI agents predict, execute, and rebalance your DeFi positions using advanced predictive models.
ETHSOLARBBASEOP
Read the Whitepaper
cyntriai.org
A Cyntri AI Project

And then the interesting part, which is that it barely mattered.

The attacker liquidated and bridged the tokens across multiple chains within roughly a day, and cleared approximately $255,000. A hundred and twenty-four and a half million tokens, converted into slightly more than a quarter of a million dollars. Upbit pulled its HEMI listing.

The gap between those two numbers is the whole story. The attacker's problem was the same one the Coldcard thief has and the PlayDapp thief had: the headline figure describes the hole in the contract, not the money you can actually walk away with. Dumping 124.5 million tokens into a market that thin collapses the price long before you have sold them all. The exploit worked perfectly and the payday was roughly what a mid-level engineer makes in a year.

Hemi is worth placing, because the target matters to how the story reads. It bills itself as a modular layer-2 that treats Bitcoin and Ethereum as components of a single supernetwork, giving contracts a view of Bitcoin state while settling with Ethereum tooling. That is a serious engineering ambition. The Genesis Drop was its token distribution event, MerkleBox was the contract handing out the unclaimed allocation, and the bug was in the part of the system with the least novel job in it. The hard, new, interesting work was elsewhere. The money left through the claim function.

It also fits a pattern that runs through 2026 and shows up repeatedly in this database. The year set a record for the number of crypto attacks while total dollar losses fell. Around ninety percent of stolen funds are never returned, but the typical amount worth stealing keeps shrinking, because the large, obvious, well-capitalised targets have mostly been hardened and what is left is a long tail of small protocols with small pools and old bugs.

The part that should worry anyone building on new infrastructure is where the bug was. Hemi's difficult, novel engineering is in the consensus and the Bitcoin-awareness layer. This flaw was in a token claim contract, the most boring component in the system, the sort of thing that gets written quickly because the interesting problems are elsewhere. Reentrancy has been in every audit checklist for ten years and it still shipped, in the file nobody was worried about. That is the recurring shape of it: teams harden what they find hard and lose money through what they found easy.

A decade-old vulnerability, on a new Bitcoin layer-2, for two hundred and fifty-five thousand dollars. The bug did not get harder to find. The rewards got smaller.

No attacker has been identified. The funds were not recovered.

The Aftermath

The stolen tokens were liquidated and bridged across multiple chains within about a day, netting roughly $255,000, which places this incident among the roughly 90% of 2026 crypto hacks where funds are never returned. Upbit removed its HEMI listing. No attacker has been identified. The gap between 124.5 million tokens drained and $255,000 realised is the practical ceiling on mint-and-dump attacks against thin markets, and it recurs throughout 2026: a record number of incidents producing falling total losses.

LESSONS LEARNED

!Reentrancy has been the best-known bug in smart contracts since 2016 and it is still being shipped. This one created token locks before updating balances.
!Flash loans turn a small amount of capital into enough leverage to trigger the flaw. Two million borrowed tokens, sixty-three calls, one transaction.
!Draining 124.5 million tokens and clearing $255,000 is the arithmetic of thin liquidity. You cannot sell what nobody is buying.
!2026's pattern in one incident: record attack frequency, shrinking payouts, and old bugs on new infrastructure.

COMMENTS

CMZ
END OF FILE
Filed under Hack Database