📈 Get daily crypto insights that make you smarter about your money

More Markets Drained of 9.3 Million USD in WFLOW Lending Exploit on Flow EVM

Decentralized lending protocol More Markets was exploited on Flow EVM on August 31, with blockchain security firm Blockaid estimating the attacker drained roughly 9.3 million USD worth of tokens from a single lending reserve. The incident marks one of the larger DeFi exploits of the quarter and once again highlights the risks that emerge when liquid staking tokens interact with complex lending mechanics.

According to Blockaid’s disclosure, the attacker removed approximately 15.5 million WFLOW from the protocol’s mFlowWFLOW lending reserve. The security firm linked the attack to the combination of an Ankr bonded liquid staking token and More Markets’ efficiency mode, known as E Mode, which allows closely correlated assets to be borrowed against each other at higher capital efficiency than standard lending parameters would permit.

## How the attack unfolded

Blockaid said the attacker used the Ankr bonded liquid staking token together with E Mode to drain the WFLOW lending reserve. The firm published the exploit transaction, the contract deployment transaction, and a cluster of post-exploit transfers used to move funds after the reserve was emptied.

Importantly, Blockaid characterized the 9.3 million USD figure as its detected impact rather than a final loss total. Investigators are still tracing the transactions to determine where the assets ultimately moved, and the final accounting could shift as the attacker’s wallet activity is mapped across decentralized and centralized venues.

Neither Ankr nor the Flow blockchain itself has been identified as compromised. The initial disclosure points squarely at More Markets, a protocol developed by More Labs, as the targeted entity.

## Inside More Markets

More Markets is a decentralized, noncustodial lending protocol deployed on Flow EVM and built using Aave V3 architecture. Its public repository lists nine supported markets, allowing users to supply assets to earn interest, borrow against collateral at variable rates, and liquidate positions that fall below required collateral thresholds.

The protocol’s parameters illustrate why the WFLOW and ankrFLOW pairing attracted the attacker’s attention. More Markets lists WFLOW with a loan-to-value ratio of 81.5 percent and a liquidation threshold of 83 percent, while ankrFLOW carries a 78.5 percent loan-to-value ratio and an 81 percent liquidation threshold. Those aggressive parameters, enabled through E Mode, allow users to borrow heavily against staked positions, amplifying both capital efficiency and risk.

Ankr’s documentation describes ankrFLOW as a reward-bearing liquid staking token issued when users stake FLOW through its staking service. The token’s value relative to FLOW increases as staking rewards accumulate, while the token balance held by the user remains unchanged. Ankr lists separate smart contracts on Flow EVM for the ankrFLOW token, the staking pool, the staking configuration, and a ratio feed containing the token’s ratio certificate.

The company states that its Flow liquid staking contracts on both Cadence and EVM underwent external audits by Halborn, and Ankr encourages users to deploy ankrFLOW in DeFi applications, including lending markets, to borrow against the value of staked assets. That integration path is precisely where the attack occurred.

## The open question

Blockaid’s initial disclosure did not provide a detailed technical breakdown of the exploit sequence, leaving a critical question unanswered: whether the underlying flaw originated in More Markets’ implementation, in the way the Ankr asset was handled within the lending protocol, in pricing assumptions, or in the interaction between the two components.

That distinction matters for the broader ecosystem. If the vulnerability lies in how reward-bearing liquid staking tokens are priced or correlated inside E Mode-style lending systems, other protocols that list similar assets face analogous exposure. Liquid staking tokens have become foundational DeFi collateral across dozens of chains, and their reward-bearing mechanics make oracle design and correlation assumptions unusually delicate.

If instead the flaw was specific to More Markets’ configuration or implementation, the blast radius is contained to the affected markets. Either way, the incident will prompt renewed scrutiny of E Mode deployments, which trade conservatism for efficiency by allowing highly correlated collateral and borrowing assets to interact with elevated parameters.

## A familiar pattern

The exploit follows a well-worn script in DeFi security incidents. A specialized attack vector targets a specific reserve, post-exploit funds move through a cluster of transactions designed to obscure their destination, and the final loss figure remains fluid while investigators work. Blockaid’s on-chain detection provided early warning, but detection is not prevention, and the mFlowWFLOW reserve was emptied before any halt could occur.

For Flow EVM, the incident is an unwelcome test of the network’s growing DeFi footprint. Flow has been pushing deeper into Ethereum-compatible functionality, and More Markets represented one of its more sophisticated lending venues. A nine-figure-token drain from a flagship protocol inevitably slows the momentum of an ecosystem trying to attract developers and liquidity.

