Reentrancy Bug Drains $255K in 10-Year-Old Vulnerability
A ten-year-old reentrancy bug resurfaced on Hemi Network's Bitcoin layer-2 project, draining 124.5 million tokens worth $255,000 from a claim contract on September 7, 2026.
The attack exploited the MerkleBox contract's flexibility in configuring custom claim groups and allocation caps, allowing the attacker to trigger recursive calls to the claim function without updating internal accounting state.
The bug was not patched due to Hemi's use of immutable code, making it a permanent scar on their system. The incident highlights the ongoing issue with reentrancy bugs, despite industry efforts to improve smart contract security.