LULA Hack
What happened
On July 28, 2026, the LULA token protocol on BNB Chain was exploited for approximately $578,100 through a price manipulation attack abusing the contract's recycle() function with a massive ~$237 million flash loan.
The attacker deployed helper accounts days in advance to accumulate referral and team reward allocations. They then executed an enormous flash loan (~$237M) to swap heavy amounts of USDT into LULA on PancakeSwap V2, inflating the liquidity pool's USDT reserves. By repeatedly calling the privileged recycle() function, which transfers LULA directly out of the PancakeSwap V2 pair and invokes sync() to force-update pool reserves, the attacker distorted the pool's asset ratios.
This enabled them to swap a small amount of LULA back to drain the liquidity pool and claim accumulated rewards via claimReward() and recycle(), netting ~$578K in profit.
Attack Transaction: 0xa219ab9d…411d7c
Protocol details
Evidence
- report @Phalcon_xyz incident report x.com
- report @CertiKAlert incident report x.com
- analysis DeFiLlama defillama.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.