The LULA token was targeted in a reserve-manipulation exploit on BNB Smart Chain, with blockchain security firms estimating the resulting loss at approximately $578,000. TenArmor first reported detecting a suspicious transaction involving LULA and placed the estimated loss at $578,100, before BlockSec Phalcon and CertiK published additional analyses of the incident on July 29, 2026.
The security firms linked their findings to an identifiable BNB Smart Chain transaction and the LULA token contract. The public alerts provide stronger confirmation than the initial third-party reporting.
We have seen a ~$578K exploit on $LULA. https://t.co/tF5DUsRxmy
Attacker deployed helpers to accumulate referral/team rewards 12 days ago, flashloaned ~$237M to swap out LULA in DEX, to maximize the deflation by claimReward() -> recycle().
Stay Vigilant! pic.twitter.com/n1tSMZtNf7
— CertiK Alert (@CertiKAlert) July 29, 2026
Reserve Changes Distorted the Pool’s Pricing
According to BlockSec Phalcon, the attack centered on a privileged function called recycle() that could remove LULA from its PancakeSwap V2 liquidity pair and then synchronize the pool’s recorded reserves. Changing the token balance before calling the pool’s synchronization function allowed the contract to recalculate prices using manipulated reserves.
Phalcon said the attacker first executed a large USDT-to-LULA trade, increasing the USDT side of the pool. The attacker then repeatedly invoked the recycling mechanism to reduce the LULA reserve before trading a comparatively small quantity of LULA back into the pool. The sequence created an artificial reserve imbalance that allowed value to be withdrawn at a heavily distorted exchange rate.
ALERT! The $LULA token on BSC was exploited for approximately $578K through a reserve manipulation involving its privileged recycle() function. The function allows the Rental contract to transfer $LULA directly out of the PancakeSwap V2 pair and then invoke function sync(),… pic.twitter.com/3tgW1VKcum
— BlockSec Phalcon (@Phalcon_xyz) July 29, 2026
The reported weakness was therefore not simply that the attacker possessed substantial temporary capital. The flash loan amplified a pricing flaw created by the token’s own reserve-adjustment mechanics, enabling the operator to scale the attack within a tightly coordinated transaction sequence. Without the underlying contract behavior, access to a large flash loan would not independently have created the same withdrawal route.
CertiK said the attacker borrowed approximately $237 million through a flash loan and used the capital to acquire LULA while maximizing the effects of the claimReward() and recycle() functions. The $237 million figure represents temporary borrowed liquidity, not the value ultimately removed from the pool, which security firms estimated at roughly $578,000. Flash loans must generally be repaid before the transaction concludes or the entire operation is reversed.
CertiK’s analysis also indicated that the operation may have required preparation well before the final transaction. The firm said helper contracts were deployed 12 days earlier to accumulate referral and team rewards. That timeline suggests a planned exploitation strategy rather than an opportunistic reaction to a momentary market movement, although the identity of the operator remains unknown.
Project Response and Final Loss Remain Unconfirmed
The alerts do not establish whether the vulnerable functionality has been disabled, whether liquidity has been restored or whether the attacker’s assets have been traced to an exchange or other destination. No confirmed recovery, contract suspension or reimbursement plan has been published in the reviewed source set. The estimated loss should consequently remain attributed to the security firms until the project releases its own accounting.
It is also unclear whether the incident affected assets outside the targeted PancakeSwap liquidity pool. The evidence currently supports describing the event as a token-contract and liquidity-pool exploit, not a compromise of PancakeSwap or BNB Smart Chain itself. The wider network continued processing transactions, while the reported weakness was associated with LULA-specific contract behavior.
The incident demonstrates how token functions that can alter decentralized-exchange balances may create risks beyond conventional transfer logic. A function may be access-restricted and still become economically exploitable when it can change pool reserves before a price synchronization. Privileged balance-management functions require analysis of their market effects, not only checks on which address is permitted to call them.
The strongest supported conclusion is that several independent security-monitoring firms identified the same LULA transaction and attributed approximately $578,000 in losses to reserve manipulation amplified by a large flash loan. The attack mechanism has received direct technical attribution, but its final financial impact and the project’s response remain pending.
