
Security firms said the LULA token on BNB Smart Chain was exploited in a PancakeSwap V2 reserve-manipulation attack using a privileged recycle() function, with losses estimated at about $578,000 to $578,100.
The LULA token on BNB Smart Chain appears to have been exploited for about $578,000 to $578,100 in a reserve-manipulation attack on its PancakeSwap V2 pool, according to TenArmor, BlockSec Phalcon and CertiK. The firms said the attacker abused a privileged recycle() function in the token’s smart contract to pull liquidity from the pair, distort recorded reserves and extract value. CertiK added that the attacker had prepared helper contracts 12 days earlier and used a flash loan of around $237 million to maximize the exploit.