More Markets lost roughly $9.3 million after an attacker drained 15.5 million WFLOW from its lending reserve on Flow EVM, security firm Blockaid said Aug. 31.
More Markets lost roughly $9.3 million after an attacker drained 15.5 million WFLOW from its lending reserve on Flow EVM, security firm Blockaid said Aug. 31.

More Markets lost roughly $9.3 million after an attacker drained 15.5 million WFLOW from its lending reserve on Flow EVM, security firm Blockaid said Aug. 31.
More Markets lost roughly $9.3 million after an attacker drained 15.5 million WFLOW from its Flow EVM lending reserve, Blockaid said Aug. 31.
"Attacker used Ankr bonded LST + E-mode to drain the WFLOW lending reserve," Blockaid said in an Aug. 31 post on X, describing the roughly $9.3 million figure as its detected impact and noting the attack transaction cluster included post-exploit exfiltration.
The drained assets came from the mFlowWFLOW pool, the interest-bearing deposit market for Wrapped Flow, the ERC-20-compatible representation of FLOW used within Flow's Ethereum Virtual Machine environment. More Markets, built on Aave V3 architecture, lists nine supported markets, with WFLOW carrying an 81.5 percent loan-to-value ratio and an 83 percent liquidation threshold, while ankrFLOW carries a 78.5 percent LTV and an 81 percent liquidation threshold. The protocol held roughly $3.99 million in total value locked across Flow at the time of the exploit, with about $3.48 million in active loans, per DefiLlama data.
The incident follows a separate $3.9 million exploit of Flow's Cadence execution layer in December 2025 and lands in a year when crypto losses have already exceeded $1.26 billion across more than 219 incidents, per Blockaid data. Neither More Markets nor More Labs had published a post-mortem as of publication, and the final loss figure remains under investigation as Blockaid traces the post-exploit transaction cluster.
Efficiency Mode, or E-mode, is an Aave V3 borrowing feature that raises maximum loan-to-value ratios and adjusts liquidation thresholds for positions restricted to assets within a correlated category. The design assumes assets in a category maintain tight price correlation. For a pair such as FLOW and ankrFLOW — economically linked because ankrFLOW represents staked FLOW plus accrued rewards — a correlation-based E-mode configuration allows borrowing at far higher LTV than a general-purpose market would permit.
Blockaid's disclosure tied the attack to an "Ankr bonded LST + E-mode" pathway without publishing a step-by-step reconstruction. It remains unclear whether the root cause originated in More Markets' implementation of E-mode, the way the ankrFLOW asset was integrated, its pricing assumptions, or an interaction between components. Ankr describes ankrFLOW as a reward-bearing liquid staking token whose value rises relative to FLOW as staking rewards accumulate, with the ratio feed serving as the on-chain source of the exchange ratio. Ankr states its Flow liquid staking contracts underwent external audits by Halborn. Blockaid has not said Ankr itself was compromised.
The Aug. 31 incident targeted an application-layer contract on Flow EVM, with no indication the Flow blockchain's base layer was compromised. Flow's EVM Gateway and core block-production infrastructure remained operational throughout, per the network's status page.
The distinction matters because Flow suffered a separate protocol-level breach in late December 2025. A Dec. 27 attack exploited a vulnerability in Flow's Cadence execution layer, allowing an attacker to duplicate fungible tokens before extracting roughly $3.9 million. Flow Foundation's post-mortem said the attacker deployed more than 40 malicious smart contracts, exploiting a flaw in Cadence runtime version 1.8.8. More than 1 billion counterfeit FLOW tokens were sent to centralized exchanges, with 484.4 million later returned by OKX, Gate.io and MEXC and destroyed, while the network isolated 98.7 percent of the remaining counterfeit supply.
Flow initially proposed a full chain rollback but abandoned it after opposition from bridge operators, adopting an isolated recovery process instead. The fallout extended to South Korea, where Flow Foundation and Dapper Labs sought a court order in March to stop Upbit, Bithumb and Coinone from delisting FLOW.
WFLOW dropped about 9 percent within an hour of the exploit, while FLOW fell roughly 8.7 percent to $0.0262, per CoinMarketCap data. The decline came as traders reacted to the incident rather than a broad market selloff.
The exploit adds to a year in which lending-protocol attacks involving specialized borrowing modes and liquid staking token pricing have emerged as a difficult vector to preempt, because the attack surface turns on the interaction between two independently sound components. Users of More Markets are advised to monitor official channels and weigh withdrawing supported assets until the team confirms the scope of the incident.
This article is for informational purposes only and does not constitute investment advice.