Security Incident

More Markets Suffers Multi-Million WFLOW Exploit on Flow EVM

According to reporting by crypto.news on August 31, 2026, the decentralized lending protocol More Markets experienced a security exploit on Flow EVM. Blockchain security firm Blockaid reported that roughly 15.5 million WFLOW tokens were drained from the platform's mFlowWFLOW lending reserve, estimating the detected impact at approximately $9.3 million. The incident, which is not officially confirmed by the project team, allegedly involved an interaction between an Ankr bonded liquid staking token and the protocol's E Mode mechanism.

Digital abstract visualization representing smart contract security vulnerabilities and token exploit monitoring on a blockchain network.
Image: crypto.news

Overview of the Flow EVM Incident

Recent reports from crypto.news indicate that the decentralized lending protocol More Markets faced a significant security breach on its Flow EVM deployment. According to the initial intelligence shared by blockchain security firm Blockaid via social media channels on August 31, 2026, malicious actors targeted the platform's liquidity reserves, resulting in a massive outflow of native wrapped assets. The primary target identified in the early disclosures was the mFlowWFLOW lending reserve, which experienced a swift depletion of digital assets before automated defenses or developers could intervene to halt the anomalous transaction sequence.

The security assessment published shortly after the event quantified the initial outflow at approximately 15.5 million WFLOW tokens. While blockchain monitors established that these funds left the protocol reserves instantly, analysts emphasized that the final economic loss and the ultimate destination of the stolen assets are still subjects of active forensic investigation. Security experts continue to map out the complex cluster of transactions used to exfiltrate the capital across various intermediary addresses, making a comprehensive accounting of the exploit's true financial footprint difficult to finalize immediately.

Mechanism Analysis and Potential Vectors

According to the public disclosures issued by Blockaid, the attack vector appeared to leverage an intricate combination of decentralized financial components. Specifically, the security firm linked the exploitation method to the utilization of an Ankr bonded liquid staking token working in tandem with More Markets' dedicated E Mode mechanism. This specialized borrowing mode is typically designed to allow higher loan-to-value ratios for correlated assets, but the interaction with the external liquid staking token appears to have introduced unforeseen vulnerabilities that the attacker successfully manipulated.

More Markets operates as a noncustodial lending protocol built upon a well-known architectural framework, supporting multiple digital assets with specific parameters for collateralization and liquidation thresholds. Although the protocol documentation outlines specific guidelines for wrapped assets and liquid staking tokens like ankrFLOW, the precise code-level flaw that permitted the reserve drainage has not been fully detailed. Observers note that further technical audits are required to determine whether the root cause stems from implementation errors within the lending protocol itself or unexpected pricing assumptions in the asset feeds.

Protocol Architecture and Ecosystem Context

More Markets provides a repository of supported markets allowing users to supply digital assets for interest generation, borrow against collateral at variable rates, and subject under-collateralized positions to liquidation. Within this ecosystem, WFLOW serves as the native wrapped asset, while ankrFLOW represents a reward-bearing liquid staking token issued when users stake their foundational network assets through Ankr's services. The documentation for the staking protocol indicates that ankrFLOW value scales upward relative to the base asset as staking rewards accumulate over time.

The integration of these financial instruments on Flow EVM has previously been promoted within the wider ecosystem through community rewards and promotional liquidity initiatives. However, analysts point out that integrating complex liquid staking derivatives into variable-rate lending markets inherently increases systemic complexity. Independent observers emphasize that while the underlying Flow blockchain infrastructure has not been reported as compromised in this specific incident, the application-layer interaction demands rigorous scrutiny from all participating developers and risk managers.

Historical Background and Network Resilience

The occurrence of this security incident arrives against a backdrop of previous challenges faced by the broader network infrastructure. In late December of the preceding year, the Flow blockchain experienced a notable security breach involving its Cadence execution layer, which allowed an unauthorized duplication of fungible tokens and subsequent extraction of value. That prior network-level event required coordinated emergency responses, temporary validation halts, and extensive asset recovery operations involving major centralized exchanges to mitigate counterfeit token distribution.

Unlike the earlier architectural flaw in the execution runtime, current available data from Blockaid indicates that the More Markets incident is isolated to an application-layer deployment on Flow EVM. Representatives from security firms and ecosystem stakeholders have reiterated that the core consensus mechanisms and network validator sets remain fully operational and separate from the reported lending protocol exploit. Nevertheless, past disruptions have heightened sensitivity among community participants regarding any sudden protocol anomalies or unexpected capital outflows.

Conclusion and Actionable Steps

In conclusion, independent crypto-exchange risk intelligence reporting by crypto.news highlights that More Markets suffered an exploit on Flow EVM, resulting in the drainage of 15.5 million WFLOW valued by Blockaid at approximately $9.3 million. This reported security incident remains not officially confirmed by the affected protocol team or independent third-party auditors at the time of publication. The affected entities include More Markets and its user base holding positions in the vulnerable lending reserves. What changes now is that liquidity providers and borrowers must exercise heightened caution regarding composite DeFi strategies involving liquid staking tokens and specialized borrowing modes, while ongoing forensic tracking continues to map the movement of stolen assets.

As the next action, users currently interacting with More Markets or utilizing related liquid staking assets across Flow EVM should immediately review their exposure, withdraw funds where safety permits, and monitor official communication channels for verified updates. Observers and market participants are advised to separate established reporting from unconfirmed speculation until comprehensive post-mortems and official attestations are released by the development team and security investigators.

Cexvia conclusion

Incident Conclusion and Next Steps

Blockchain security firm Blockaid reported that More Markets suffered an exploit on Flow EVM, draining 15.5 million WFLOW valued at roughly $9.3 million. The specific details, ultimate losses, and potential network vulnerabilities remain not officially confirmed pending further investigative work.

Risk meaning
The incident highlights ongoing smart contract integration risks involving liquid staking tokens and specialized borrowing modes on alternative EVM layers.
User action
Users interacting with lending pools and liquid staking assets on Flow EVM should monitor protocol announcements and evaluate their exposure.
Not Applicable