More Markets Exploit: How a Liquid Staking Token and E-Mode Pulled $9.3 Million Out of a Lending Market

Around 15.5 million WFLOW drained from the lending market More Markets on August 31, 2026, worth roughly $9.3 million according to the security firm Blockaid. The attacker needed no stolen keys and no gap in the blockchain underneath. They used two building blocks that are wired into almost every larger lending market: a liquid staking token as collateral, and the so-called E-Mode, which treats both sides of a loan as equivalent. That is precisely why this incident can concern you beyond one small chain. If you have borrowed against staked Ethereum somewhere, or one stablecoin against another, your position is very likely running in the same mode. This article sets out what is established as of today, what remains open, how E-Mode works, and which four details you can look up in your own lending market. More Markets Exploit: What Happened on Flow EVM on August 31, 2026 More Markets is a non-custodial lending market from More Labs that builds on the Aave V3 codebase and runs on Flow EVM. Users deposit assets there to earn interest, or post them as collateral to borrow against. WFLOW and ankrFLOW are among the supported markets. According to Blockaid, the incident began on August 31, 2026 at 07:58 UTC. 15.5 million WFLOW disappeared from the reserve labelled mFlowWFLOW. Blockaid explicitly described the figure of roughly $9.3 million as detected impact and not as a final loss figure; the definitive amount is not yet settled, because the transactions are still being traced. The security firm made the incident public first through its channel on the short-message service X, from where several trade outlets picked it up the same day. More Markets commented briefly on the same day, saying its own team was investigating the reports of an attack and would share its findings. A full post-mortem of the incident is not available at the time of writing. Everything this article says about the sequence of events therefore comes from the security firm's observation and not from the protocol's own analysis. ankrFLOW and E-Mode: How the Attack Worked According to Blockaid Blockaid's brief description is that the attacker used a bonded liquid staking token from Ankr together with E-Mode to empty the WFLOW reserve. Put at greater length: the value of the deposited ankrFLOW holdings was set higher in the protocol than it actually was. Against that overvalued collateral, the attacker borrowed real WFLOW and cleared out the reserve with it. What matters just as much is what that description does not say. Blockaid did not describe either Ankr itself or the Flow blockchain as compromised. On this account, only the More Markets application running on Flow EVM was affected.
عنوان اصلی (انگلیسی): More Markets Exploit: How a Liquid Staking Token and E-Mode Pulled $9.3 Million Out of a Lending Market
مشاهدهی خبر کامل در منبع ↗ بازگشت به Ankrاین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.