NewsCryptoMore Markets loses $9.3M in WFLOW after attack on Ankr LST and E-mode pricing

More Markets loses $9.3M in WFLOW after attack on Ankr LST and E-mode pricing

Author: Metaverse Post·

Key Takeaways

  • Blockaid said roughly 15.5 million wrapped WFLOW tokens were drained from More Markets’ lending reserve on Flow EVM.
  • The estimated loss from the exploit was about $9.3 million.
  • Blockaid said the attacker used Ankr’s bonded liquid staking token together with More Markets’ E-mode to carry out the attack.
  • More Markets said it was investigating the alleged exploit and would share findings later.
  • Blockaid did not say Ankr was compromised and said the incident appears to have affected the application layer rather than Flow’s underlying network.
More Markets loses $9.3M in WFLOW after attack on Ankr LST and E-mode pricing

Crypto lending protocol More Markets has suffered an exploit that resulted in the loss of approximately $9.3 million. Blockchain security firm Blockaid detected the attack on More Labs’ lending protocol operating on Flow EVM, where roughly 15.5 million wrapped WFLOW tokens were drained from the mFlowWFLOW lending reserve.

According to Blockaid’s disclosure, the attacker used Ankr’s bonded liquid staking token together with More Markets’ E-mode mechanism to carry out the exploit. The attacker appears to have manipulated the perceived value of collateral, allowing borrowed genuine WFLOW against artificially inflated collateral and then depleting the protocol’s entire WFLOW lending reserve.

Blockaid detected an exploit on More Markets (More Labs) on Flow EVM. Attacker used Ankr bonded LST + E-mode to drain the WFLOW lending reserve. 15.5M WFLOW emptied from mFlowWFLOW (~$9.3M detector impact). Attack tx cluster includes post-exploit exfil. More details in — Blockaid (@blockaid_) August 31, 2026

Blockaid identified the exploit transaction, the initial contract deployment, and a cluster of post-exploit transfers used to exfiltrate funds after the drainage, although the firm had not provided a final accounting of the attacker’s holdings at the time of disclosure. For protocols that depend on collateral routing and internal pricing rules, the incident underscores how implementation details can matter as much as the assets involved, especially when a reserve is emptied before a broader response can be completed.

More Markets is a decentralized, noncustodial lending protocol built on Aave V3 architecture and deployed on Flow EVM. The platform lists nine supported markets where users supply assets to earn interest, borrow against collateral at variable rates, and liquidate positions that fall below required collateral levels. WFLOW, the native wrapped asset, carries an 81.5% loan-to-value ratio and an 83% liquidation threshold, while ankrFLOW has a 78.5% LTV and an 81% liquidation threshold.

Application-layer incident is separate from Flow’s earlier network breach

The ankrFLOW token, issued by Ankr, is a reward-bearing liquid staking token whose value appreciates relative to FLOW as staking rewards accrue, without changing the holder’s token balance. Ankr’s documentation says its Flow liquid staking contracts on both Cadence and EVM underwent external audits by Halborn.

Blockaid’s analysis did not identify Ankr itself as compromised, and said only that the bonded LST and More Markets’ E-mode were components in the attacker’s methodology. The exact technical sequence has not been disclosed, leaving open whether the vulnerability originated in More Markets’ implementation, the handling of the Ankr asset, its pricing assumptions, or an interaction between those components.

The incident targeted an application operating within Flow EVM, an Ethereum-compatible execution environment on the Flow blockchain, with no indication that the underlying network infrastructure was compromised. That distinction is notable given Flow’s recent security history. In December 2025, a separate attack exploited a vulnerability in Flow’s Cadence execution layer version 1.8.8, enabling the duplication of a protected asset disguised as a standard data structure and the extraction of approximately $3.9 million.

That earlier incident involved more than one billion counterfeit FLOW tokens minted and distributed to centralized exchanges, though 484.4 million were later returned by OKX, Gate.io, and MEXC and destroyed, while the network isolated 98.7% of the remaining counterfeit supply.

Our team is currently investigating a claim that MORE Markets was exploited. We will share our findings shortlhy. — MORE Markets (@MORE_DeFi) August 31, 2026

Our team is currently investigating a claim that MORE Markets was exploited. We will share our findings shortlhy.

Following the disclosure, the More Markets team said it was investigating claims that the protocol had been exploited and would share its findings shortly.