Incident case file
Sign in to watchZentra Finance Citrea repayWithATokens Rounding Exploit — $140K
0 views
Estimated loss
Affected users
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatOn September 9, 2026 at 12:59:37 UTC, an attacker exploited an accounting edge case in Zentra Finance's repayWithATokens function on Citrea. The attacker used a flash liquidity injection of approximately 200,000 USDC.e as temporary collateral, exploiting the fact that debt could be marked complete while the aToken burn simultaneously reduced the position to zero, extracting 140,000 ctUSD plus 30 USDC.e for a total of $140,030. Zentra's operations multisig paused all markets approximately 17 minutes after detection, preventing a second exploit attempt. Zentra Finance has officially confirmed it has never publicly disclosed the attacker's wallet address.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)