← LULA Token (BSC Reserve Manipulation Exploit)1 decision on this page
Audit log
Every state-changing event for LULA Token (BSC Reserve Manipulation Exploit): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-07-30 12:06:19ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
Gs19CXGu3zYE…9dsHGjVfsha256 → base58
verifying row…canonical bytes (15657 B) ▸
{"actor":"system:backfill","investigation_id":"3449259e-7976-4555-98b7-9d9f4667e474","kind":"publish","page_slug":"lula-token-bsc-reserve-manipulation-exploit","published_at":"2026-07-30T12:06:19.555Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"LULA Token (BSC Reserve Manipulation Exploit)","sections":[{"content":"On July 29, 2026, an attacker drained approximately $578,100 from the LULA token's PancakeSwap V2 liquidity pool on Binance Smart Chain in a reserve manipulation attack. TenArmor was the first security firm to publicly flag the incident, reporting that its monitoring system detected a suspicious attack involving the LULA token on BSC resulting in an approximate loss of $578.1K. Detailed technical breakdowns were subsequently published by BlockSec Phalcon and CertiK on the same day. The exploit is classified as a reserve manipulation attack — a category of vulnerability in which an attacker manipulates the internal reserve accounting of an automated market maker (AMM) pair to extract funds at artificially favorable rates.","heading":"Exploit Overview","severity":"critical","sources":[{"credibility":2,"name":"LULA Token on BSC Exploited for $578K in Reserve Manipulation Attack — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/29/lula-token-on-bsc-exploited-for-578k-in-reserve-manipulation-attack/"}]},{"content":"According to BlockSec Phalcon, the exploit centered on the LULA token contract's recycle() function, which used an internal _basicTransfer() method that adjusted token balances and emitted a Transfer event while bypassing the checks a standard ERC-20 transfer would apply. This allowed the Rental contract — a privileged contract within the LULA system — to transfer LULA tokens directly out of the PancakeSwap V2 LULA/USDT pair address without the pair's knowledge. After removing tokens from the pair, the attacker called sync() on the PancakeSwap V2 pair, which forced the pair to accept the new, artificially deflated LULA reserve as its canonical state. CertiK identified that the attacker flash-loaned approximately $237 million to swap out LULA from the decentralized exchange, maximizing reserve deflation through both the claimReward() and recycle() functions. The full attack flow as reconstructed by Phalcon proceeded as follows: (1) the attacker executed a large USDT-to-LULA swap to inflate the pair's USDT reserve; (2) the attacker repeatedly triggered recycle() to shrink the LULA reserve; (3) the attacker called sync() to commit the manipulated balances to the pair's state; and (4) the attacker swapped a small amount of LULA back to drain liquidity at heavily skewed exchange rates. The $237 million flash loan was used to amplify the scale of the initial USDT-to-LULA swap, maximizing the reserve imbalance and therefore the profit extractable in step four.","heading":"Attack Mechanics","severity":"critical","sources":[{"credibility":2,"name":"LULA Token on BSC Exploited for $578K in Reserve Manipulation Attack — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/29/lula-token-on-bsc-exploited-for-578k-in-reserve-manipulation-attack/"}]},{"content":"CertiK's analysis identified a 12-day preparation period preceding the July 29 attack. During this window, the attacker allegedly deployed helper contracts designed to accumulate referral and team rewards within the LULA protocol. This premeditated accumulation phase suggests the attacker performed deliberate reconnaissance of the protocol's reward distribution mechanics before executing the exploit. The 12-day setup period, combined with the large flash loan and multi-step