Newsroom

More Markets Drained of $9.3 Million in WFLOW on Flow EVM

31 August, 2026   /   News   /  AI   /   Tags:  wflow, blockaid, ankrflow, lending, ankr

More Markets Drained of $9.3 Million in WFLOW on Flow EVM

Security firm Blockaid reported an attacker emptied 15.5 million WFLOW from a More Markets lending reserve using an Ankr liquid staking token and E-Mode, marking the third major DeFi lending incident in five days

A decentralized lending protocol operating on Flow EVM lost approximately $9.3 million after an attacker drained its primary WFLOW reserve. Blockchain security firm Blockaid identified the incident on August 31, stating that 15.5 million WFLOW tokens were removed from the mFlowWFLOW market.

The protocol, developed by More Labs and built on Aave V3 architecture, allows users to supply assets, borrow against collateral and liquidate undercollateralized positions. WFLOW and ankrFLOW rank among its supported assets. Blockaid linked the attack to the use of an Ankr bonded liquid staking token combined with the protocol’s E-Mode feature.

How the Attack Unfolded

E-Mode, or efficiency mode, raises borrowing limits for assets expected to move in tandem, such as a liquid staking token and its underlying asset. More Markets assigns WFLOW an 81.5 percent loan-to-value ratio and an 83 percent liquidation threshold. ankrFLOW carries a 78.5 percent loan-to-value ratio and an 81 percent liquidation threshold.

Blockaid said the attacker employed the Ankr token together with E-Mode to overborrow from the WFLOW reserve. The firm published the exploit transaction, a related contract deployment and a cluster of subsequent transfers used to move the funds. Final losses and the ultimate destination of the assets remain under investigation.

Blockaid detected an exploit on More Markets (More Labs) on Flow EVM. Attacker used Ankr bonded LST + E-mode to drain the WFLOW lending reserve. 15.5M WFLOW emptied from mFlowWFLOW (~$9.3M detector impact). Attack tx cluster includes post-exploit exfil.
Blockaid

Blockaid has not indicated that Ankr’s contracts or the Flow blockchain itself were compromised. The disclosure identified only More Markets as the targeted protocol and the bonded liquid staking token plus E-Mode as the components involved.

Protocol Details and Response Status

More Markets is a noncustodial lending platform deployed in the Ethereum-compatible environment on Flow. Its public documentation lists multiple supported markets and describes ankrFLOW as a reward-bearing liquid staking token issued when users stake FLOW through Ankr’s service. The value of ankrFLOW relative to FLOW rises as staking rewards accumulate while the token balance remains fixed.

At the time of the initial reports, More Markets had not issued a public statement confirming the incident or detailing whether users incurred losses. Available data showed the protocol’s Flow deployment held tens of millions in deposits and active loans prior to the event, with most capital outside the drained reserve.

Broader Context of Recent Lending Exploits

The More Markets incident is the third significant loss at a decentralized lending protocol within a five-day span. On August 27, Moonwell on the Base network lost $8.7 million after an attacker inflated the price of a thinly traded token and borrowed against it. Three days later, an attack on Tectonic, a lending protocol on Cronos, involved a sharp rise in the price of its governance token and resulted in estimated losses of $66 million to $75 million, prompting validators to halt the Cronos network.

These separate events occurred on different chains with distinct attacker wallets and no shared exploit code. Each involved vulnerabilities related to the pricing of collateral assets. The More Markets drain contributed to total cryptocurrency hack losses of roughly $139.7 million for August, the third-highest monthly figure recorded so far in 2026, though still well below the $254 million seen in July.

Flow Network Background

Flow EVM provides an Ethereum-compatible environment that lets applications written for the Ethereum Virtual Machine operate on the network. More Markets runs its lending contracts in that environment. The current incident is confined to the application layer according to available disclosures.

The network previously experienced a separate security event on December 27, 2025. An attacker exploited a flaw in Flow’s Cadence execution layer, enabling the duplication of fungible tokens and the extraction of approximately $3.9 million. Validators halted the chain within hours. Flow Foundation later abandoned an initial proposal for a full chain rollback after objections from bridge operators and instead pursued an isolated recovery that destroyed counterfeit assets while preserving legitimate history.

Investigators continue to examine the post-exploit transaction cluster from the More Markets event to determine the final path of the drained funds.

Associated cryptocurrencies
Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.