More Markets Drained Of $9.3M In WFLOW After Attacker Exploits Ankr LST And E-Mode Collateral Pricing

Crypto lending protocol More Markets has suffered an exploit ensuing within the lack of roughly $9.3 million. Blockchain safety agency Blockaid detected the assault on More Labs’ lending protocol working on Flow EVM, the place roughly 15.5 million wrapped WFLOW tokens had been drained from the mFlowWFLOW lending reserve.
According to Blockaid’s disclosure, the attacker employed Ankr’s bonded liquid staking token at the side of More Markets’ E-mode mechanism to execute the exploit. The attacker seems to have manipulated the perceived worth of their collateral, permitting them to borrow real WFLOW towards artificially inflated collateral and subsequently deplete the protocol’s whole WFLOW lending reserve.
Blockaid recognized the exploit transaction, the preliminary contract deployment, and a cluster of post-exploit transfers used to exfiltrate funds following the drainage, although the agency had not supplied a closing accounting of the attacker’s holdings on the time of disclosure.
More Markets operates as a decentralized, noncustodial lending protocol constructed on Aave V3 structure and deployed on Flow EVM. The platform lists 9 supported markets the place customers provide property to earn curiosity, borrow towards collateral at variable charges, and liquidate positions falling beneath required collateral ranges. WFLOW, the native wrapped asset, carries an 81.5% loan-to-value ratio and 83% liquidation threshold, whereas ankrFLOW holds a 78.5% LTV and 81% liquidation threshold.
Application-Layer Scope Distinguishes Exploit from Flow’s Prior Network Breach
The ankrFLOW token, issued by Ankr, features as a reward-bearing liquid staking token whose worth appreciates relative to FLOW as staking rewards accumulate, with out altering the holder’s token stability. Ankr’s documentation states that its Flow liquid staking contracts on each Cadence and EVM underwent exterior audits by Halborn.
Blockaid’s evaluation didn’t determine Ankr itself as compromised, specifying solely that the bonded LST and More Markets’ E Mode served as elements within the attacker’s methodology. The exact technical sequence stays undisclosed, leaving uncertainty whether or not the vulnerability originated in More Markets’ implementation, the dealing with of the Ankr asset, its pricing assumptions, or an interplay between these elements.
The incident focused an software working inside Flow EVM, an Ethereum-compatible execution surroundings on the Flow blockchain, with no indication that the underlying community infrastructure was compromised. This distinction carries significance given Flow’s latest safety historical past. In December 2025, a separate assault exploited a vulnerability in Flow’s Cadence execution layer model 1.8.8, enabling the duplication of a protected asset disguised as a regular information construction and the extraction of roughly $3.9 million.
That incident concerned over one billion counterfeit FLOW tokens minted and distributed to centralized exchanges, although 484.4 million had been subsequently returned by OKX, Gate.io, and MEXC and destroyed, whereas the community remoted 98.7% of the remaining counterfeit provide.
Following the disclosure, the More Markets staff reported that it was investigating claims that the protocol had been exploited and that it might share its findings shortly.
The publish More Markets Drained Of $9.3M In WFLOW After Attacker Exploits Ankr LST And E-Mode Collateral Pricing appeared first on Metaverse Post.

Blockaid detected an exploit on More Markets (More Labs) on Flow EVM. Attacker used Ankr bonded LST + E-mode to empty the WFLOW lending reserve. 15.5M WFLOW emptied from mFlowWFLOW (~$9.3M detector affect). Attack tx cluster contains post-exploit exfil.
(@MORE_DeFi)