← Radar

Incident case file

Sign in to watch

Projekt (GREEN/GOLD) Reward Vault — Flash Loan Reward-Logic Exploit

Incident date July 25, 2026Last updated Aug 1, 2026

1 views

ClosedEthereum L1Flash loan / reward-logic exploitCluster: PROJEKT-FLASH-2026-07

Estimated loss

$561.2K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Ledger

Attacker

0x61e7Ad696215688d274C729A4cD0FbbC88FC4f85 (initial deployer, funded with 0.02 ETH)

Funds moved to

The full drained amount (300.70 ETH, ~$561,202) was transferred directly to 0x7bd736631afbe1d3795a94f60574f7fa0ae89347, the same address that had pre-funded the attacker's deployer wallet with 0.02 ETH. 1 ETH was sent to BuilderNet as a private-inclusion tip, keeping the exploit transaction out of the public mempool. No further downstream movement identified as of reporting.

Linked

Victim contract (unverified 'buy-to-earn' reward vault): 0x574Fc478BC45cE144105Fa44D98B4B2e4BD442CB, deployed via 'Projekt Diamond: Deployer'. Attacker/orchestration contract (survived, self-destructs not applied): 0x12d6fe4822325bba82faf6cf706e6b6885c922f9. Flash-loan routing contract (survived): 0xa34bf19a63079fbb3f3f0756d552a3dc0f5f4885. 13 of 15 total contracts deployed in the single attack transaction self-destructed immediately after use. Funding source / final beneficiary: 0x7bd736631afbe

Chronology

1 beat
  1. T-1 — Prior to the attack: 0x7bd736631afbe1d3795a94f60574f7fa0ae89347 sends 0.02 ETH to 0x61e7Ad696215688d274C729A4cD0FbbC88FC4f85, funding the attacker's deployer wallet. T0 — July 25, 2026 (single transaction, hash 0x90f40d3c3b60370f7287d51d972ef54596c46e98f21af91b03a4e84c5e410f64, block 25606412): the attacker deploys 15 contracts in one transaction, 13 of which self-destruct immediately after use to obscure the attack path and reduce gas cost. A flash loan of ~13,997.84 WETH is borrowed from Morpho and pushed sequentially through 13 Uniswap V2 memecoin pairs (including Kirby Inu, CMERGE, Infinity Token, Projekt Diamond/DIAMND, ApeBullInu, Beer-inu, Mimetic, NTENDO, ROTTSCHILD, Covir, Ganja, PEPETH, Fitcoin), using skim() on each pair to register fabricated 'purchase' events without genuine token swaps. DefimonAlerts confirmed: 'An unverified buy-to-earn reward vault credits an ETH allocation via the permissionless trackPurchase(buyer), which reads the buyer's token balance delta to size the reward, then pays it out with massWithdraw() -> msg.sender.transfer(alloc).' Because trackPurchase never verifies actual ETH spent, the fabricated skim events inflate the attacker's reward allocation arbitrarily. The flash loan is fully repaid to Morpho within the same transaction. The attacker then calls massWithdraw() to drain 300.70 ETH (~$561,202) from the vault's reward pool, sends 1 ETH to BuilderNet to keep the transaction out of the public mempool (avoiding front-running/MEV extraction), and forwards the remaining 300.70 ETH directly to 0x7bd736631afbe1d3795a94f60574f7fa0ae89347. No post-incident statement from the Projekt team has been identified; the attacker remains unattributed.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)