Projekt Reward Vault Exploit

Estimated loss $560K
ethereum
Reward Accounting Logic Flaw

What happened

Security researchers reported that 301.7 ETH, approximately $560,000, was drained from the Projekt (GREEN/GOLD) Ethereum reward vault on July 25, 2026. The cited analysis identifies the exploit transaction and victim vault; the victim contract source was unverified.

Technical root cause

Researchers report that reward allocation relied on raw token-balance changes without validating an actual purchase. The victim contract source was unverified.

How it happened

  1. The published analysis attributes the drain to trackPurchase crediting rewards from token-balance increases without validating genuine ETH expenditure.
  2. Flash liquidity and Uniswap V2 skim calls reportedly inflated those balances, enabling withdrawal of the vault rewards.
  3. This mechanism is attributed to the cited researchers; no project-controlled post-mortem was identified in that analysis.

Protocol details

Classification Input Validation
Protocol Type Exploit/Flash Loan Attack
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.