en
Back to the list

More Markets suffers $9.3m WFLOW exploit on Flow EVM

source-logo  crypto.news 1 h
image

More Markets has suffered an exploit on Flow EVM that drained about 15.5 million WFLOW from the lending protocol, with blockchain security firm Blockaid estimating the impact at roughly $9.3 million.

Blockaid said in an Aug. 31 X post that an attacker exploited More Markets, developed by More Labs, by using an Ankr bonded liquid staking token together with the protocol’s E Mode mechanism. The security firm identified the mFlowWFLOW lending reserve as the source of the drained tokens and published transactions linked to the attack.

🚨 Blockaid detected an exploit on More Markets (More Labs) on Flow EVM. Attacker used Ankr bonded LST + E-mode to drain the WFLOW lending reserve. 15.5M WFLOW emptied from mFlowWFLOW (~$9.3M detector impact). Attack tx cluster includes post-exploit exfil.
More details inđź§µ

— Blockaid (@blockaid_) August 31, 2026

The firm’s initial assessment puts the amount removed from the reserve at 15.5 million WFLOW. Blockaid described the roughly $9.3 million figure as its detected impact, meaning the final loss has yet to be confirmed as investigators trace the transactions and determine where the assets ultimately moved.

Blockaid published an exploit transaction, the contract deployment transaction and a cluster of post exploit transfers. The firm said the cluster contained transactions used to move funds after the reserve was drained, but had not provided a final accounting of the attacker’s holdings at the time of writing.

More Markets exploit targeted its WFLOW lending reserve

More Markets is a decentralized, noncustodial lending protocol deployed on Flow EVM and built using Aave V3 architecture. Its public repository lists nine supported markets and allows users to supply assets for interest, borrow against collateral at variable rates and liquidate positions that fall below required collateral levels.

WFLOW and ankrFLOW are among the assets supported by the protocol. More Markets lists WFLOW with a loan to value ratio of 81.5% and a liquidation threshold of 83%, while ankrFLOW has a 78.5% loan to value ratio and an 81% liquidation threshold.

The protocol’s documentation identifies ankrFLOW as a liquid staking token, or LST, while WFLOW serves as the native wrapped asset within the lending market.

Blockaid specifically tied the attack to an Ankr bonded LST and E Mode, but its initial disclosure did not provide a detailed technical breakdown explaining the sequence used to drain the WFLOW reserve. It remains unclear from the disclosure whether the underlying issue originated in More Markets’ implementation, the way the Ankr asset was handled within the lending protocol, its pricing assumptions, or an interaction between the two components.

Ankr’s documentation describes ankrFLOW as a reward bearing liquid staking token issued when users stake $FLOW through its staking service. Its value relative to $FLOW increases as staking rewards accumulate, while the number of ankrFLOW tokens held by the user remains unchanged.

Ankr lists separate smart contracts on Flow EVM for the ankrFLOW token, staking pool, staking configuration and ratio feed. The ratio feed contains the token’s ratio certificate, according to its documentation.

The company’s Flow liquid staking documentation says users can deploy ankrFLOW in DeFi applications, including lending markets, to borrow against the value represented by their staked $FLOW. Ankr states that the Flow liquid staking contracts on Cadence and EVM underwent external audits by Halborn.

Blockaid had not said that Ankr itself was compromised in the incident. Its disclosure only identified the bonded LST and More Markets’ E Mode mechanism as components used by the attacker.

Flow EVM has remained separate from the attack vector disclosed so far

The Aug. 31 incident targeted an application running on Flow EVM based on the information released by Blockaid, with no indication in the initial disclosure that the Flow blockchain itself had been compromised.

Flow EVM provides an Ethereum compatible environment on Flow, allowing applications written for the Ethereum Virtual Machine to operate on the network. More Markets runs its lending contracts in that environment.

Flow has previously promoted both More Markets and Ankr as applications available to users within its DeFi ecosystem. Its Community Rewards program, for example, offered rewards for activity involving lending protocols such as More Markets and for staking $FLOW through Ankr’s liquid staking product.

The distinction between the More Markets incident and a network level exploit is particularly relevant because Flow suffered a separate security breach in late 2025.

As crypto.news previously reported, a Dec. 27 attack exploited a vulnerability in Flow’s Cadence execution layer and allowed an attacker to duplicate fungible tokens before extracting approximately $3.9 million in value.

Flow Foundation’s subsequent post mortem said the attacker deployed more than 40 malicious smart contracts in a coordinated sequence. A flaw in Cadence runtime version 1.8.8 allowed a protected asset that should not have been copyable to be disguised as a standard data structure and duplicated.

More than 1 billion counterfeit $FLOW tokens were sent to centralized exchanges during that incident. Flow said 484.4 million $FLOW were later returned by OKX, Gate.io and MEXC and destroyed, while the network isolated 98.7% of the remaining counterfeit supply.

Flow previously changed its recovery plan after $3.9 million exploit

The December attack forced Flow validators to halt the blockchain within hours of the first malicious transaction. Flow Foundation initially proposed a full chain rollback, which would have returned the network to a checkpoint before the exploit.

The proposed Flow chain rollback faced opposition from bridge operators and other ecosystem participants. Critics warned that reversing confirmed transactions could produce duplicated balances for users who had moved assets through bridges during the affected period and create losses for users who had bridged assets in.

Flow subsequently abandoned the global rollback and adopted an isolated recovery process designed to identify and destroy counterfeit assets while retaining legitimate transaction history.

During the recovery, developers worked on restoring both Cadence and Flow EVM functionality. Accounts linked to suspicious activity faced temporary restrictions while external forensic firms helped verify affected accounts, with Flow estimating that more than 99.9% of accounts would regain full access once the recovery was completed.

The fallout later extended to South Korea, where Flow Foundation and Dapper Labs sought a court order in March to stop Upbit, Bithumb and Coinone from ending trading support for $FLOW. The exchanges had moved toward delisting after the December security incident, while Flow maintained that existing user balances had not been compromised.

For the More Markets attack, Blockaid’s Aug. 31 disclosure remained an initial assessment. The security firm said more details were still being investigated after identifying the 15.5 million WFLOW outflow and the subsequent transaction cluster used to move funds after the exploit.

crypto.news