The LULA token on Binance Smart Chain has been exploited for approximately $578,000 in a reserve manipulation attack, with the attacker abusing a privileged recycle() function embedded in the token’s smart contract to pull liquidity directly out of the PancakeSwap V2 pair.
Blockchain security firm TenArmor was the first to flag the incident, followed by detailed breakdowns from BlockSec Phalcon and CertiK on July 29.
TenArmor reported the attack in a post on X, stating that its system detected a suspicious attack involving the LULA token on BSC that resulted in an approximate loss of $578.1K. The firm shared the attack transaction and pointed to a series of on-chain transfers that moved value out of the protocol before it was detected.
How the attack unfolded
According to BlockSec Phalcon, the exploit hinged on a reserve manipulation involving the token’s recycle() function. The function allowed the Rental contract to transfer LULA directly out of the PancakeSwap V2 pair and then call sync(), forcing the pair’s reserves to update to the manipulated balances.
Phalcon’s breakdown analysis of the flow showed the attacker first executed a large USDT-to-LULA swap to inflate the pair’s USDT reserve, then repeatedly triggered the recycle() function to shrink the LULA reserve, before swapping a small amount of LULA back to drain the liquidity pool.
Because the reserves no longer matched the real token balances, the attacker was able to extract value at a heavily skewed rate, a pattern seen earlier this year when the PancakeSwap LABUBU pool was exploited for $1.1 million through a similar reserve imbalance.
The vulnerable code shared by Phalcon showed that recycle() was restricted to the rental contract, calculated a maximum take equal to one-third of the pair’s LULA balance, and used an internal _basicTransfer() method to move tokens straight from the pair before syncing. That _basicTransfer() function simply adjusted balances and emitted a Transfer event, bypassing the checks a standard transfer would apply.
CertiK points to 12-day setup and $237M flash loan
CertiK, which flagged the same incident at a loss of roughly $578K, added that the attacker had prepared well in advance. In its analysis, the firm said the attacker deployed helper contracts to accumulate referral and team rewards 12 days before the exploit, then flashloaned around $237 million to swap out LULA in the decentralized exchange, maximizing the deflation through claimReward() and recycle().
The attack transaction is viewable on BscScan, and both TenArmor and CertiK linked to their respective explorer breakdowns through Phalcon Explorer and Skylens. The LULA token contract sits at 0x72ad494fda63d2b91b9d7290737e8ef1194a0c47 on BSC.
BSC remains a frequent target
The LULA incident adds to a long run of exploits hitting projects on Binance Smart Chain through 2026. In June, the BY token on BSC lost about $88,400 in a suspected exploit also flagged by TenArmor, while last week the 42DAO stablecoin BLC depegged to near zero after a $912K oracle exploit on BNB Chain.
The pattern fits the wider picture laid out in CertiK’s Hack3D report, which found Web3 lost more than $1.31 billion across 344 incidents in the first half of the year. Code vulnerability was the most prolific attack category with 204 incidents, and the firm flagged a growing trend of attackers revisiting older, previously deployed codebases.
The week of July 19 to 25 alone saw over $47 million in confirmed losses across protocols including AFX Trade, Wanchain, Verus, and Lien Finance, underscoring how relentless the current stretch of on-chain attacks has become.
Also Read: Crypto Hacks Cross $1.1B in Record H1 2026 Losses: Blockaid
