LULA pool on PancakeSwap V2 loses $578K to reserve exploit
Security & Exploits ·
An attacker manipulated a privileged contract function to siphon funds from the LULA token pool on BSC, according to a security firm's analysis.
The exploit targeted a function called recycle(), which gave the Rental contract permission to pull LULA tokens directly out of the PancakeSwap V2 pair and then call sync() to reset the pool's reserve figures to reflect the altered balances. This privileged access became the entry point for the attack rather than a standard trading vulnerability.
The attacker's method involved a sequence of moves: first, a sizable USDT-to-LULA swap pushed up the pool's USDT reserve artificially; then recycle() was called multiple times to progressively reduce the LULA side of the reserve; finally, a modest LULA-to-USDT swap was executed to extract value from the now-imbalanced pool. The combination of inflating one reserve while shrinking the other created the conditions needed to drain liquidity with a comparatively small closing trade.
Total losses from the incident were placed at roughly $578,000. The LULA contract address on BSC has been identified in on-chain records tied to the exploited token.
Separate accounts within the same reporting cluster indicate that the project's team responded by setting a 36-hour deadline for the attacker to return 25 percent of the drained funds, warning that legal action would follow if the window passed without compliance. Two distinct sources have covered the incident, both describing the same recovery ultimatum and the same estimated loss figure.
What remains unclear is whether the attacker has responded to the recovery deadline, whether any funds have moved since the exploit, and if the underlying recycle() vulnerability has been patched or disclosed publicly by the project. No confirmation has emerged yet on law enforcement involvement or the current status of the drained assets.