Zentra Finance exploited for $143K on the Citrea network.
Security & Exploits ·
On September 9, 2026, an attacker executed a flash loan exploit against Zentra Finance on the Citrea network, extracting 140,000 ctUSD and 30 USDC.e from the platform's lending pool in a single transaction at block 12428145. The attacker deployed a custom contract without prior test runs, borrowed ctUSD using 200,000 USDC.e in temporary flash liquidity, then repaid the debt using a calculation that exploited rounding behavior to avoid burning the required collateral tokens. The total value targeted in the incident reached approximately $143K.
The vulnerability stemmed from a specific flaw in Zentra's aToken accounting—separate from a known rounding issue in upstream Aave V3 versions disclosed in March 2026. When repaying debt via repayWithATokens, the aToken burn operation could reduce to zero if the caller held no aTokens, yet the Pool still treated the repayment as valid, enabling the attacker to withdraw collateral while retaining borrowed assets. Zentra's own post-mortem analysis identified the attack sequence and confirmed the exploit targeted token accounting logic, not Citrea's protocol or bridge infrastructure.
The operations multisig paused all reserves, revenue distribution, and superstaking 16 minutes and 50 seconds after the exploit. Zentra plans a one-time proportional balance adjustment of approximately 10.19% to affected zctUSD holders, with restart targeted for September 15, 2026, following independent review and a two-day timelock. The platform offered a negotiable bounty to the attacker's address with a September 14 deadline and indicated plans to escalate through technical and legal channels if funds remain unreturned.