Web3 Daily Exploits — 12 Sep 2026: Zentra ~$140k Citrea Drain + ORB Reentrancy

First public desk confirmation of Zentra’s 9 Sep ctUSD reserve drain on Citrea (~$140k official / ~$143k Defimon), a SlowMist-confirmed ~$32.6k ORB reentrancy on BNB Chain, and a pending fake rollup assertion against Edgeless’s dormant L1 bridge (~9.2 ewETH at risk).

Web3 Daily Exploits — 12 Sep 2026: Zentra ~$140k Citrea Drain + ORB Reentrancy

Required monitors were checked through the 12 Sep 2026 America/Panama cutoff: DefimonAlerts, CertiKAlert, Phalcon, GoPlusSecurity, SlowMist_Team, PeckShieldAlert, BlockSecTeam, Lookonchain, ZachXBT, CyversAlerts, Immunefi, and rekt.news. Two confirmed protocol drains moved in this slice, plus one unfinished L1-bridge assertion that is not yet a withdrawal. Combined live loss scored on this card is approximately $173k: Zentra’s official reserve print of 140,000 ctUSD plus 30 USDC.e (~$140k; Defimon’s first public headline was $143k) and SlowMist’s $32,610.72 ORB figure. The Edgeless L1 bridge still holds ~9.2 ewETH (~$22.7k). That stack is at risk until block 25,999,225. It is not live loss.

Yesterday’s Symbiosis realized WBTC (~$336k), BeatXswap, ether.fi AtomicQueue, and OMNI404 items stay on the 11 Sep brief. They are not re-scored. Material updates in this window: Symbiosis said it recovered approximately 15 BTC onto a team multisig, kept the Bitcoin Bridge paused, and restated a 20% white-hat window through 13 Sep; Bitcoin swaps were routed through Chainflip and THORChain instead. Liquid’s unpaid ~598.5 BTC is unchanged. ZachXBT posted that both Revolut accounts had blocked him while he was checking a separate Revolut incident write-up; that is off-chain and unverified as a protocol drain. All dollar figures below are amounts still outside the affected party’s control unless a return transaction is cited.

Zentra Finance / ctUSD reserve — Citrea — Confirmed

What happened: At 14:17 UTC on 11 Sep 2026, Zentra published a post-mortem of a 9 Sep exploit against its Citrea money market. Defimon’s first public desk headline in the same minute called it a $143k hack. Official accounting: a single transaction at 12:59:37 UTC on 9 Sep removed 140,000 ctUSD and 30 USDC.e from the lending pool. The operations multisig paused all four reserves, revenue distribution, and superstaking at 13:16:27 UTC — 16 minutes and 50 seconds later. No second exploit occurred before the pause.

Protocol / chain / asset: Zentra Finance, a non-custodial money market on Citrea mainnet (Bitcoin Type-2 zkEVM, chainId 4114). Asset taken: ctUSD from the reserve, swapped on-chain to USDC.e and sent to a bridge. Citrea later said its own protocol and bridge contracts were not in the exploit path and restored selected asset routes on 9–10 Sep after a precautionary pause.

Loss: Official reserve-level print 140,000 ctUSD + 30 USDC.e. Defimon’s public headline: $143k. Card uses ~$140k from the project post-mortem and records $143k as the same-incident desk headline, not a second drain. Zentra later measured the ctUSD reserve shortfall at approximately 139,961 ctUSD against depositor claims. No return transaction was cited at cutoff. A planned ~10.19% proportional adjustment to zctUSD balances is a solvency patch, not a recovery of the stolen units.

Attack type: Lending-core accounting inconsistency on repayWithATokens. Debt-token path could complete while the matching aToken burn was reduced to zero. Zentra says the stack is Aave V3 Core v3.0.x–based, that a separate March 2026 upstream rounding class exists on pre-3.5 Aave V3, and that this transaction used a different boundary in the deployed token accounting rather than reproducing that upstream cycle.

Technical details: The attacker funded a fresh wallet with 0.0001 cBTC for gas at 12:49:53 UTC, received 8.900023 USDC.e via a bridge mint at 12:52:41 UTC, then deployed a purpose-built contract and executed in the same second at block 12,428,145. Sequence described by Zentra: 200,000 USDC.e of external flash liquidity as temporary collateral, borrow ctUSD, call repayWithATokens for outstanding debt plus one base unit. Both malicious repayments used debt-plus-one, which Zentra reads as targeting debt-token ceil-rounding so the debt cleared even though the exploit contract held no corresponding aTokens. Collateral was then withdrawn; borrowed assets were retained.

