LULA token contract on BSC exploited via recycle() function for $578K; team demands 25% return ($144.5K) within 22 hours to avoid legal action.
Security & Exploits ·
The LULA token contract on the Binance Smart Chain has been exploited via a vulnerability in the recycle() function, resulting in the loss of approximately $578,000 worth of tokens. The attack targeted the Rental/LULA contract and drained liquidity from the PancakeSwap V2 BSC-USD/LULA pool. The team behind LULA issued an on-chain message demanding the return of at least 25% of the stolen funds—approximately $144,500 in USDT or BNB—to a specified wallet address within 22 hours.
The team framed the partial recovery demand as a test of good faith, threatening to pursue legal action if the condition was not met by the deadline. The specific vulnerability exploited, the recycle() function, enabled attackers to drain tokens from the liquidity pool. The receiving address involved in the exploit has been identified on-chain.
It remains unclear whether the 22-hour deadline was met, whether any funds were recovered, or what actions the LULA team has taken following the expiration of the ultimatum. The technical details of how the recycle() function could be weaponized to drain liquidity have not been disclosed.