A More Markets exploit reportedly moved 15.5 million WFLOW and caused an estimated $9.3 million impact. The final loss remains unconfirmed.A More Markets exploit reportedly moved 15.5 million WFLOW and caused an estimated $9.3 million impact. The final loss remains unconfirmed.

More Markets Exploit Reportedly Drains WFLOW Reserves on Flow EVM

2026/08/31 16:06
5 мин. читање
За повратни информации или грижи во врска со оваа содржина, ве молиме контактирајте нè на [email protected]

More Markets, a lending protocol on Flow EVM, has reportedly suffered an exploit involving an Ankr-related liquid staking token and its E-Mode lending system.

Preliminary monitoring identified about 15.5 million WFLOW moving out of the mFlowWFLOW reserve, with the impact estimated at roughly $9.3 million. Investigators are still tracing the funds, so the amount transferred should not yet be treated as the protocol’s final loss.

The early evidence points to a problem within the lending market rather than an attack on the Flow blockchain itself. It also does not prove that Ankr’s staking protocol was compromised.

How the WFLOW Reserve Was Reportedly Drained

More Markets is built on Aave V3 architecture. Users supply assets as collateral and borrow other tokens from the protocol’s reserves.

According to the preliminary attack analysis, the attacker used an Ankr-related bound liquid staking token as part of the collateral process. The position was then placed into E-Mode, which appears to have increased the amount of WFLOW that could be borrowed.

The reported path was relatively direct: the attacker obtained or created the relevant staking asset, used it to gain borrowing power, entered E-Mode and withdrew WFLOW from the available lending reserve. The funds were then moved through a group of related transactions.

The exact weakness has not been confirmed. It may have involved the way More Markets counted the staking token, the way E-Mode valued the position or a mismatch between the token’s transfer rules and the protocol’s collateral calculations.

Until More Markets publishes a technical report, describing the incident as an oracle attack or a flaw in the underlying Aave V3 code would be premature.

E-Mode Turned a Small Assumption Into a Larger Exposure

E-Mode is designed for assets expected to stay close in value. In this case, WFLOW and ankrFLOW both represent exposure to FLOW, so treating them as correlated assets may appear reasonable.

That relationship allows a protocol to give users more borrowing power. The trade-off is a smaller safety margin if the two assets stop behaving as expected.

Liquid staking tokens are not simply wrapped copies of their underlying assets. Ankr describes ankrFLOW as a reward-bearing token whose value against FLOW can increase over time. Its redemption process may also involve an unbonding period.

These differences matter. A lending protocol must understand not only the token’s market price but also how it is minted, transferred, redeemed and recorded in user balances. If one of those behaviors is handled incorrectly, E-Mode can turn an accounting mismatch into real borrowing capacity.

From MEXC’s perspective, this is the central issue. The incident appears less like a broad failure of Flow EVM and more like a failure to account for how a specific collateral asset behaved inside an aggressive lending mode. Reusing audited lending code does not remove the risks created by new collateral integrations.

The Final Loss May Differ From the $9.3 Million Estimate

The reported movement of 15.5 million WFLOW shows the potential size of the incident, but it does not reveal how much money the protocol will ultimately lose.

Some value may remain in the attacker’s collateral position. Funds could also be moved repeatedly between related addresses, making the transaction total larger than the actual amount removed. Recovery efforts, asset freezes and any remaining collateral will affect the final result.

For lenders, the more important number is the bad debt left in the WFLOW reserve. If the attacker borrowed more than the remaining collateral can repay, mFlowWFLOW holders may face a shortfall.

A clear reserve report from More Markets is therefore more useful than another estimate of the attacker’s transfers. It should show the WFLOW still available, the outstanding debt and whether affected deposit claims remain fully backed.

The Next Update Will Determine Whether the Damage Spreads

The immediate risk appears concentrated around More Markets and the affected WFLOW market. There is no confirmed evidence that the Flow network or other Flow EVM applications share the same weakness.

Users should now watch for an official post-mortem, the status of deposits and withdrawals, and the location of the transferred funds. It will also be important to learn whether More Markets has frozen the affected collateral, disabled new borrowing or introduced a recovery plan.

The event may also cause other lending protocols to review liquid staking assets placed in high-efficiency collateral groups. Two tokens can follow the same price while still behaving differently at the contract level. That difference becomes dangerous when a protocol allows users to borrow close to the full value of their collateral.

For FLOW traders, the market impact will depend less on the headline attack amount and more on whether the problem remains limited to one protocol. Evidence of wider exposure would increase the risk, while a contained incident with a clear recovery plan would reduce it.

FAQ

How much was lost in the More Markets exploit?

Preliminary monitoring estimated an impact of about $9.3 million and identified roughly 15.5 million WFLOW moving from the mFlowWFLOW reserve. The final loss has not been confirmed.

Was Flow EVM itself hacked?

Current evidence points to an exploit involving More Markets’ lending system. There is no confirmed indication that the Flow blockchain or Flow EVM infrastructure was compromised.

Did the attacker exploit Ankr?

An Ankr-related liquid staking token was reportedly used in the attack path, but this does not prove that Ankr’s protocol was hacked. The weakness may have been in how More Markets integrated and valued the asset.

Risk Warning

The attack path, affected balance and final loss remain under investigation. Early on-chain estimates may include repeated transfers or assets that are still recoverable. Users should confirm the operating status of More Markets directly before supplying, borrowing or withdrawing assets. DeFi lending and liquid staking products carry smart-contract, collateral, liquidity and liquidation risks.

Research checked outside article body: More Markets protocol repository and market configuration, More Markets documentation, Ankr Flow liquid staking documentation, Flow ecosystem documentation.

AI Reshapes the Memory Market?

AI Reshapes the Memory Market?AI Reshapes the Memory Market?

SanDisk shifts to supplying AI infrastructure

Секој напис напишан од нашиот внатрешен уреднички тим на MEXC News е само за општи информативни цели и не претставува финансиски, инвестициски или трговски совет. Пазарите на криптовалути се многу нестабилни. Секогаш направете сопствено истражување и независно проверете ги информациите пред да донесете какви било финансиски одлуки. MEXC не е одговорен за какви било загуби што произлегуваат од потпирање на оваа содржина. Ако сметате дека некоја содржина ги прекршува правата на трети страни, ве молиме контактирајте на [email protected] за отстранување.

4 Ways to Put Your BTC to Work

4 Ways to Put Your BTC to Work4 Ways to Put Your BTC to Work

Low-fee buys, Earn, DCA & 0% loans. Up to 100% APR!