
A vulnerability in Ankr’s ankrFLOW liquid-staking contract allowed an attacker to create millions of unbacked tokens and use them as collateral to drain roughly $410,000 from the WFLOW reserve on MORE Markets.
The exploit began at approximately 06:18 UTC on August 31, when the attacker created about 8.6 million unbacked ankrFLOW through a vulnerable Ankr Solidity contract. The tokens were then deposited as collateral on MORE Markets, enabling the attacker to withdraw approximately 15.5 million WFLOW.
ankrFLOW is Ankr’s liquid-staking token for FLOW, designed to represent FLOW deposited through its staking infrastructure. The affected ankrFLOW contract operates on Flow EVM alongside Ankr’s staking pool and ratio infrastructure.
Once the attacker created the unbacked tokens, they were used as collateral inside MORE Markets to borrow against the protocol’s WFLOW reserve. Approximately 15.5 million WFLOW worth $410,000 left the reserve.
The attacker ultimately realized approximately $246,000 after slippage while moving out of the position. The original $9.3 million estimate attached to the attack was based on an initial detector valuation and has since been retracted and corrected to approximately $410,000.
The underlying vulnerability was in Ankr’s Solidity smart contract. Neither MORE Markets’ lending contracts nor Flow EVM were compromised, and the Flow blockchain continued processing transactions normally throughout the attack.
Ankr and MORE Markets paused the affected contracts within hours of the exploit. ankrFLOW staking and MORE Markets lending will remain unavailable until Ankr deploys a contract upgrade addressing the vulnerability.
No MORE Markets or ankrFLOW depositor lost funds, while FLOW holders were also unaffected. The Flow Foundation and Ankr will replace the drained WFLOW in the MORE Markets reserve and rebalance liquidity in the affected ankrFLOW/WFLOW pool.
Some exchange partners temporarily suspended FLOW deposits while the attack was being investigated. Flow has asked those platforms to restore deposits after the exploit was contained and the network remained fully operational.
The attack was confined to the Ankr liquid-staking contract and its downstream use as collateral on MORE Markets. It did not exploit Flow’s EVM implementation, consensus infrastructure or FLOW token mechanics.
The corrected scope separates the attack from the recent Tectonic exploit on Cronos, where manipulated TONIC collateral was used to borrow assets and validators subsequently halted block production. A separate Moonwell attack involved manipulated collateral pricing on Base.
Flow remained operational after the Ankr exploit, while ankrFLOW staking and MORE Markets lending remain paused until Ankr deploys the contract upgrade fixing the vulnerable contract.
The post Ankr Contract Exploit Drains $410K From MORE Markets WFLOW Reserve appeared first on Crypto Adventure.