TL;DR:
- An exploit targeting Zentra Finance’s ctUSD reserve on the Citrea network resulted in estimated losses of $143,000 on September 9th at 12:59:37 UTC.
- The platform paused all its lending markets and tracked the extracted funds to a specific wallet address.
- The team established a deadline until September 14th at 12:00 UTC to negotiate a bounty before undertaking legal and technical actions.
Lending protocol Zentra Finance confirmed the theft of approximately $143,000 from its ctUSD reserve on the Citrea mainnet following a security breach detected this week.
🚨@ZentraFinance on @citrea_xyz hacked for $143K https://t.co/H5AqXrPk8q pic.twitter.com/vJofKI9ayR
— Defimon Alerts (@DefimonAlerts) September 11, 2026
The technical team immediately suspended lending operations after identifying the breach. Protocol information indicates that this preventive measure will remain in effect while fund traceability efforts are completed and a review of the affected infrastructure is conducted.
The attack was executed with precision on September 9th, 2026, at 12:59:37 UTC. According to Zentra Finance’s report, the transaction involved was identified on the blockchain under hash 0x9ac5df7e93988cd977e4b1b0564f559ec3096db2fe1abdd97e45c348e3074aa1, with no direct impact observed in the protocol’s other liquidity pools so far.
The firm has not made public the details of the attack vector or the vulnerability exploited. Disclosed technical records suggest that the breach focused exclusively on the contract managing the synthetic asset reserve, ctUSD.
Fund Tracking and Ultimatum on the Citrea Network

Initial investigations concluded on September 11th with the identification of the wallet receiving the stolen capital. The entity requested the full return of resources to the treasury address 0x0A66f2D0c603A6E9C23b64Ea29525B7E6F5609B8.
In exchange for voluntary restitution, the developers offered a technical bug bounty subject to negotiation terms. The official communication specifies that if the responsible party accepts the agreement under the stipulated conditions, they will not face legal proceedings or investigations before competent authorities.
The deadline to issue a response expires on Monday, September 14th, 2026, at 12:00 UTC. According to warnings published by administrators, if no conciliation is reached by that date, the protocol will activate onchain forensic tracking mechanisms, technical coordination, and legal interventions.
The monetary reward could also be reallocated to compensate informants who provide verifiable leads about the incident. The channels enabled for this exchange encompass the designated address itself and the Blockscan Chat messaging platform.
The Zentra Finance event coincides with a series of recent breaches in the DeFi sector’s infrastructure. In past days, an attacker used ether.fi’s AtomicQueue system to create tokens without real backing and introduce fraudulent offers without breaching the main Liquid vault.
Likewise, the Symbiosis bridge infrastructure reported the anomalous issuance of 368.9 billion synthetic Bitcoin (syBTC), a fraction of which was liquidated for 4.39 WBTC on Uniswap V4 within Ethereum, while nearly 184.5 billion remained on BNB Chain at the time of publication.
The reactivation of lending contracts on Zentra Finance will depend on the final balance yielded by the security audit once the September 14th deadline has passed.





