Key Highlights
- Zentra Finance reported an exploit involving its ctUSD reserve on Citrea Mainnet, resulting in about $143,000 in losses.
- The incident occurred on September 9 at 12:59:37 UTC, according to Zentra’s post-mortem.
- Zentra’s lending markets remain suspended following the incident.
Zentra Finance has reported an exploit involving its ctUSD reserve on Citrea Mainnet, with the protocol estimating losses at approximately $143,000.
According to a post-mortem published September 11, the incident occurred at 12:59:37 UTC on September 9. Zentra subsequently paused its lending markets while assessing the affected system and tracing the funds.
The protocol has not disclosed the specific vulnerability or attack method and has not publicly identified the wallet holder.
ctUSD reserve affected
The incident involved Zentra’s ctUSD reserve on Citrea Mainnet.
The protocol identified the transaction associated with the exploit as:
0x9ac5df7e93988cd977e4b1b0564f559ec3096db2fe1abdd97e45c348e3074aa1
Zentra has not indicated that other reserves were affected.
The project has also not provided a detailed technical explanation of how the reserve was compromised.
Exploited funds traced to wallet
On September 11, Zentra said its investigation had traced the affected funds to a specific wallet.
The protocol asked the wallet holder to return the assets to:
0x0A66f2D0c603A6E9C23b64Ea29525B7E6F5609B8
Zentra said it was offering a bounty for the return of the funds, with the terms to be negotiated.
It added that the wallet holder would not face legal or investigative action if the assets were returned under the agreed conditions.
September 14 deadline set
Zentra has set September 14, 2026, at 12:00 UTC as the deadline for the wallet holder to respond.
The protocol said communication could take place through the designated onchain address and that it was monitoring Blockscan Chat as another possible channel.
If no response is received by the deadline, Zentra said it may pursue technical, onchain and legal measures.
The bounty could also be used to compensate verified informants if the funds are not recovered.
Zentra’s lending markets remain suspended following the exploit.
The protocol has not announced a reopening date or specified what changes will be required before services resume.
The project is continuing to assess the affected system while working to recover the funds.
Recent DeFi security incidents
The Zentra incident follows other recent attacks involving different components of decentralized finance infrastructure.
In a recent incident involving ether.fi’s legacy AtomicQueue system, an attacker reportedly created a worthless token and used it to make fraudulent offers. The underlying Liquid vault was not directly compromised.
Separately, an attacker targeting the Symbiosis Bridge reportedly minted approximately 368.9 billion synthetic Bitcoin (syBTC). Some of the tokens were subsequently sold for about 4.39 WBTC on Ethereum’s Uniswap V4, while roughly 184.5 billion syBTC remained on BNB Chain at the time of reporting.
These incidents involved different attack mechanisms and infrastructure, including token systems, bridges and supporting DeFi components.
Investigation continues
Zentra has disclosed the affected reserve, estimated losses, associated transaction and wallet containing the funds.
The protocol has not yet provided a full technical account of the exploit or confirmed whether the affected assets will be recovered.
The immediate deadline is September 14, when Zentra expects a response from the wallet holder. The status of the lending markets will depend on the outcome of the investigation and the project’s subsequent security assessment.
Also Read: Liquid Network Restarts After $320M Exploit; Adam Back Says LBTC Peg Will Be Covered
