Contract exploit report VR-4690757D
Investigator report
Filed by a vetted PublicAML investigator rather than by an anonymous reader. The account itself has not been independently re-checked.
The addresses below carry a risk label from this report.
- Type
- Hack
- Reported as
- Contract exploit
- Chain
- bsc
- Reported by
- DenysInvestigator
- Incident date
- Jul 29, 2026
- Published
- Sep 9, 2026
What happened
LULA exploit on BNB Smart Chain, 29 July 2026, ~$578K lost. Reported by CertiK Alert; PublicAML read the addresses out of their call-trace screenshot and verified the contract types on-chain. Mechanism visible in the trace: a chain of contracts calls claimTeamReward() and claimReferralReward() on the LULA contract, which triggers recycle(amount = 5,466,425,413,399,659,914,651) and then LULA.transfer() payouts back to the callers. The privileged recycle() path is abused to mint rewards repeatedly. Addresses reported here, all with the same role β callers that received the drained LULA: 0x2a6Cf8592D1CC22BEd916481bb745ccAf80aE6F1 (received 5,335,604,142,729,676,918,919 LULA) 0xF60F0895301fdEF5f4795A8A6b57f5cb2A664E3c 0xFE2554A23b352dEC8A93aFD2DD463A453d8eE0CE 0xfD7eaBd41D826ADBA28Ef982BcC75AB1C679E4FA 0x6222155a9010Ec62dDe38e8E1606c7Bcd4Ce5897 0x296f885d55Fd78482e2bE4BC660518BE7E4d4481 (received 280,821,270,669,982,995,732 LULA) Verified via eth_getCode on BNB Smart Chain: the first five are minimal-proxy clones (48 bytes of code each) β disposable contracts deployed to repeat the reward claim. The last is an externally owned account. Deliberately NOT reported: 0x377a015f44C3FDf71060e94648EDC9e0316C7f1a appears in the same trace, but it carries 43,764 bytes of code and does not respond to name(). It may be protocol infrastructure rather than attacker-controlled, and we do not flag an address we cannot place with confidence. Source: https://x.com/CertiKAlert/status/2082309959484911845. Filed by PublicAML from public reporting plus our own on-chain verification, not by a victim of the incident.
Addresses named in this report
- 0x2a6Cf8592D1CC22BEd916481bb745ccAf80aE6F1
- 0xF60F0895301fdEF5f4795A8A6b57f5cb2A664E3c
- 0xFE2554A23b352dEC8A93aFD2DD463A453d8eE0CE
- 0xfD7eaBd41D826ADBA28Ef982BcC75AB1C679E4FA
- 0x6222155a9010Ec62dDe38e8E1606c7Bcd4Ce5897
- 0x296f885d55Fd78482e2bE4BC660518BE7E4d4481
Named here and believe it is wrong? Open the address page above and use the flag on the assessment. Every dispute is read.
