More Markets Drained Of $9.3M In WFLOW After Attacker Exploits Ankr LST And E-Mode Collateral Pricing

31-Aug-2026 mpost.io
More Markets Drained Of $9.3M In WFLOW After Attacker Exploits Ankr LST And E-Mode Collateral Pricing

Crypto lending protocol More Markets has suffered an exploit resulting in the loss of approximately $9.3 million. Blockchain security firm Blockaid detected the attack on More Labs’ lending protocol operating on Flow EVM, where roughly 15.5 million wrapped WFLOW tokens were drained from the mFlowWFLOW lending reserve.

According to Blockaid’s disclosure, the attacker employed Ankr’s bonded liquid staking token in conjunction with More Markets’ E-mode mechanism to execute the exploit. The attacker appears to have manipulated the perceived value of their collateral, allowing them to borrow genuine WFLOW against artificially inflated collateral and subsequently deplete the protocol’s entire WFLOW lending reserve. 

Blockaid identified the exploit transaction, the initial contract deployment, and a cluster of post-exploit transfers used to exfiltrate funds following the drainage, though the firm had not provided a final accounting of the attacker’s holdings at the time of disclosure.

More Markets operates as a decentralized, noncustodial lending protocol built on Aave V3 architecture and deployed on Flow EVM. The platform lists nine supported markets where users supply assets to earn interest, borrow against collateral at variable rates, and liquidate positions falling below required collateral levels. WFLOW, the native wrapped asset, carries an 81.5% loan-to-value ratio and 83% liquidation threshold, while ankrFLOW holds a 78.5% LTV and 81% liquidation threshold.

Application-Layer Scope Distinguishes Exploit from Flow’s Prior Network Breach

The ankrFLOW token, issued by Ankr, functions as a reward-bearing liquid staking token whose value appreciates relative to FLOW as staking rewards accumulate, without altering the holder’s token balance. Ankr’s documentation states that its Flow liquid staking contracts on both Cadence and EVM underwent external audits by Halborn. 

Blockaid’s analysis did not identify Ankr itself as compromised, specifying only that the bonded LST and More Markets’ E Mode served as components in the attacker’s methodology. The precise technical sequence remains undisclosed, leaving uncertainty whether the vulnerability originated in More Markets’ implementation, the handling of the Ankr asset, its pricing assumptions, or an interaction between these components.

The incident targeted an application operating within Flow EVM, an Ethereum-compatible execution environment on the Flow blockchain, with no indication that the underlying network infrastructure was compromised. This distinction carries importance given Flow’s recent security history. In December 2025, a separate attack exploited a vulnerability in Flow’s Cadence execution layer version 1.8.8, enabling the duplication of a protected asset disguised as a standard data structure and the extraction of approximately $3.9 million. 

That incident involved over one billion counterfeit FLOW tokens minted and distributed to centralized exchanges, though 484.4 million were subsequently returned by OKX, Gate.io, and MEXC and destroyed, while the network isolated 98.7% of the remaining counterfeit supply.

Following the disclosure, the More Markets team reported that it was investigating claims that the protocol had been exploited and that it would share its findings shortly.

The post More Markets Drained Of $9.3M In WFLOW After Attacker Exploits Ankr LST And E-Mode Collateral Pricing appeared first on Metaverse Post.

Also read: HEMI Just Jumped 29% in a Day After a String of August Announcements
WHAT'S YOUR OPINION?
Related News