execution, indicates a sophisticated, planned attack rather than an opportunistic one.","heading":"Pre-Attack Preparation","severity":"high","sources":[{"credibility":2,"name":"LULA Token on BSC Exploited for $578K in Reserve Manipulation Attack — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/29/lula-token-on-bsc-exploited-for-578k-in-reserve-manipulation-attack/"}]},{"content":"Three independent blockchain security firms confirmed the exploit mechanics. TenArmor issued the initial public alert via X (formerly Twitter), stating its system detected a suspicious attack involving the LULA token on BSC that resulted in an approximate loss of $578.1K. BlockSec Phalcon published a technical breakdown of the reserve manipulation mechanism, detailing the recycle() and sync() function interaction and noting that the _basicTransfer() method bypassed standard transfer protections. CertiK independently confirmed the attack, identified the $237 million flash loan, and flagged the 12-day preparation window involving reward-accumulation contracts. On-chain transaction data was viewable on BscScan, and attack flow visualizations were available via Phalcon Explorer and CertiK's Skylens tool.","heading":"Security Firm Confirmations","severity":"high","sources":[{"credibility":2,"name":"LULA Token on BSC Exploited for $578K in Reserve Manipulation Attack — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/29/lula-token-on-bsc-exploited-for-578k-in-reserve-manipulation-attack/"},{"credibility":2,"name":"BlockSec Phalcon Explorer — Transaction Analysis Tool","type":"research","url":"https://blocksec.com/phalcon/explorer"},{"credibility":2,"name":"CertiK — Blockchain Security Firm","type":"research","url":"https://www.certik.com/"}]},{"content":"The exploited LULA token carries the BEP-20 contract address 0x72ad494fda63d2b91b9d7290737e8ef1194a0c47 on Binance Smart Chain. As of available data, the token had only approximately 8 recorded holders, indicating an extremely low adoption and liquidity profile relative to the $578K drained. The minimal holder count suggests the liquidity pool was the primary repository of value associated with this token at the time of the exploit. No verified official project website, whitepaper, or team information was identified in available sources. The token's BscScan page and exploit-related transaction hashes — including 0xef6a9a9b4c50bb1c8bc60d6b75bcf9be1fc08e2c92d6484943c9f62b4fa78902, 0xbd2f1bca392b0e13ee5ddbf6497490203837d158ae3634ae640449d7d700fb47, and 0x8f9a6db646d6bc402c02a29d750e484424940778aa6b328121db4f6dd83e2c20 — are publicly viewable on BscScan.","heading":"Token Contract and On-Chain Footprint","severity":"high","sources":[{"credibility":3,"name":"LULA COIN (LULA) Price and Market Stats — TheBitTimes","type":"on_chain","url":"https://thebittimes.com/token-LULA-BSC-0x72ad494fda63d2b91b9d7290737e8ef1194a0c47.html"},{"credibility":1,"name":"BscScan Transaction 0xef6a9a...","type":"on_chain","url":"https://bscscan.com/tx/0xef6a9a9b4c50bb1c8bc60d6b75bcf9be1fc08e2c92d6484943c9f62b4fa78902"},{"credibility":1,"name":"BscScan Transaction 0xbd2f1b...","type":"on_chain","url":"https://bscscan.com/tx/0xbd2f1bca392b0e13ee5ddbf6497490203837d158ae3634ae640449d7d700fb47"},{"credibility":1,"name":"BscScan Transaction 0x8f9a6d...","type":"on_chain","url":"https://bscscan.com/tx/0x8f9a6db646d6bc402c02a29d750e484424940778aa6b328121db4f6dd83e2c20"}]},{"content":"The LULA exploit is part of a documented pattern of reserve manipulation attacks targeting BEP-20 tokens on Binance Smart Chain throughout 2026. Several similar incidents were reported in the months preceding the LULA attack. In June 2026, the JB token on BNB Chain was exploited using a structurally identical mechanism: a privileged contract function burned JB tokens directly from the PancakeSwap V2 pair address and called sync() to force the pair to accept deflated reserves, enabling the attacker to repeatedly extract USDT