More Markets on Flow EVM Becomes Third DeFi Lending Exploit in Five Days

More Markets, a lending protocol built on Flow EVM, lost about $9.3 million on Sunday after an attacker used a liquid-staking token from Ankr to drain its WFLOW reserve. Blockaid, the security firm that flagged the attack, said 15.5 million WFLOW were emptied from the protocol’s mFlowWFLOW market using a combination of the bonded Ankr token and More Markets’ E Mode setting, a feature that lets certain paired assets borrow against each other at a higher loan-to-value ratio. Blockaid detected an exploit on More Markets (More Labs) on Flow EVM. Attacker used Ankr bonded LST + E-mode to drain the WFLOW lending reserve. 15.5M WFLOW emptied from mFlowWFLOW (~$9.3M detector impact). Attack tx cluster includes post-exploit exfil. More details in — Blockaid (@blockaid_) August 31, 2026 The More Markets incident is not an isolated one. It is the third time in five days that a decentralized lending protocol has lost funds because of how it priced a collateral asset. Moonwell, on Coinbase’s Base network, lost $8.7 million on August 27 after an attacker inflated the price of MAMO, a thinly traded token, and borrowed real bitcoin and stablecoins against it. Three days later, an attacker pushed the price of TONIC, the governance token of Cronos lending protocol Tectonic, roughly 100 times higher in about 20 minutes, draining an estimated $66 million to $75 million and forcing Cronos validators to halt the entire chain. The three attacks hit three unrelated chains with three different attacker wallets and no shared exploit code, but each one turned the same weakness, how a lending market prices a correlated or thinly traded collateral token, against a different protocol. FIVE-DAY WINDOW · AUG 27–31, 2026 More Markets runs on Aave V3 architecture and lists WFLOW with an 81.5% loan-to-value ratio and an 83% liquidation threshold, while ankrFLOW, the liquid-staking token Ankr issues for staked FLOW, carries a 78.5% loan-to-value ratio. E Mode exists to let assets like these, a token and its staked derivative, borrow against each other more efficiently than unrelated assets would. That efficiency is also what made the exploit possible: because the protocol treated the bonded Ankr position as high-quality collateral, the attacker could borrow close to the reserve’s full value once that collateral’s pricing was manipulated. Blockaid has not said Ankr’s own contracts were compromised, and it has not indicated that Flow EVM itself was affected, only that the attacker used a legitimate asset type against the protocol’s own risk settings. Flow has been through this before. A December 27 attack exploited a flaw in the network’s separate Cadence execution layer, allowing an attacker to duplicate tokens and extract close to $3.9 million before validators froze the chain, according to the Flow Foundation’s own technical post-mortem.
عنوان اصلی (انگلیسی): More Markets on Flow EVM Becomes Third DeFi Lending Exploit in Five Days
مشاهدهی خبر کامل در منبع ↗ بازگشت به Ankrاین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.