Public AML

Projekt reward vault exploited on Ethereum

The Projekt reward vault on Ethereum was exploited, resulting in a loss of approximately $560,000. The attacker used a flash loan to manipulate reward allocations and drain funds from the vault.

On July 25, 2026, the Projekt (GREEN/GOLD) reward vault on the Ethereum blockchain was compromised. The attacker executed a flash loan of around 14,000 WETH from Morpho and manipulated multiple Uniswap V2 memecoin pairs to create fraudulent purchase records.

By exploiting the permissionless trackPurchase function, which did not verify actual ETH spent, the attacker inflated reward allocations. This led to the draining of approximately 301.7 ETH, equivalent to about $560,000, from the vault's reward pool through a mass withdrawal.

Sources

Share:XTelegramLinkedIn