Highlights

  • An attacker drained roughly 15.5 million WFLOW, worth about $9.3 million, from More Markets' lending reserve on Flow EVM.
  • Security firm Blockaid says the exploit paired Ankr's staked FLOW token with Aave V3's efficiency mode to overborrow against the pool.
  • The stolen sum is more than double the protocol's pre-exploit total value locked of roughly $3.99 million, implying the pool now carries significant bad debt.
  • Neither More Markets nor More Labs had published an official post-mortem at the time of reporting.

More Markets, a noncustodial lending protocol built on Aave V3 architecture and deployed on Flow EVM, lost about $9.3 million after an attacker drained 15.5 million WFLOW from its mFlowWFLOW reserve, according to Crypto Banter, citing security firm Blockaid. The firm said the attacker combined an Ankr staked FLOW token with the protocol's efficiency mode to overborrow against the pool.

Futuristic circuit board with glowing ring and abstract digital elements
Photo by Brecht Corbeel on Unsplash

How the Exploit Worked

Blockaid identified the mechanism as "Ankr bonded LST + E-mode," pointing to ankrFLOW, a reward-bearing liquid staking token whose value accrues as staking rewards build up, paired with Aave V3's efficiency mode, a feature designed to let borrowers extract more capital against assets that are supposed to hold a tight price correlation. CryptoTimes reports the vulnerability likely stemmed from how More Markets priced that correlation internally rather than from any flaw in Ankr's own contracts, and traced the attack to a primary exploit transaction and a dedicated attacker contract before funds moved through a separate helper wallet. Blockaid has not implicated Ankr or the Flow blockchain itself, and says the final on-chain loss and destination of the drained assets are still being reconciled.

A Pool That Was Already Thin

What stands out is the size mismatch: More Markets carried only about $3.99 million in total value locked and roughly $3.48 million in active loans before the attack, yet lost $9.3 million — more than double its own TVL. That gap points to the protocol's own reserve and any linked pools absorbing bad debt beyond what was actually deposited, a pattern seen in other E-mode-related exploits where correlated-asset pricing assumptions let attackers borrow well past a pool's real backing.

Related: Cronos Halts Chain After $75M Tectonic Exploit Traps Stolen Funds

Part of a Wider Pattern on Emerging Chains

The incident adds to a run of DeFi exploits on newer or lower-liquidity EVM-compatible chains this year, where lending protocols built quickly atop forked Aave code inherit efficiency-mode features without always re-verifying the price assumptions behind them. For Flow, a chain that has pushed hard to attract EVM-compatible DeFi activity, a high-profile drain so soon after launch risks slowing the deposit growth the ecosystem needs to compete with more established L2s and app-chains.

Forward Look

Watch for a formal post-mortem from More Labs detailing the exact contract flaw and any plan to make affected depositors whole, along with Blockaid's promised update on the final loss figure and whether any funds can be frozen or recovered on-chain.

FAQ

How much was stolen from More Markets?
An attacker drained about 15.5 million WFLOW tokens, which Blockaid estimated at roughly $9.3 million.

What caused the exploit?
Blockaid says the attacker combined Ankr's staked FLOW liquid staking token with Aave V3's efficiency mode to overborrow against More Markets' lending pool.

Was Ankr or Flow itself hacked?
No. Blockaid has not said Ankr's contracts or the Flow blockchain were compromised; it identified More Markets' own pricing integration as the point of failure.

Has More Markets responded?
No official post-mortem or remediation statement had been published by More Markets or More Labs at the time of reporting.