Roughly $9.3 million in WFLOW was drained from the More Markets lending protocol on Flow EVM on Aug. 31, according to a security firm tracking the incident. It is the latest decentralized-finance lending exploit to surface this week.
Blockchain-security platform Blockaid said its detection system flagged an ongoing attack on More Markets’ WFLOW lending reserves. The firm put the loss at about 15.5 million WFLOW, or $9.3 million. That number, Blockaid noted, is its “detected impact” estimate. The final tally has not been confirmed as investigators trace the transactions.
The attacker, according to Blockaid, combined an Ankr liquid-staking token with the E-Mode mechanism inside More Markets to overborrow against mispriced collateral and empty the reserve. E-Mode is short for efficiency mode, an Aave V3 feature that allows users to borrow more heavily against assets considered closely correlated. In this case, those assets were apparently ankrFLOW and WFLOW.
More Markets is a noncustodial lending protocol deployed on Flow EVM and built on Aave V3 architecture, crypto.news reported. On the platform, WFLOW carries an 81.5% loan-to-value ratio with an 83% liquidation threshold. ankrFLOW, Ankr’s reward-bearing liquid-staking token for FLOW, carries a 78.5% LTV and an 81% liquidation threshold.
That spread between the two settings is where the exploit appears to have lived. ankrFLOW is designed to appreciate against FLOW as staking rewards accrue while the token count stays fixed. The property lets it function as yield-bearing collateral. Blockaid did not say which specific assumption the attacker broke.
Blockaid also disclosed that it had published an exploit transaction, a contract-deployment transaction, and a cluster of post-exploit transfers used to move funds once the reserve was emptied. No accounting of the attacker’s holdings was available at the time of reporting. The firm did not provide a detailed technical breakdown of the exploit sequence.
In its initial disclosure, Blockaid stopped short of saying Ankr itself had been compromised. The bonded LST and More Markets’ E-Mode, the firm said, were the components the attacker used. Ankr’s Flow liquid-staking contracts on Cadence and EVM underwent external audits by Halborn, the staking provider’s documentation states.
Where the underlying issue originated remained unclear. It could sit in More Markets’ implementation, in the way the Ankr asset was handled within the lending protocol, in its pricing assumptions, or in some interaction between the two components. Nothing in the initial disclosure suggested the Flow blockchain itself was compromised. The incident targeted an application running on Flow EVM.
Flow EVM provides an Ethereum-compatible environment on the Flow network. More Markets runs its lending contracts there.
This is the second Flow-related security event in recent months. In late December, an attacker exploited a vulnerability in Flow’s Cadence execution layer to duplicate tokens and extract roughly $3.9 million in value. The Flow Foundation said the attacker deployed more than 40 malicious smart contracts. A flaw in Cadence runtime version 1.8.8 allowed a protected asset to be disguised as a standard data structure and duplicated. More than one billion counterfeit FLOW tokens were sent to centralized exchanges before the network was halted. OKX, Gate.io and MEXC later returned 484.4 million FLOW, which was destroyed.
Blockaid said it was continuing to monitor the More Markets situation. No protocol-level response or statement from More Markets or its parent, More Labs, had surfaced in either outlet’s reporting at the time of publication.
The drained reserve, as ever, is the part investigators can see. What the attacker does with it next is the part they cannot.


