Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    What Happens If the CLARITY Act Does Not Pass?
    What Happens If the CLARITY Act Does Not Pass?
    The Trump Crypto Presidency Power, Policy, and $1.4 Billion
    The Donald Trump Crypto Presidency: Power, Policy, and $2.3 Billion
    GENIUS Deadline Missed, CLARITY Act Stalls on Ethics: USA’s 2 Crypto Laws Stuck
    GENIUS Deadline Missed, CLARITY Act Stalls on Ethics: USA’s 2 Crypto Laws Stuck
    2 Years of the ₹2,000 Cr WazirX Hack: The Money Never Came Back. Neither Did the Founder
    2 Years of the ₹2,000 Cr WazirX Hack: The Money Never Came Back. Neither Did the Founder
    The Robinhood Chain Paradox Built for Tokenized Stocks, Dominated by Memecoins
    The Robinhood Chain Paradox: Built for Tokenized Stocks, Dominated by Memecoins
  • Opinion
    OpinionShow More
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Bitcoin Treasury Blueprint What Stress Testing on Strategy Inc.’s MSTR-STRC Reveals
    The Bitcoin Treasury Blueprint: What Stress Testing on Strategy Inc.’s MSTR-STRC Reveals
    Why Wall Street is Divided Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    Why Wall Street is Divided: Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

LULA Token on BSC Exploited for $578K in Reserve Manipulation Attack

The attacker used a $237 million flash loan to manipulate LULA reserves, ultimately stealing around $578,100 from the PancakeSwap V2 liquidity pool.

Written By Dishita Malvania
Edited by Divya Mistry
Published 1 hour ago·Updated 46 minutes ago
Make The Crypto Times preferred on GoogleGoogle
LULA Token on BSC Exploited for $578K in Reserve Manipulation Attack

The LULA token on Binance Smart Chain has been exploited for approximately $578,000 in a reserve manipulation attack, with the attacker abusing a privileged recycle() function embedded in the token’s smart contract to pull liquidity directly out of the PancakeSwap V2 pair. 

Blockchain security firm TenArmor was the first to flag the incident, followed by detailed breakdowns from BlockSec Phalcon and CertiK on July 29.

AI Summary
Show
TenArmor flagged the LULA token exploit, detecting a $578,000 loss due to reserve manipulation
BlockSec Phalcon and CertiK broke down the attack, revealing the abuse of the recycle() function
CertiK found the attacker prepared 12 days in advance, using a $237 million flash loan to maximize the exploit

TenArmor reported the attack in a post on X, stating that its system detected a suspicious attack involving the LULA token on BSC that resulted in an approximate loss of $578.1K. The firm shared the attack transaction and pointed to a series of on-chain transfers that moved value out of the protocol before it was detected.

How the attack unfolded

According to BlockSec Phalcon, the exploit hinged on a reserve manipulation involving the token’s recycle() function. The function allowed the Rental contract to transfer LULA directly out of the PancakeSwap V2 pair and then call sync(), forcing the pair’s reserves to update to the manipulated balances.

Phalcon’s breakdown analysis of the flow showed the attacker first executed a large USDT-to-LULA swap to inflate the pair’s USDT reserve, then repeatedly triggered the recycle() function to shrink the LULA reserve, before swapping a small amount of LULA back to drain the liquidity pool. 

Because the reserves no longer matched the real token balances, the attacker was able to extract value at a heavily skewed rate, a pattern seen earlier this year when the PancakeSwap LABUBU pool was exploited for $1.1 million through a similar reserve imbalance.

The vulnerable code shared by Phalcon showed that recycle() was restricted to the rental contract, calculated a maximum take equal to one-third of the pair’s LULA balance, and used an internal _basicTransfer() method to move tokens straight from the pair before syncing. That _basicTransfer() function simply adjusted balances and emitted a Transfer event, bypassing the checks a standard transfer would apply.

CertiK points to 12-day setup and $237M flash loan

CertiK, which flagged the same incident at a loss of roughly $578K, added that the attacker had prepared well in advance. In its analysis, the firm said the attacker deployed helper contracts to accumulate referral and team rewards 12 days before the exploit, then flashloaned around $237 million to swap out LULA in the decentralized exchange, maximizing the deflation through claimReward() and recycle().

The attack transaction is viewable on BscScan, and both TenArmor and CertiK linked to their respective explorer breakdowns through Phalcon Explorer and Skylens. The LULA token contract sits at 0x72ad494fda63d2b91b9d7290737e8ef1194a0c47 on BSC.

BSC remains a frequent target

The LULA incident adds to a long run of exploits hitting projects on Binance Smart Chain through 2026. In June, the BY token on BSC lost about $88,400 in a suspected exploit also flagged by TenArmor, while last week the 42DAO stablecoin BLC depegged to near zero after a $912K oracle exploit on BNB Chain.

The pattern fits the wider picture laid out in CertiK’s Hack3D report, which found Web3 lost more than $1.31 billion across 344 incidents in the first half of the year. Code vulnerability was the most prolific attack category with 204 incidents, and the firm flagged a growing trend of attackers revisiting older, previously deployed codebases.

The week of July 19 to 25 alone saw over $47 million in confirmed losses across protocols including AFX Trade, Wanchain, Verus, and Lien Finance, underscoring how relentless the current stretch of on-chain attacks has become.

Also Read: Crypto Hacks Cross $1.1B in Record H1 2026 Losses: Blockaid

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

44 State AGs Tell CFTC It Lacks Authority Over Sports Prediction Markets
44 State AGs Tell CFTC It Lacks Authority Over Sports Prediction Markets
Crypto DAO Drained for $8.2M on BNB Chain via Access-Control Bug
Crypto DAO Drained for $8.2M on BNB Chain via Access-Control Bug
Bitcoin Price Stalls Near $64K While Spot Trading Activity Collapses 75%
Bitcoin Price Stalls Near $64K While Spot Trading Activity Collapses 75%
Visa Details Full-Stack Stablecoin Strategy as Q3 Revenue Hits $11.6B
Visa Details Full-Stack Stablecoin Strategy as Q3 Revenue Hits $11.6B
Crypto Hacks Cross $1.1B in Record H1 2026 Losses Blockaid
Crypto Hacks Cross $1.1B in Record H1 2026 Losses: Blockaid

Find Us on Socials

You may also like

Strategy’s MSTR Stock Token Goes Live on Solana via Sunrise

Strategy’s MSTR Stock Token Goes Live on Solana via Sunrise

Why Is HOOD Stock Going Down Today Robinhood Falls 6%

Why Is HOOD Stock Going Down Today? Robinhood Falls 6%

Varo Hits $31.6M Volume Within First 14 Hours on Robinhood Chain

Varo Hits $31.6M Volume Within First 14 Hours on Robinhood Chain

Crypto Market Slumps Amid Clarity Act Vote Delay BTC, ETH Down 3%

Crypto Market Slumps Amid Clarity Act Vote Delay: BTC, ETH Down 3%

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information