Highlights
- Citrea has restored cross-chain bridging for ctUSD, USDC, USDT, WBTC and CTR after a multi-day suspension.
- The pause followed a security incident at Zentra Finance, a third-party lending protocol built on Citrea.
- Citrea says its own protocol and bridge contracts were unaffected, and upgraded its bridge validator quorum from 2-of-2 to 3-of-4.
- Some Solver-based routing services remain in gradual restoration; the impact on Zentra's ctUSD Earn Vault and depositors will be disclosed separately.
Bridging Back Online
Bitcoin ZK-rollup Citrea has resumed cross-chain bridging for five assets after suspending the service in response to a security incident at Zentra Finance, a third-party lending protocol built on the network. Citrea said that following a full review, bridging for ctUSD, USDC, USDT, WBTC and CTR is back online, though some Solver-based routing options are still being restored gradually. The team said its own protocol and cross-chain bridge contracts were not affected by the incident, which was isolated to Zentra Finance's smart contracts. Citrea did not disclose a dollar figure for losses at Zentra but said it would separately detail the incident's impact on ecosystem projects tied to the lender, including its ctUSD Earn Vault and its depositors.
What Happened, and What Citrea Changed
Zentra Finance is a decentralized money market built natively on Citrea and modeled on Aave's lending architecture, letting users supply, borrow and stake assets in a non-custodial, over-collateralized structure. The protocol's role as one of the larger lending venues on Citrea's still-young ecosystem made the incident significant enough to trigger a network-wide pause of cross-chain bridging rather than an isolated freeze of Zentra's own contracts, a precaution the team said let it confirm the root cause before reopening the bridge to any asset. Alongside restoring bridging, Citrea disclosed a hardening step taken during the pause: the network's bridge validator setup was upgraded from a 2-of-2 quorum to a 3-of-4 configuration, requiring agreement from three of four validators rather than both of two before assets move across the bridge. That change mirrors a pattern seen elsewhere in the Bitcoin layer-2 space this year, where bridge operators have moved to widen validator sets after security scares — Osmosis similarly halted BTC-alloyed asset minting earlier this year after a security incident hit its Nomic bridge. Citrea launched its mainnet in January 2026 as Bitcoin's first Type 2 zkEVM rollup, anchoring EVM smart contracts and a wrapped BTC asset to Bitcoin's settlement layer through a BitVM-based bridge design, and has been adding lending, stablecoin and trading applications to a still-small but fast-growing ecosystem.
Why It Matters for Bitcoin L2s
For Bitcoin layer-2 networks generally, incidents at third-party applications carry outsized reputational risk because the entire premise of these rollups is that they can host DeFi activity without compromising Bitcoin's base-layer security guarantees. A lending protocol exploit or bug happening one layer up doesn't touch bitcoin itself, but it does test whether a young network's bridge and governance can respond quickly and transparently — exactly what larger capital allocators watch before committing meaningful liquidity. Citrea's decision to pause bridging across all assets rather than isolate the affected contracts suggests the team prioritized certainty over uptime, a trade-off that cost it days of frozen cross-chain activity but should reduce the odds of a repeat freeze if a similar issue surfaces again.
Related: Cronos Halts Chain After $75M Tectonic Exploit Traps Stolen Funds
That calculus matters for a network still building its base: Citrea's ecosystem has run at a fraction of established EVM chains' TVL since its January mainnet launch, and any protracted loss of bridging function during a formative period can slow the deposits and integrations a young chain needs to compound growth. Other lending protocols built on emerging chains have faced similar tests this year — from oracle manipulation to governance-vote attacks — and the ones that recovered fastest tended to be those that disclosed root causes quickly rather than let rumors fill the gap, a lesson Citrea's own messaging around the Zentra incident appears to be following. A Moonwell lending market on Base was drained of $8.7 million earlier this year in a comparable exploit of a lending protocol's price logic, underscoring how often DeFi lending remains the weakest link even on otherwise secure infrastructure.
What to Watch Next
The next disclosure to watch is Citrea's promised breakdown of how the Zentra incident affected the ctUSD Earn Vault and individual depositors, which will determine whether any user funds require reimbursement or remain permanently impaired. The remaining Solver-based routing paths still being restored are the other loose end; until those return to full service, some cross-chain routes into and out of Citrea will stay slower or unavailable even though direct bridging for the five listed assets is live again. Longer term, the upgraded 3-of-4 validator quorum will be tested the next time bridge activity spikes, and how Zentra itself responds — whether it patches and reopens or winds down — will shape confidence in third-party lending built on Citrea's still-maturing base.
FAQ
Which assets can now bridge to and from Citrea again?
Citrea has restored cross-chain bridging for ctUSD, USDC, USDT, WBTC and CTR, though some Solver-based routing options are still being restored gradually.
What caused the pause?
A security incident hit Zentra Finance, a third-party Aave-style lending protocol built on Citrea; Citrea suspended bridging network-wide as a precaution while it confirmed the root cause.
Was Citrea's own protocol affected?
No — Citrea said its own protocol and cross-chain bridge contracts were not affected and that the incident was isolated to Zentra Finance's smart contracts.
What changed on Citrea's bridge as a result?
Citrea upgraded its bridge validator setup from a 2-of-2 quorum to a 3-of-4 configuration, requiring agreement from three of four validators before assets move across the bridge.
