LULA token contract exploited for $578k via recycle() function vulnerability on BSC; team offers 36-hour window for 25% fund recovery to avoid legal action.
Security & Exploits ·
LULA token experienced a $578,000 exploit on the Binance Smart Chain after attackers leveraged a vulnerability in the recycle() function within the Rental/LULA contract and drained funds from the PancakeSwap V2 BSC-USD/LULA liquidity pool. The LULA team announced the incident in an onchain message and set a 36-hour deadline for partial fund recovery.
The team offered a conditional settlement: if at least 25% of the stolen amount—approximately $144,500 in USDT or BNB—is returned to a designated address within 36 hours, they stated they would forgo legal action and treat the partial repayment as a gesture of good faith. The specific mechanics of the recycle() function vulnerability and how it was exploited remain unclear from the team's statement.
It is not yet known whether the attacker has responded to the offer, whether any funds have been recovered, or what steps the LULA team plans to take if the deadline passes without a satisfactory response. The team has not disclosed details about the vulnerability itself or any immediate remediation measures beyond the settlement offer.