The aToken implementation included a safeguard that reduced an oversized scaled burn to the available balance instead of reverting, with no explicit maximum gap between requested burn and available balance. Under repayWithATokens, if the caller held no aTokens the available balance was zero and the burn could collapse to zero while the Pool still treated repayment as complete. At 13:12:51 UTC the attacker swapped 139,999.999999 ctUSD for 139,940.792477 USDC.e and sent 139,959.692499 USDC.e to the bridge. One unrelated user withdrew 0.2518 WcBTC before the pause. Pre-pause residual cash reachable by repeating the cycle was estimated at about $60,926 across the three borrowing-enabled reserves; sUSN was out of scope because borrowing was disabled.

Zentra’s recovery plan at cutoff: snapshot and apply a one-time ~10.19% zctUSD adjustment, deploy a patched implementation after independent review and a two-day timelock, then reopen withdrawals and repayments first with new borrowing restricted. Target date named for patch-and-restart: Monday 15 Sep 2026, described as a target not a commitment. Compensation for depositors hit by the haircut was promised in a follow-up, not published in this window. An on-chain bounty message asked the holder of traced proceeds to return funds to 0x0A66f2D0c603A6E9C23b64Ea29525B7E6F5609B8 and reply to 0x76Be77A14E8bDf7fb6dfb05Bf1B8AC0B21c2F860 before 14 Sep 2026 12:00 UTC.

Explorer links:

Status: Confirmed by the project post-mortem and by Defimon. Markets paused. Funds not reported returned. Bounty clock runs to 14 Sep 12:00 UTC. Citrea bridge/protocol out of scope per both teams.

Sources: https://x.com/ZentraFinance/status/2098415552293195831, https://x.com/DefimonAlerts/status/2098415749421244566, https://x.com/DefimonAlerts/status/2098414497199247690

ORB / ORBCore — BNB Chain — Confirmed

What happened: At 06:38 UTC on 12 Sep 2026, SlowMist published a TI alert for a ~$32,610.72 loss on $ORB. The print is the first required-monitor first-report in this cutoff. No project statement from an ORB official account was located in the same window.

Protocol / chain / asset: ORBToken plus ORBCore on BNB Chain, with a PancakeSwap pair as the liquidity surface. Asset taken: ORB / pair inventory realized as ~$32.6k in SlowMist’s dollar print.

Loss: ~$32,610.72. No return transaction identified.

Attack type: Tax-whitelist plus missing reentrancy guard, then LP burn and sync() reserve skew. Not an oracle-manipulation print in SlowMist’s write-up.

Technical details: SlowMist: ORBCore is whitelisted on ORBToken, so sales through that core skip the 5% burn tax. ORBToken’s receive() automatically grants a maximum allowance and makes an external call into ORBCore addPoolAndSell, which had no reentrancy guard. That path let the attacker loop tax-free sells. When ORBCore sold, burnLP destroyed a large ORB balance inside the pair; a subsequent sync() adjusted reserves and locked in the profit. Addresses named by SlowMist: attacker EOA 0xd8b49172b1a33e77c2619a78e08471facff5dad3; attack contract 0x4f33733a40fae6c19c3a4faf9bc08ce9a1806831; ORBToken 0xc4d27261c06407053cad16cb825ecc0eee7ee7d7; ORBCore 0x24b6308ab84b182d0598b73d21a42f4c2bb33c18; PancakeSwap pair 0x64fad72e5dde70b2960497744b348fd64cb4788c. Example transaction resolved from SlowMist’s alert shortlink: 0x5e6b33b7d69b505d8ae6e50ca6967e13bf513b61593d29011dbcc6d134515b34.

Explorer links:

Status: Confirmed by SlowMist. No public project containment note located at cutoff. Funds not reported returned.

