Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
    Kevin Warsh, Chair of the Federal Reserve of the United States
    Bitcoin Falls Below $78K as Fed Hike Odds Jump to 56%: What Experts Say
    Gold Bitcoin coin on a city street in front of a green rising candlestick chart showing BTC at $78,816.11
    Inside Crypto’s Fastest Week of 2026: Bitcoin’s August Price Rally Was Not a Retail Story
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

LULA Token on BSC Exploited for $578K in Reserve Manipulation Attack

The attacker used a $237 million flash loan to manipulate LULA reserves, ultimately stealing around $578,100 from the PancakeSwap V2 liquidity pool.

Written By Dishita Malvania
Edited by Divya Mistry
Published 2026-07-29·Updated 2 months ago
Make The Crypto Times preferred on GoogleGoogle
LULA Token on BSC Exploited for $578K in Reserve Manipulation Attack

The LULA token on Binance Smart Chain has been exploited for approximately $578,000 in a reserve manipulation attack, with the attacker abusing a privileged recycle() function embedded in the token’s smart contract to pull liquidity directly out of the PancakeSwap V2 pair. 

Blockchain security firm TenArmor was the first to flag the incident, followed by detailed breakdowns from BlockSec Phalcon and CertiK on July 29.

AI Summary
Show
TenArmor flagged the LULA token exploit, detecting a $578,000 loss due to reserve manipulation
BlockSec Phalcon and CertiK broke down the attack, revealing the abuse of the recycle() function
CertiK found the attacker prepared 12 days in advance, using a $237 million flash loan to maximize the exploit

TenArmor reported the attack in a post on X, stating that its system detected a suspicious attack involving the LULA token on BSC that resulted in an approximate loss of $578.1K. The firm shared the attack transaction and pointed to a series of on-chain transfers that moved value out of the protocol before it was detected.

How the attack unfolded

According to BlockSec Phalcon, the exploit hinged on a reserve manipulation involving the token’s recycle() function. The function allowed the Rental contract to transfer LULA directly out of the PancakeSwap V2 pair and then call sync(), forcing the pair’s reserves to update to the manipulated balances.

Phalcon’s breakdown analysis of the flow showed the attacker first executed a large USDT-to-LULA swap to inflate the pair’s USDT reserve, then repeatedly triggered the recycle() function to shrink the LULA reserve, before swapping a small amount of LULA back to drain the liquidity pool. 

Because the reserves no longer matched the real token balances, the attacker was able to extract value at a heavily skewed rate, a pattern seen earlier this year when the PancakeSwap LABUBU pool was exploited for $1.1 million through a similar reserve imbalance.

The vulnerable code shared by Phalcon showed that recycle() was restricted to the rental contract, calculated a maximum take equal to one-third of the pair’s LULA balance, and used an internal _basicTransfer() method to move tokens straight from the pair before syncing. That _basicTransfer() function simply adjusted balances and emitted a Transfer event, bypassing the checks a standard transfer would apply.

CertiK points to 12-day setup and $237M flash loan

CertiK, which flagged the same incident at a loss of roughly $578K, added that the attacker had prepared well in advance. In its analysis, the firm said the attacker deployed helper contracts to accumulate referral and team rewards 12 days before the exploit, then flashloaned around $237 million to swap out LULA in the decentralized exchange, maximizing the deflation through claimReward() and recycle().

The attack transaction is viewable on BscScan, and both TenArmor and CertiK linked to their respective explorer breakdowns through Phalcon Explorer and Skylens. The LULA token contract sits at 0x72ad494fda63d2b91b9d7290737e8ef1194a0c47 on BSC.

BSC remains a frequent target

The LULA incident adds to a long run of exploits hitting projects on Binance Smart Chain through 2026. In June, the BY token on BSC lost about $88,400 in a suspected exploit also flagged by TenArmor, while last week the 42DAO stablecoin BLC depegged to near zero after a $912K oracle exploit on BNB Chain.

The pattern fits the wider picture laid out in CertiK’s Hack3D report, which found Web3 lost more than $1.31 billion across 344 incidents in the first half of the year. Code vulnerability was the most prolific attack category with 204 incidents, and the firm flagged a growing trend of attackers revisiting older, previously deployed codebases.

The week of July 19 to 25 alone saw over $47 million in confirmed losses across protocols including AFX Trade, Wanchain, Verus, and Lien Finance, underscoring how relentless the current stretch of on-chain attacks has become.

Also Read: Crypto Hacks Cross $1.1B in Record H1 2026 Losses: Blockaid

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Revolut Handed Over Bitcoin Histories, Passports on Spoofed Government Email
Revolut Handed Over Bitcoin Histories, Passports on Spoofed Government Email
Coinbase CFO Says It Has SEC-CFTC Backup Plan if CLARITY Act Stalls
Coinbase CFO Says It Has SEC-CFTC Backup Plan if CLARITY Act Stalls
India’s FM Urges RBI to Scale Digital Rupee Pilots Amid Tokenisation Push
India’s FM Urges RBI to Scale Digital Rupee Pilots Amid Tokenisation Push
Wintermute Moves $160M in ETH to Binance and Coinbase as Ethereum Rejects $2,667
Wintermute Moves $160M in ETH to Binance and Coinbase as Ethereum Rejects $2,667
Central Bureau of Investigation India emblem mounted on a stone wall.
CBI Warns Indian Crypto Users Over P2P Trades and UPI Payments

Find Us on Socials

You may also like

Zentra Finance logo on a soft orange and white gradient background.

Zentra Finance Reports $143K Exploit Affecting ctUSD Reserve

Person holding a smartphone displaying the Zcash logo and text.

Zcash Holder Says $589K USDT Stuck on NEAR Intents 50 Days After Zodl Swap

Smartphone displaying the orange Metaplanet logo against an orange background.

Metaplanet Shares Fall 3.86% as Firm Proposes ¥27.8B Capital Cut & Hong Kong Unit

Hooded figure in dark clothing sitting behind a laptop screen with the green octopus logo and text for "Symbiosis" illuminated in the background

Symbiosis Bridge Exploit: Hacker Mints 368.9 Billion Synthetic Bitcoin

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information