Projekt buy-to-earn reward vault exploited for ~$560K via flash-loan-powered fake purchase allocations that bypassed reward verification.
Security & Exploits ·
Projekt's buy-to-earn reward vault lost approximately $560K on July 25, 2026, after an attacker exploited a logic flaw in how purchase allocations were tracked and rewarded. The vault's trackPurchase function credited rewards based on token balance changes without verifying actual ETH expenditure, allowing the attacker to register fake purchases at negligible cost. The exploit involved flash-loaning approximately 14K WETH from Morpho, deploying those funds across dozens of Uniswap V2 memecoin pairs to generate token skims, and using those inflated token balances to claim outsized reward allocations before draining roughly 301.7 ETH from the vault in a single transaction.
The attack succeeded because the massWithdraw function honored allocation payouts without secondary verification. The attacker repaid the flash loan within the same transaction, leaving no direct collateral trail. The vault's permissionless design allowed any caller to submit purchase records by calling trackPurchase with arbitrary buyer addresses.
The transaction and attacker address remain publicly visible on-chain. It is not yet clear whether recovery mechanisms or governance intervention are underway.