More Markets — a lending protocol on Flow EVM — was hit by an exploit that drained roughly 15.5 million WFLOW (about $9.3 million), according to blockchain security firm Blockaid. What happened - On Aug. 31 Blockaid posted on X that an attacker emptied the mFlowWFLOW lending reserve by combining an Ankr bonded liquid-staking token (ankrFLOW) with More Markets’ E Mode feature. Blockaid published the exploit transaction, a related contract deployment, and a cluster of post‑exploit transfers used to move funds, but said its $9.3 million figure is an initial detected impact and the final loss is still being traced. - Blockaid did not allege any compromise of Ankr itself; their disclosure tied the exploit to the interaction between a bonded LST and More Markets’ E Mode, without yet offering a detailed technical chain-of-events. About More Markets and the assets involved - More Markets is a decentralized, noncustodial lending protocol built on Flow EVM using Aave V3 architecture. Its public repo shows nine supported markets where users can supply assets for interest, borrow against collateral, and liquidate undercollateralized positions. - The protocol supported both WFLOW (the wrapped native asset) and ankrFLOW (Ankr’s reward-bearing liquid staking token). More Markets listed WFLOW with an LTV of 81.5% and a liquidation threshold of 83%; ankrFLOW had a 78.5% LTV and an 81% liquidation threshold. - Ankr describes ankrFLOW as a liquid staking token whose value relative to FLOW rises as staking rewards accrue while the token balance remains unchanged. Ankr’s Flow staking contracts and ratio feed are published on Flow EVM; Ankr says those contracts were externally audited by Halborn. How the exploit is framed - Blockaid specifically named an Ankr bonded LST plus E Mode as the components used by the attacker. E Mode — an Aave V3 feature that increases borrowing power for highly correlated assets — can amplify borrowing capacity when certain conditions are met. Blockaid’s initial disclosure did not pinpoint whether the root cause was More Markets’ implementation, Ankr’s asset handling or pricing inputs, or a complex interaction between them. Flow EVM context and prior incidents - The incident targeted an application running in Flow EVM (Flow’s Ethereum‑compatible execution environment); Blockaid’s disclosure did not indicate a compromise of the Flow network itself. - Flow’s DeFi ecosystem has previously promoted both More Markets and Ankr as available services. The distinction between an application-level exploit and a network-level breach matters: Flow experienced a separate, high-profile Cadence execution-layer attack in December 2025 that allowed an attacker to duplicate tokens and extract about $3.9 million. That prior incident led to a complex recovery process and wider ecosystem disruption — but it is separate from the More Markets exploit. Current status - Blockaid’s findings remain an initial assessment. The firm published transaction evidence and a post‑exploit transfer cluster but has not released a full accounting of attacker holdings. Investigations are ongoing to trace where the drained WFLOW moved and to determine the precise vulnerability chain. We'll update as forensic firms, protocol developers and on-chain monitors release further technical analysis and recovery information. Read more AI-generated news on: undefined/news