across sixteen sell cycles. In June 2026, the DLMC token on BNB Chain lost approximately $222,600 in a flash loan exploit that also abused internal price calculation and reward distribution mechanics. The AIDC token lost approximately $121,000 in a burn-bug exploit draining its PancakeSwap pool in the same month. In April 2026, the LML protocol on BSC was hit for approximately $950,000 in a price manipulation attack targeting its staking pool. These incidents collectively reflect a systemic vulnerability class: BEP-20 token contracts that grant privileged access to pair reserve accounting without adequate separation from AMM safety invariants.","heading":"Broader Pattern: BSC Reserve Manipulation Attacks in 2026","severity":"medium","sources":[{"credibility":2,"name":"JB Token Pair-Burn Reserve Manipulation — DARKNAVY Blog","type":"research","url":"https://www.darknavy.org/web3/exploits/jb-token-pair-burn-reserve-manipulation/"},{"credibility":2,"name":"DLMC Token on BNB Chain Loses Approximately $222,600 in Flash Loan Exploit — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/06/25/dlmc-token-on-bnb-chain-loses-approximately-222600-in-flash-loan-exploit/"},{"credibility":2,"name":"AIDC Token Burn Bug Exploit Drains $121K From PancakeSwap — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/06/29/aidc-token-burn-bug-exploit-drains-121k-from-pancakeswap/"},{"credibility":2,"name":"LML Protocol Hit by $950K Price Manipulation in BSC Staking Pool — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/04/01/lml-protocol-bsc-staking/"}]},{"content":"No verified official website, whitepaper, named team, or audit history for the LULA token (contract 0x72ad494fda63d2b91b9d7290737e8ef1194a0c47) was identified in available sources. A separate token also named LulaCoin (contract 0xa13a91b3675bF74d6D3ca0A7F36aA5f1f6DBAABb) exists on BSC and appears to be a distinct project with social media presence under the handle @lulacoinbrasil, described as a socioeconomic tool for local development in Brazil; this project should not be conflated with the exploited token. The exploited LULA contract had only approximately 8 holders at time of the attack and no publicly documented development team, which significantly limits independent verification of the project's origins or intent. The absence of a security audit and the presence of a privileged function (recycle()) with direct pair-transfer capability and no standard transfer guards constitute serious pre-existing risk factors.","heading":"Project Background and Transparency","severity":"high","sources":[{"credibility":3,"name":"LULA COIN (LULA) Price and Market Stats — TheBitTimes","type":"on_chain","url":"https://thebittimes.com/token-LULA-BSC-0x72ad494fda63d2b91b9d7290737e8ef1194a0c47.html"},{"credibility":3,"name":"LulaCoin Token — Binplorer","type":"other","url":"https://binplorer.com/address/0xa13a91b3675bf74d6d3ca0a7f36aa5f1f6dbaabb"}]}],"sources_used":[{"credibility":2,"name":"LULA Token on BSC Exploited for $578K in Reserve Manipulation Attack — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/29/lula-token-on-bsc-exploited-for-578k-in-reserve-manipulation-attack/"},{"credibility":2,"name":"JB Token Pair-Burn Reserve Manipulation — DARKNAVY Blog","type":"research","url":"https://www.darknavy.org/web3/exploits/jb-token-pair-burn-reserve-manipulation/"},{"credibility":2,"name":"DLMC Token on BNB Chain Loses Approximately $222,600 in Flash Loan Exploit — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/06/25/dlmc-token-on-bnb-chain-loses-approximately-222600-in-flash-loan-exploit/"},{"credibility":2,"name":"AIDC Token Burn Bug Exploit Drains $121K From PancakeSwap — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/06/29/aidc-token-burn-bug-exploit-drains-121k-from-pancakeswap/"},{"credibility":2,"name":"LML Protocol Hit by $950K Price Manipulation in BSC Staking Pool — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/04/01/lml-protocol-bsc-staking/"},{"credibility":3,"name":"LULA