For lenders and borrowers on More Markets, the immediate practical steps are familiar: assume the affected reserve is a loss until proven otherwise, review any exposure to the protocol, and watch for an official incident response from More Labs. For the wider market, the exploit is a reminder that the most dangerous vulnerabilities often sit not in audited core contracts but in the seams between them, where a staking token’s reward mechanics meet a lending engine’s efficiency optimizations.

Blockaid has not said Ankr or the Flow blockchain itself was compromised, and its investigation continues. The final loss figure, the attacker’s cash-out path, and any recovery efforts will define the aftermath of what stands as a costly lesson in liquid staking collateral risk.

Disclaimer: This article is for informational purposes only and does not constitute financial advice.

27 thoughts on “More Markets Drained of 9.3 Million USD in WFLOW Lending Exploit on Flow EVM”

  1. a single reserve holding 15.5M WFLOW with no breaker. at some point the eighth exploited fork this year stops being a surprise

  2. 9.3m gone and once again e mode is in the blast radius. ankr LST next to correlated borrowing on a chain nobody audits deeply

    1. E Mode works fine on Aave. The issue is porting it to Flow EVM where the oracle for a wrapped staking token is paper thin.

      1. thats the part nobody prices. porting aave mechanics to a chain where the wrapped staking oracle has no depth is the actual bug

        1. checked the ankrFLOW pool after the news, thinner than the reserve it was pricing by an order of magnitude. e mode just made the exit efficient

          1. the wild part is it was one mFlowWFLOW reserve. ankr LST pricing plus e mode and 9.3M walks out before anyone blinks

    1. 15.5M out of one reserve and the breaker stays asleep. thats the part that should scare flow tvl more than the exploit itself

      1. breaker asleep while 15.5M leaves a single reserve. the exploit was the loud part, the missing kill switch is what keeps tvl away forever

    2. breakers are a feature you wish you had shipped, never one you retrofit in peace. that 15.5M reserve was the whole lesson

      1. 15.5M WFLOW drained and even Blockaid is only estimating. every cross chain deployment of these liquid staking tokens needs isolated borrow ceilings, not copy pasted e mode

    1. 81.5 percent LTV with an ankr LST as collateral. whoever approved that combo should explain before we blame E mode itself

      1. because aave restricts e mode to tightly correlated stablecoin families for exactly this reason. porting it onto an ankr LST pair was the unforced error

        1. aave spent years stress testing e mode pairs before shipping them. copying the knob without the research was the actual exploit

  3. 9.3M gone and blockaid calls it detected impact, not final loss. aave v3 fork with params way too aggressive

  4. blockaid already clustered the postexploit transfers and recovery is still a maybe. hope the flow bridge link in the article covers tvl that left before this headline

  5. eighth fork drained this year and every postmortem says the same thing. correlated collateral plus high LTV equals eventual zero

    1. eighth or ninth depending who counts, and the postmortems all rhyme. correlated collateral at high ltv is a countdown timer

  6. flow evm gets one real lending protocol and it cant survive a quarter without a 9.3m drain. the fork casino claims another victim

  7. 15.5M WFLOW out of one reserve and the token still trades. wrapped staking derivatives are becoming the CDOs of this cycle

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$76,572.00-1.7%ETH$2,370.80-3.3%SOL$98.33-3.6%BNB$682.13-0.5%XRP$1.32-3.3%ADA$0.1933-2.1%DOGE$0.0806-2.1%DOT$0.8475-0.9%AVAX$7.09-1.8%LINK$11.02-2.8%UNI$6.08+7.3%ATOM$1.45-1.9%LTC$48.65+0.1%ARB$0.1123+2.9%NEAR$1.83-4.4%FIL$0.7849+12.5%SUI$0.7136-1.1%BTC$76,572.00-1.7%ETH$2,370.80-3.3%SOL$98.33-3.6%BNB$682.13-0.5%XRP$1.32-3.3%ADA$0.1933-2.1%DOGE$0.0806-2.1%DOT$0.8475-0.9%AVAX$7.09-1.8%LINK$11.02-2.8%UNI$6.08+7.3%ATOM$1.45-1.9%LTC$48.65+0.1%ARB$0.1123+2.9%NEAR$1.83-4.4%FIL$0.7849+12.5%SUI$0.7136-1.1%
Scroll to Top