EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Upbit removed HEMI and launched CP and USELESS

2026-09-09 16:45:12
Bookmark

Upbit canceled Hemi launch plan after discovering evidence of token theft.

South Korean cryptocurrency exchange Upbit announced the launch of Cluster Protocol (CP) and Useless Coin (USELESS) on September 8, but canceled the transaction originally scheduled to be conducted by Hemi (HEMI) after identifying evidence related to token theft.

Upbit urgently suspended the HEMI transaction after confirming that a smart contract exploit occurred on September 7. The attackers stole approximately 124.5 million unused HEMI tokens and converted the proceeds into stablecoins and Ether.

At the same time, Cluster Protocol (CP) has started trading in Upbit's KRW, BTC and USDT trading pairs through the Base Network Deposit feature. Useless Coin (USELESS) is also trading in the BTC and USDT pairs, while Upbit dropped its HEMI support ahead of its scheduled opening.

The Hemi project party stated that its core tokens, networks, tunnels and third-party bridging systems were not affected by this exploit.

Upbit adjusted launch announcement

Previously, Upbit announced that it would start HEMI and USELESS transactions for Bitcoin and Tether at 9:30 pm Korean Standard Time. However, 18 minutes before the scheduled opening, at 9:12 pm, the exchange updated its announcement and decided to withdraw support for HEMI.

The exchange pointed out that a security breach from the previous day was exploited and the HEMI token was suspected to be stolen. Upbit said it had reviewed the possible impact of the incident on transactions before deciding not to open the market.

Vulnerability details and capital flow

Hemi confirmed that the attacker used its old "Genesis Drop" contract at 3:36 a.m. UTC on September 7. The post-event analysis report of the project party pointed out that approximately 124.5 million unused HEMI tokens were removed.

The attacker exploited a reentry vulnerability in a modified MerkleBox contract. According to Hemi, the contract creates a token lock-in mechanism before updating the remaining receivable balance and allows users to configure a claim group with a custom lock-in contract.

The attacker created a malicious collection group and repeatedly called the collection function before accounting records were updated. This operation used two million HEMI flash loans and recursively performed 63 collection processes.

Hemi said the attackers sold approximately 80.15 million HEMIs for approximately 158,200 USDT, and another 41.4 million HEMIs for approximately 84,900 USDC. Another approximately 2.95 million HEMI were exchanged for 0.3442 hemiBTC.

These sales ultimately generated approximately US$255,000 in stablecoins. The attacker then moved funds between multiple chains such as Ethereum, Arbitrum, BNB Chain, Optimism, Avalanche and Polygon, and converted most of the proceeds into Ethereum.

Hemi emphasized that the attack only involved Genesis Drop receiving contracts. Hemi and veHEMI tokens, Hemi virtual machines (HVMs), native tunnels and third-party bridging systems were not affected. The above statement is based on the results of its internal investigation.

Normal trading between CP and USELESS

Cluster Protocol (CP) began trading in Upbit's KRW, BTC and USDT trading pairs at 2:30 pm Korean time. Currently, only deposits and withdrawals on the Base network through Upbit designated contracts are supported.

Upbit describes Cluster Protocol as an artificial intelligence infrastructure that connects models, data, GPU computing and AI agents, providing a single interface and an on-chain payment system. CP supports payments, pledges and participant incentives within the agreement.

In the early stages of its launch, Upbit limited CP purchases to about five minutes. During this period, sell orders selling at least 10% below the previous day's closing price were also restricted. In the first two hours, only limited order services will be provided.

USELESS starts trading in BTC and USDT pairs at 9:30 pm as scheduled. Upbit currently only supports USELESS deposits and withdrawals through the Solana network.

USELESS does not claim to be technical practical. Upbit describes it as a community-focused Meme Coin built around the ironic concept of "promising no product or centralized development roadmap."

Subsequent impact and regulatory environment

The launch of these two tokens follows Upbit's recent move to expand the small-cap token market. Related reports show that the exchange added eight trading pairs to four altcoins in August and recently introduced direct Korean won access channels for several tokens.

Hemi stated that it discovered the issue approximately 2 hours and 44 minutes after the breach occurred. The project party contacted partners and referred the incident to SEAL 911 Security Response Services.

The project party pointed out that since the stolen HEMI tokens have been sold, the attacker no longer holds the stolen tokens in his hands. However, when Hemi released the report, most of the converted funds remained in Ethereum addresses associated with the attacker.

Hemi has not announced a compensation plan, a recall deadline or negotiated a refund. It said it is tracking the flow of funds and working with law enforcement and security companies to explore various recycling options.

Other exchanges may conduct independent reviews. Bithumb listed HEMI as an investment risk warning after identifying abnormal withdrawals of the Genesis Drop contract. Unless the project party addresses the exchange's concerns, this could lead to further restrictions.

Upbit said it will strengthen its pre-listing review process after canceling the HEMI transaction. The exchange has not given a new launch date, which means HEMI will need to be re-evaluated before any future Upbit launches.

The move comes as South Korean regulators continue to review exchange safety and consumer protection. As previously reported, authorities have launched sanctions proceedings against Upbit operator Dunamu in connection with another wallet leak reported in November 2025.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP