Crypto Prices

More Markets Hit by Major $9.3 Million Exploit on Flow EVM

2 hours ago
1 min read
1 views

Overview of the More Markets Exploit

More Markets, a decentralized lending protocol built on the Flow EVM architecture, became the target of a significant exploit that drained approximately 15.5 million WFLOW tokens, equating to an estimated financial impact of $9.3 million. The security incident, disclosed on August 31 by blockchain security firm Blockaid, involves a complex interaction between Ankr’s bonded liquid staking token and the protocol’s E Mode functionality.

Details of the Exploit

Blockaid traced the origin of the drained tokens to the mFlowWFLOW lending reserve, detailing the transactional pathways that led to the exploitation. It reported a cluster of transactions moving funds post-exploit, though it has yet to ascertain the total assets the attacker currently holds. Additionally, the firm’s preliminary analysis highlights the potential financial implications, while the exact extent of the loss is still being clarified as investigations continue.

Functionality of More Markets

More Markets operates on Flow EVM, utilizing aspects of Aave V3 architecture, allowing users to deposit assets for interest, borrow against collateral, and enforce liquidation protocols for under-collateralized positions. Supported assets within this lending framework include:

  • WFLOW: with a loan-to-value ratio of 81.5%
  • ankrFLOW: with a ratio of 78.5%

The documentation characterizes WFLOW as the native wrapped asset essential for transactions within the protocol, while ankrFLOW serves as the liquid staking token granted to users staking FLOW through Ankr’s platform.

Investigation and Implications

While Blockaid has not determined whether the exploit was rooted in a flaw within More Markets’ code or an issue with the Ankr asset’s handling, there is an ongoing investigation into the matter. Ankr itself remains unaffiliated with the security breach, according to the information released, though its bonded liquid staking token was specifically implicated in the exploit by the attacker.

Context of the Attack

The attack occurred on applications running in the Flow EVM, which enables Ethereum-compatible operations on Flow. This incident is especially pertinent against a backdrop of a prior attack in late 2025 that saw a serious vulnerability in Flow’s Cadence execution layer exploited, resulting in the creation of counterfeit tokens valued at around $3.9 million.

Following that breach, Flow had to take dramatic measures to secure the network, including a brief halt to all operations and proposals for a comprehensive rollback of transactions, which faced considerable pushback from various stakeholders.

Community Concerns and Future Outlook

The More Markets exploit has raised concerns within the crypto community as it underscores vulnerabilities in decentralized finance (DeFi) platforms. As of now, Blockaid continues to investigate the situation and further details are expected to emerge. As the DeFi ecosystem evolves, the focus on security measures and insurances against such breaches is set to intensify, given the significant sums involved.

Flow has previously touted both More Markets and Ankr as integral components of its DeFi portfolio, promoting various rewards for user engagement in lending and staking activities. However, as this incident develops, it reflects the ongoing challenges faced by decentralized protocols in maintaining robust security frameworks.

Popular