COIN (LULA) Price and Market Stats — TheBitTimes","type":"on_chain","url":"https://thebittimes.com/token-LULA-BSC-0x72ad494fda63d2b91b9d7290737e8ef1194a0c47.html"},{"credibility":1,"name":"BscScan Transaction 0xef6a9a9b4c50bb1c8bc60d6b75bcf9be1fc08e2c92d6484943c9f62b4fa78902","type":"on_chain","url":"https://bscscan.com/tx/0xef6a9a9b4c50bb1c8bc60d6b75bcf9be1fc08e2c92d6484943c9f62b4fa78902"},{"credibility":1,"name":"BscScan Transaction 0xbd2f1bca392b0e13ee5ddbf6497490203837d158ae3634ae640449d7d700fb47","type":"on_chain","url":"https://bscscan.com/tx/0xbd2f1bca392b0e13ee5ddbf6497490203837d158ae3634ae640449d7d700fb47"},{"credibility":1,"name":"BscScan Transaction 0x8f9a6db646d6bc402c02a29d750e484424940778aa6b328121db4f6dd83e2c20","type":"on_chain","url":"https://bscscan.com/tx/0x8f9a6db646d6bc402c02a29d750e484424940778aa6b328121db4f6dd83e2c20"},{"credibility":2,"name":"BlockSec Phalcon Explorer","type":"research","url":"https://blocksec.com/phalcon/explorer"},{"credibility":2,"name":"CertiK — Blockchain Security Firm","type":"research","url":"https://www.certik.com/"},{"credibility":3,"name":"LulaCoin Token — Binplorer (separate contract, for disambiguation)","type":"other","url":"https://binplorer.com/address/0xa13a91b3675bf74d6d3ca0a7f36aa5f1f6dbaabb"}],"summary":"LULA Token (contract 0x72ad494fda63d2b91b9d7290737e8ef1194a0c47) is a BEP-20 token deployed on Binance Smart Chain that was exploited on July 29, 2026 for approximately $578,000 in a reserve manipulation attack. The attacker abused the token's recycle() function to drain the PancakeSwap V2 liquidity pair and called sync() to force reserves to attacker-controlled values, leveraging a $237 million flash loan after 12 days of on-chain preparation. Three independent blockchain security firms — TenArmor, BlockSec Phalcon, and CertiK — confirmed the exploit mechanics.","timeline":[{"date":"2026-07-17","event":"Alleged start of 12-day preparation period: attacker reportedly deployed helper contracts to accumulate referral and team rewards within the LULA protocol ahead of the exploit (per CertiK analysis).","source":"CryptoTimes / CertiK","source_url":"https://www.cryptotimes.io/2026/07/29/lula-token-on-bsc-exploited-for-578k-in-reserve-manipulation-attack/"},{"date":"2026-07-29","event":"Attacker executed the reserve manipulation exploit against the LULA token PancakeSwap V2 pair on BSC, draining approximately $578,100 using a $237 million flash loan and abusing the recycle() and claimReward() functions combined with a sync() call to commit manipulated reserves.","source":"CryptoTimes / TenArmor / BlockSec Phalcon / CertiK","source_url":"https://www.cryptotimes.io/2026/07/29/lula-token-on-bsc-exploited-for-578k-in-reserve-manipulation-attack/"},{"date":"2026-07-29","event":"TenArmor published the first public alert on X, reporting approximately $578.1K lost in a suspicious LULA token attack on BSC.","source":"TenArmor via CryptoTimes","source_url":"https://www.cryptotimes.io/2026/07/29/lula-token-on-bsc-exploited-for-578k-in-reserve-manipulation-attack/"},{"date":"2026-07-29","event":"BlockSec Phalcon published a technical breakdown of the exploit, detailing the recycle() and sync() reserve manipulation mechanism and the _basicTransfer() bypass.","source":"BlockSec Phalcon via CryptoTimes","source_url":"https://www.cryptotimes.io/2026/07/29/lula-token-on-bsc-exploited-for-578k-in-reserve-manipulation-attack/"},{"date":"2026-07-29","event":"CertiK independently confirmed the exploit, identified the $237 million flash loan, and documented the 12-day preparation period involving reward-accumulation contracts.","source":"CertiK via CryptoTimes","source_url":"https://www.cryptotimes.io/2026/07/29/lula-token-on-bsc-exploited-for-578k-in-reserve-manipulation-attack/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 3c2abdd4-563b-4e4f-a130-73d66283b23f
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.