
More Markets, a decentralized lending protocol deployed on Flow EVM, has suffered an exploit that drained approximately 15.5 million Wrapped FLOW (WFLOW) tokens from its mFlowWFLOW lending reserve, according to blockchain security firm Blockaid.
Blockaid estimated the affected assets at about $9.3 million. The firm described that figure as the detector impact, while the final loss and the ultimate destination of the funds remain under investigation.
The incident was detected on August 31, 2026. Blockaid said the attack involved an Ankr bonded liquid staking token and More Markets’ Efficiency Mode, commonly called E-Mode.
More Markets said it was investigating a claim that the protocol had been exploited and would publish its findings. The team has not yet released a final technical explanation or confirmed a final recovery amount.
According to Blockaid’s on-chain investigation, the attacker drained the WFLOW reserve and then moved funds through a cluster of post-exploit transactions. The security firm identified the movement of assets away from the original reserve but did not provide a final accounting of all funds under the attacker’s control.
More Markets is a decentralized, non-custodial liquidity protocol built on Aave V3 architecture and deployed on Flow EVM. Its public source repository says the protocol allows users to supply digital assets, borrow against collateral and liquidate undercollateralized positions.
The repository lists nine supported markets on Flow EVM. They include WFLOW, ankrFLOW, WETH, WBTC, cbBTC, USDF, stgUSDC and PYUSD0, with WBTC and cbBTC listed as frozen while the other markets shown in the configuration are active.
More Markets’ listed risk parameters assign WFLOW an 81.5% loan-to-value ratio and an 83% liquidation threshold. AnkrFLOW is listed with a 78.5% loan-to-value ratio and an 81% liquidation threshold.
The protocol’s market documentation describes E-Mode as a feature for closely correlated assets that can provide higher loan-to-value ratios. The system also uses health-factor checks, liquidation mechanisms, supply and borrowing caps, isolation mode and price feeds.
Blockaid linked the exploit specifically to the combination of Ankr’s bonded liquid staking token and More Markets’ E-Mode mechanism. However, the available evidence does not establish that Ankr’s own smart contracts were breached.
Ankr’s documentation describes ankrFLOW as a reward-bearing liquid staking token representing staked FLOW. Its value relative to FLOW increases as staking rewards accumulate, while the token balance itself does not necessarily increase.
Ankr also documents a dedicated Flow liquid staking system that includes an ankrFLOW token, staking pool, staking configuration and a ratio feed. Ankr says its Flow liquid staking Cadence and EVM smart contracts underwent an external audit by Halborn in August 2024.
The existence of that audit does not establish the security of the complete More Markets integration. The two systems have separate code, configurations and operational assumptions.
More Markets’ public repository lists security reviews by PeckShield in December 2024 and Zenith in January 2025. It also lists several historical audits of the underlying Aave V3 protocol, including reviews by OpenZeppelin, Trail of Bits, SigmaPrime, Certora, ABDK and PeckShield.
The precise technical failure behind the August 31 exploit has not been established publicly. The initial disclosures do not conclusively show whether the problem originated in More Markets’ implementation, the way ankrFLOW was integrated, pricing or collateral assumptions, the E-Mode configuration, or an interaction between those components.
That distinction is important because E-Mode is intended to increase capital efficiency for assets considered closely related in value. Its use does not by itself indicate a software vulnerability.
Market prices also reacted after the incident became public. Reporting on the event placed WFLOW’s decline at roughly 9%, while FLOW fell about 8.7% during the initial market reaction.
The exploit also comes after a separate Flow security incident in December 2025 involving the network’s Cadence execution environment. That earlier incident was not identified as the cause of the More Markets attack, and there is currently no evidence in the available reporting that Flow’s underlying blockchain consensus or EVM infrastructure was compromised in this case.
The size of the drained reserve should also not be confused with a final protocol-loss figure. Blockaid’s 15.5 million WFLOW figure refers to the amount observed leaving the mFlowWFLOW reserve, while its approximately $9.3 million figure is an initial detector impact estimate.
A final assessment will depend on the protocol’s investigation, reconciliation of the affected positions and continued tracing of the post-exploit transactions.
For now, the confirmed picture is that More Markets’ WFLOW lending reserve was drained on Flow EVM, Blockaid connected the attack to ankrFLOW and E-Mode, and the protocol is investigating the incident. The exact root cause, final economic loss and any potential recovery remain unresolved.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.


