PublicAML
← All reports

Contract exploit report VR-4690757D

Investigator report

Filed by a vetted PublicAML investigator rather than by an anonymous reader. The account itself has not been independently re-checked.

The addresses below carry a risk label from this report.

Type
Hack
Reported as
Contract exploit
Chain
bsc
Reported by
DenysInvestigator
Incident date
Jul 29, 2026
Published
Sep 9, 2026

What happened

LULA exploit on BNB Smart Chain, 29 July 2026, ~$578K lost. Reported by CertiK Alert; PublicAML read the addresses out of their call-trace screenshot and verified the contract types on-chain. Mechanism visible in the trace: a chain of contracts calls claimTeamReward() and claimReferralReward() on the LULA contract, which triggers recycle(amount = 5,466,425,413,399,659,914,651) and then LULA.transfer() payouts back to the callers. The privileged recycle() path is abused to mint rewards repeatedly. Addresses reported here, all with the same role β€” callers that received the drained LULA: 0x2a6Cf8592D1CC22BEd916481bb745ccAf80aE6F1 (received 5,335,604,142,729,676,918,919 LULA) 0xF60F0895301fdEF5f4795A8A6b57f5cb2A664E3c 0xFE2554A23b352dEC8A93aFD2DD463A453d8eE0CE 0xfD7eaBd41D826ADBA28Ef982BcC75AB1C679E4FA 0x6222155a9010Ec62dDe38e8E1606c7Bcd4Ce5897 0x296f885d55Fd78482e2bE4BC660518BE7E4d4481 (received 280,821,270,669,982,995,732 LULA) Verified via eth_getCode on BNB Smart Chain: the first five are minimal-proxy clones (48 bytes of code each) β€” disposable contracts deployed to repeat the reward claim. The last is an externally owned account. Deliberately NOT reported: 0x377a015f44C3FDf71060e94648EDC9e0316C7f1a appears in the same trace, but it carries 43,764 bytes of code and does not respond to name(). It may be protocol infrastructure rather than attacker-controlled, and we do not flag an address we cannot place with confidence. Source: https://x.com/CertiKAlert/status/2082309959484911845. Filed by PublicAML from public reporting plus our own on-chain verification, not by a victim of the incident.

Addresses named in this report

Named here and believe it is wrong? Open the address page above and use the flag on the assessment. Every dispute is read.

Contract exploit report VR-4690757D | PublicAML