South Korean crypto exchange Upbit listed Cluster Protocol and Useless Coin on Sept. 8, but canceled the planned Hemi listing just 18 minutes before trading was supposed to begin after finding signs that HEMI tokens had been stolen.
Upbit had planned to open HEMI and USELESS trading at 9:30 p.m. Korea Standard Time. But at 9:12 p.m., the exchange updated its notice and said it would not launch HEMI trading.
Upbit said the decision came after it found that a security flaw had been exploited on Sept. 7 and that HEMI tokens appeared to have been stolen. The exchange reviewed the possible impact on the market before canceling the listing.
Hemi said the attacker targeted its older Genesis Drop contract at 03:36 UTC on Sept. 7. Around 124.5 million unclaimed HEMI tokens were taken.
The attack used a reentrancy flaw in a modified MerkleBox contract. The attacker created a malicious claim group and repeatedly called the claim function before the contract could properly update its records.
The attacker used a two-million-HEMI flash loan and repeated the claim process 63 times.
Around 80.15 million HEMI were later sold for about 158,200 USDT, while another 41.4 million HEMI were exchanged for roughly 84,900 USDC. About 2.95 million HEMI were also traded for 0.3442 hemiBTC.
In total, the sales produced about $255,000 in stablecoins. The attacker moved the money through Ethereum, Arbitrum, BNB Chain, Optimism, Avalanche and Polygon, before changing most of it into Ether.
Hemi said the attack was limited to the Genesis Drop claim contract. According to the project, the HEMI and veHEMI tokens, Hemi Virtual Machine, native tunnels and third-party bridges were not affected.
While HEMI trading was canceled, the other Upbit listings went ahead.
Cluster Protocol started trading at 2:30 p.m. Korea time in Upbit’s KRW, BTC and USDT markets. Deposits and withdrawals are supported only through Base using the contract specified by Upbit.
Upbit described Cluster Protocol as an AI infrastructure project that connects AI models, data, GPU computing and AI agents through one system. Its CP token is used for payments, staking and rewards within the network.
Upbit placed some temporary limits on CP trading. For the first few minutes, certain purchase orders were restricted, while sell orders priced at least 10% below the previous closing price were also limited. Only limit orders were available during the first two hours.
USELESS trading began at the planned 9:30 p.m. time against BTC and USDT. Upbit supports deposits and withdrawals for the token through Solana only.
Unlike many crypto projects, USELESS does not claim to provide a technical product or utility. It is presented as a community-focused meme coin built around the idea of having no product and no centralized development roadmap.
Hemi is now focused on tracking the stolen funds and trying to recover them. The project said it discovered the vulnerability about two hours and 44 minutes after the attack and contacted security partners before involving the SEAL 911 response service.
Hemi said the stolen HEMI had already been sold, so the attacker no longer held the tokens. However, most of the money received from those sales was still sitting in an Ethereum address linked to the attacker when Hemi released its report.
The project has not announced any reimbursement plan, recovery deadline or agreement to return the funds. It said it is working with law enforcement and security companies while exploring ways to recover the money.
Other exchanges are also reviewing the situation. Bithumb placed HEMI under an investment warning after detecting unusual withdrawals from the Genesis Drop contract. That could lead to further restrictions if the concerns are not resolved.
Upbit said it would strengthen its listing review process following the cancellation. The exchange has not announced another date for HEMI, meaning the token will need to go through another review before it can potentially be listed in the future.





