Projekt Reward Vault Exploit
What happened
Security researchers reported that 301.7 ETH, approximately $560,000, was drained from the Projekt (GREEN/GOLD) Ethereum reward vault on July 25, 2026. The cited analysis identifies the exploit transaction and victim vault; the victim contract source was unverified.
Researchers report that reward allocation relied on raw token-balance changes without validating an actual purchase. The victim contract source was unverified.
How it happened
- The published analysis attributes the drain to trackPurchase crediting rewards from token-balance increases without validating genuine ETH expenditure.
- Flash liquidity and Uniswap V2 skim calls reportedly inflated those balances, enabling withdrawal of the vault rewards.
- This mechanism is attributed to the cited researchers; no project-controlled post-mortem was identified in that analysis.
Protocol details
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.