PublicAML

Zentra Finance Exploited for $140,030 via Flash Loan Attack

Zentra Finance suffered a loss of $140,030 due to a single transaction exploit. The attack involved using flash liquidity to drain funds from the lending pool.

On September 9, 2026, an attacker exploited a vulnerability in Zentra Finance, resulting in the loss of 140,000 ctUSD and 30 USDC.e from its lending pool. The attack was executed using a single transaction on the Citrea mainnet, leveraging approximately 200,000 USDC.e of flash liquidity as temporary collateral. The root cause of the incident was identified as an accounting edge case in the repayWithATokens function, where the debt path could complete while the corresponding aToken burn was reduced to zero.

Following the exploit, the operations multisig took action by pausing all markets approximately 17 minutes later to prevent further losses. No additional exploits were reported after the initial incident. The specific chain involved in the attack was not stated, but the use of flash liquidity indicates a sophisticated approach to manipulating the lending pool's mechanics.

The on-chain record reflects the transaction details, but specific addresses were not provided in the description. The incident highlights the need for robust accounting mechanisms to prevent similar vulnerabilities in decentralized finance platforms.

Sources

Share:XTelegramLinkedIn
Zentra Finance Exploited for $140,030 via Flash Loan Attack | PublicAML