← Radar

Incident case file

Sign in to watch

Zentra Finance Citrea repayWithATokens Rounding Exploit — $140K

Incident date Sep 8, 2026Last updated Sep 24, 2026

0 views

ContainedCitreaRounding/accounting edge caseCluster: ZENTRA-CITREA-2026-09

Estimated loss

$140.0K

Affected users

Number of affected users is not confirmed
Group joining is coming soon.

Investigation

65%

Facts and investigation

Ledger

Attacker

TODO

Funds moved to

TODO — no attacker address publicly disclosed.

Linked

Zentra Finance's own team publicly confirmed the wallet address was never released, contrary to a false address invented in one third-party AI-generated report.

Chronology

1 beat
  1. On September 9, 2026 at 12:59:37 UTC, an attacker exploited an accounting edge case in Zentra Finance's repayWithATokens function on Citrea. The attacker used a flash liquidity injection of approximately 200,000 USDC.e as temporary collateral, exploiting the fact that debt could be marked complete while the aToken burn simultaneously reduced the position to zero, extracting 140,000 ctUSD plus 30 USDC.e for a total of $140,030. Zentra's operations multisig paused all markets approximately 17 minutes after detection, preventing a second exploit attempt. Zentra Finance has officially confirmed it has never publicly disclosed the attacker's wallet address.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)