LULA token exploit on BSC drains $578K via recycle() function; team demands 25% recovery within 36 hours or pursues legal action.
Security & Exploits ·
The LULA token team announced detection of a $578,000 exploit affecting its BSC contract, specifically targeting the recycle() function and liquidity pools on PancakeSwap V2. The team issued a 36-hour ultimatum, requesting return of at least 25% of stolen funds—approximately $144,500 in USDT or BNB—to a designated wallet address.
The mechanism of the exploit centered on abuse of the recycle() function within the Rental/LULA smart contract, which allowed the attacker to drain tokens from the BSC-USD/LULA pool. The team framed the recovery demand as a test of good faith, offering to forgo legal recourse if the partial restitution arrived within the deadline.
Beyond the initial 36-hour window, the team stated it would escalate to formal legal proceedings, including law enforcement collaboration, exchange reports, and on-chain investigation. What remains unclear is whether the attacker has been identified, whether any funds were recovered after the deadline passed, and what specific vulnerability in the recycle() function enabled the drain.