LULA Hack

Reported loss $578K
BNB Chain
Improper Access Control

What happened

On July 28, 2026, the LULA token protocol on BNB Chain was exploited for approximately $578,100 through a price manipulation attack abusing the contract's recycle() function with a massive ~$237 million flash loan.

The attacker deployed helper accounts days in advance to accumulate referral and team reward allocations. They then executed an enormous flash loan (~$237M) to swap heavy amounts of USDT into LULA on PancakeSwap V2, inflating the liquidity pool's USDT reserves. By repeatedly calling the privileged recycle() function, which transfers LULA directly out of the PancakeSwap V2 pair and invokes sync() to force-update pool reserves, the attacker distorted the pool's asset ratios.

This enabled them to swap a small amount of LULA back to drain the liquidity pool and claim accumulated rewards via claimReward() and recycle(), netting ~$578K in profit.

Attack Transaction: 0xa219ab9d…411d7c

Protocol details

Classification Access Control / Token
Protocol Type Exploit/Flash Loan Attack
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.