📈 Get daily crypto insights that make you smarter about your money

DeFi Lending Protocol More Markets Drained of 15.5 Million WFLOW in 9.3 Million USD Exploit on Flow

A DeFi lending protocol called More Markets was exploited on Sunday, with an attacker draining roughly 15.5 million WFLOW tokens from a lending reserve — an amount security firm Blockaid estimates at about 9.3 million USD in damage.

By Priya Sharma | August 31, 2026

The attack hit More Markets, a decentralized, noncustodial lending protocol deployed on Flow EVM — the Ethereum-compatible side of the Flow blockchain. Blockaid disclosed the exploit in an August 31 post on X, tying the attack to a combination of an Ankr bonded liquid staking token and the protocol’s E Mode mechanism. If you held funds in the affected reserve, here is what happened and why it matters.

The Hook: How the Attacker Drained the Reserve

According to Blockaid’s initial disclosure, the attacker used an Ankr bonded liquid staking token — a token that represents staked crypto that keeps earning rewards while being usable elsewhere — together with More Markets’ E Mode feature to empty the protocol’s mFlowWFLOW lending reserve. E Mode is a mechanism borrowed from Aave V3’s design that lets closely-related assets be borrowed against each other at higher efficiency.

In plain English: the attacker found a way to make the protocol’s own lending rules work against it, borrowing far more than they should have been able to and walking away with the reserve’s tokens. Blockaid said the attack transaction cluster includes transfers made after the initial exploit as the attacker moved the funds.

On-Chain Evidence: What Investigators Know So Far

  • 15.5 million WFLOW drained from the mFlowWFLOW lending reserve, per Blockaid.
  • Roughly 9.3 million USD estimated impact — described by Blockaid as its “detected impact,” meaning final losses are not yet confirmed.
  • Blockaid published the exploit transaction, the attacker’s contract deployment transaction, and a cluster of post-exploit transfers.
  • Not compromised: Blockaid has not said that Ankr or the Flow blockchain itself was breached — the target was More Markets’ implementation.

The final destination of the stolen assets remains under investigation, and the security firm has not yet provided a complete accounting of the attacker’s holdings.

The Core Conflict: Borrowed Architecture, Borrowed Risk?

More Markets is built using Aave V3 architecture — essentially, it reuses the blueprints of one of DeFi’s most battle-tested lending protocols. Its public repository lists nine supported markets where users can supply assets for interest, borrow against collateral and liquidate under-collateralized positions. WFLOW (the wrapped native asset of Flow) and ankrFLOW are among the supported assets.

That is the tension at the heart of this incident: forking proven code gets you a solid foundation, but every customization — new assets, new risk parameters, E Mode configurations for tokens like ankrFLOW — introduces fresh surface area for attack. Blockaid’s initial disclosure did not provide a full technical breakdown, and it remains unclear whether the flaw originated in More Markets’ implementation or in how the Ankr asset was handled within the lending market.

Market Implications: Another Reminder About Small Reserves

For regular DeFi users, the lesson is one of concentration risk. The affected reserve held about 9.3 million USD worth of a single asset on a single protocol. Deposits in smaller, newer markets earn attractive rates precisely because they carry more risk — and exploits like this are what that risk looks like when it materializes.

It has been a rough stretch for cross-chain and multichain DeFi: the More Markets incident follows the Cosmos EVM vulnerability that drained MANTRA, TAC and KiiChain networks and a smaller 28,000 USD flash-loan attack on Float Protocol, both reported in recent days. None of this means DeFi is broken — the largest protocols continue to hold billions without incident — but it does mean the newest corners of the market remain the most dangerous.

The Verdict

If you used More Markets, watch the project’s official channels for a post-mortem and any compensation plan, and be extremely skeptical of “recovery” offers — scammers routinely impersonate exploited protocols. If you are simply a DeFi observer, file this one as the latest evidence that yield follows risk: the extra percentage point a smaller market pays you is rent for the chance it gets drained.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

Disclaimer: This article is for informational purposes only and does not constitute financial advice.

