T
iTokenly

Zentra Finance (ctUSD reserve) hack — September 2026

Verified — 4 sourcesLast checked September 15, 2026

Incident facts

Date of incident
Target typeLending protocol
Loss$143,000Price at time of incident
MethodContract logic errorIn Zentra's Aave V3 fork, repayWithATokens could clear a borrower's debt while the matching aToken burn was clamped to zero, so the reserve received nothing for the debt it wrote off
ChainsOther
OutcomeUnresolved

What happened

Zentra Finance, a lending protocol on Citrea, a bitcoin rollup, lost about $143,000 from its ctUSD reserve at 12:59:37 UTC on 9 September 2026, in a single transaction. The attacker took about 140,000 ctUSD and 30 USDC.e.

Zentra's lending core is a fork of Aave V3. Its post-mortem of 11 September says the Pool, aToken and debt-token paths could reach inconsistent results during repayWithATokens: in one edge case the debt was cleared while the matching aToken burn was reduced to zero, so the reserve received nothing for the debt it wrote off. A proof of concept submitted to DeFiHackLabs reproduces the attack: flash-borrow 200,000 USDC.e, post it as collateral, borrow ctUSD, then repay with aTokens one base unit above the debt while holding none, so a safeguard meant to absorb one-wei rounding clamps the burn to nothing.

Zentra suspended its lending markets, traced the funds to a wallet, offered a negotiable bounty and set a deadline of 12:00 UTC on 14 September, after which it said it would pursue technical, on-chain and legal measures. No return had been reported by 15 September. In the meantime Zentra said it would temporarily cut every zctUSD holder's balance by 10.2%, which puts the loss on the reserve's depositors until it finds a better fix.

The amount is Zentra's own figure. The stolen token count, at a dollar each, gives about $140,030, which is kept as the low end.

Sources

  1. The Crypto TimesSecondary · retrieved 2026-09-15
  2. Crypto EconomySecondary · retrieved 2026-09-15
  3. LivecoinsSecondary · retrieved 2026-09-15
  4. DeFiHackLabs, proof of concept (pull request 1250)Secondary · retrieved 2026-09-15

Changes to this entry

  • Recorded six days after the incident. The amount is Zentra's own figure of about $143,000; the stolen token count, about 140,000 ctUSD and 30 USDC.e at a dollar each, gives $140,030 and is kept as the low end. The 14 September return deadline passed with no return reported.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Zentra Finance (ctUSD reserve) hack — September 2026", iTokenly, accessed 2026-09-15, https://itokenly.com/hacks/zentra-finance-ctusd
https://itokenly.com/hacks/zentra-finance-ctusd

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.