Sources: https://x.com/SlowMist_Team/status/2098662550019694645

Edgeless Network L1 bridge — fake rollup assertion — Ethereum — Pending / not withdrawn

What happened: At 05:24 UTC on 12 Sep 2026, Defimon flagged a fake rollup assertion against Edgeless Network, described as an abandoned Arbitrum Orbit L2 whose team stopped posting to the sequencer around Sep 2025. About 9.2 ewETH (~$22.7k) still sits in the L1 bridge. A Railgun-funded EOA deployed an exploit contract and called propose(), staking a fake assertion (node 228) that claims an invalid L2 state. Validation was left permissionless and no validator remains to dispute it. If the challenge window expires unchallenged, the attacker can confirm the fake state and withdraw through the Outbox.

Protocol / chain / asset: Edgeless Network bridge on Ethereum L1. Asset at risk: ~9.2 ewETH. This is not a completed Outbox withdrawal in Defimon’s alert.

Loss: $0 live on this card. ~$22.7k at risk if node 228 confirms. Do not add it to the $173k live-loss box.

Attack type: Unchallenged permissionless rollup assertion against a dormant Orbit stack. Fraud-proof window still open at the alert.

Technical details: Defimon: the desk caught the deploy before propose() landed. Node 228 cannot be confirmed until L1 block 25,999,225, estimated ~17–18 Sep 2026. Defimon states anyone can stop the path by posting the correct assertion and opening a fraud proof with 0.1 ETH. That is an operational note from the alerting desk, not a how-to reproduced here. Addresses resolved from Defimon’s shortlinks: attacker 0xb88a67357b321d5d8d94f6de8332a901f378a565; exploit contract 0xe2417b5ceb2fd4eb4cbae85bca3a5bbb7da53e98; victim bridge 0x6b595398152999bbc759d5d8ed8169793f915488.

Explorer links:

Status: Confirmed as a proposed fake assertion by Defimon. Withdrawal not reported complete. Challenge window open until the named L1 block.

Sources: https://x.com/DefimonAlerts/status/2098643882267304049

Also noted

  • Symbiosis Bitcoin Bridge (UPDATE, not re-scored): First-report mint-and-dump remains on the 11 Sep brief. In this window Symbiosis said only the Bitcoin Bridge was affected; EVM, TRON, TON, Octopools and other routes were isolated. The team reported recovery of approximately 15 BTC onto a team-controlled multisig, a 20% white-hat bounty open until 13 Sep 2026, and LP outreach for a compensation framework still being written. At 12:12 UTC on 11 Sep it said Bitcoin swaps were back through Chainflip and THORChain while the native Bitcoin Bridge stayed paused. Defimon later noted a message sent from the Symbiosis deployer. Sources: https://x.com/symbiosis_fi/status/2098442463358718264, https://x.com/symbiosis_fi/status/2098384161673285716, https://x.com/DefimonAlerts/status/2098675872303640671.
  • Liquid Network (UPDATE, not re-scored): ~598.5 BTC remains with the 6 Sep actor. No new return hash in this cutoff. SlowMist’s 11 Sep 10:13 UTC cache-key collision write-up is already cited on yesterday’s brief.
  • ZachXBT / Revolut (off-chain, unverified as a protocol exploit): ZachXBT posted that both Revolut accounts had blocked him after he went to check whether Revolut had published on “its recent incident,” pointing at a Telegram investigations post. No on-chain protocol loss figure from the required monitor set. Source: https://x.com/zachxbt/status/2098665718850220042.
  • Lookonchain: Wintermute ETH deposits to Binance/Coinbase, BTC/ETH ETF outflows, a whale BTC buy, and Pump.fun SOL sales. Market-flow notes, not exploit first-reports.
  • CertiKAlert, PeckShieldAlert, Phalcon, BlockSecTeam, GoPlusSecurity, CyversAlerts, Immunefi, rekt.news: no new first-report smart-contract drain with a fresh loss figure after the 11 Sep 11:30 UTC window open. CertiKAlert’s earlier Brevo relay stays on the 11 Sep brief. Immunefi posts in the window were leaderboard / Studio / ENS-competition notes.

Sources & references

Editor’s note: Card live-loss is this window’s confirmed new protocol drains only (~$140k Zentra official print + ~$32.6k ORB). Edgeless is scored as one pending incident with $0 live loss. Symbiosis 15 BTC recovery and the 20% bounty are updates to the 11 Sep item, not a new drain. White-hat and bounty claims are recorded as claims. No how-to or exploit reproduction steps. Verify explorers and official channels before acting on any alert.