27 thoughts on “DeFi Lending Protocol More Markets Drained of 15.5 Million WFLOW in 9.3 Million USD Exploit on Flow”

  1. another aave v3 fork drained, this time for 15.5M WFLOW on Flow. the implementation was the weak link, not the chain itself. same story every month

    1. serious question, how many of these forks pay for a real audit before shipping vs just forking and hoping for the best

      1. most forks point to the audit of the original protocol and call it covered. the moment your diff touches collateral logic that report is worthless

      2. did due diligence work briefly, most forks ship with the original protocols audit pdf and call it covered. nobody pays for a diff audit until the drains start

        1. a diff audit on collateral logic costs maybe 20k usd. more markets probably did multiples of that in fees before sunday. cheap insurance nobody buys

          1. 20k for a diff audit is optimistic tbh, collateral logic plus liquidation sims is closer to 60k. still rounding error vs 9.3M gone

          2. 60k still rounds to zero against 9.3M. the real question is who underwrote the risk parameters, LTVs dont set themselves

      3. worked at a shop that audited aave forks back to back. budget ones fork the code, skip the audit, then act shocked when E Mode with an LST as collateral blows up

        1. E Mode was designed for correlated stables, not LSTs at high LTV. every team flipping that switch without simulating liquidation loops is rolling dice

    2. the 9.3M vs 15.5M token gap says everything about Flow dex depth. blockaid had the estimate out fast too, wonder if the attacker even got half that in real exit liquidity

  2. 15.5M WFLOW drained for about 9.3M USD real value. The discount on the dump is basically a measurement of how thin Flow DEX liquidity is.

    1. that 40% discount is basically a live slippage readout on flow dexes. whoever absorbed the exit got paid for providing liquidity nobody else wanted to

      1. The slippage angle deserves more attention. Whoever bought that WFLOW dump at a 40 percent haircut is sitting on a huge position if Flow liquidity ever comes back.

        1. flow liquidity coming back is a big if. dex depth on WFLOW was paper thin even before the drain, whoever caught that knife basically is the market now

          1. Disagree slightly. Aave v3 code is battle tested, the fork audits are the weak link. More Markets skipped the public audit contest route, that is where this got through

    2. every exit on flow dexes prints a discount like that. 15.5M nominal dumping into a book that size, youd eat 40 percent trying to sell a house that way too

  3. Ankr bonded liquidity mechanism as the entry vector again. Same building blocks keep showing up in these post mortems, someone needs to write the canonical teardown.

    1. the teardown already exists, its called every aave v3 fork post mortem since 2023. teams just dont read the ones from other chains apparently

  4. E Mode plus a liquid staking token as collateral, the same combo that has killed other lending protocols. why do teams keep enabling correlated collateral at high LTV

    1. because correlated collateral posts juicier apr numbers in the marketing deck. every LST lending blowup has the same root, LTVs set for stables pasted onto a token that can depeg 40%

      1. the marketing deck line is exactly it. aave literally documents E Mode as for correlated stables and these forks flip it on for an ankr LST pair at max LTV like its a free apr dial

  5. If you had funds in that reserve, pause and check the recovery flow before touching anything. Exploits like this attract copycat phishing within hours.

    1. can confirm the phishing part, got a fake recovery airdrop link within hours of the aave fork drain last year. never click anything right after an exploit

  6. the reserve sat there quoting healthy LTVs the whole time tho. liquidation loops with a staked token that depegs 40 percent are not an edge case, they are the base case

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,154.00-0.9%ETH$2,410.63-1.5%SOL$99.58-2.5%BNB$685.820.0%XRP$1.34-1.8%ADA$0.1957-0.8%DOGE$0.0814-1.3%DOT$0.8635+1.1%AVAX$7.19-0.4%LINK$11.17-1.3%UNI$6.32+11.6%ATOM$1.46-1.5%LTC$49.02+1.3%ARB$0.1171+5.7%NEAR$1.85-3.7%FIL$0.8003+16.2%SUI$0.7230+0.4%BTC$77,154.00-0.9%ETH$2,410.63-1.5%SOL$99.58-2.5%BNB$685.820.0%XRP$1.34-1.8%ADA$0.1957-0.8%DOGE$0.0814-1.3%DOT$0.8635+1.1%AVAX$7.19-0.4%LINK$11.17-1.3%UNI$6.32+11.6%ATOM$1.46-1.5%LTC$49.02+1.3%ARB$0.1171+5.7%NEAR$1.85-3.7%FIL$0.8003+16.2%SUI$0.7230+0.4%
Scroll to Top