Points of Focus
- Attackers used unbacked ankrFLOW collateral to drain More Markets reserves.
- Blockaid corrected its $9.3-million estimate to roughly $410,000.
- Tectonic and Moonwell suffered major lending exploits days earlier, too.
More Markets has become the latest DeFi lender caught in a collateral exploit after an attacker used unbacked liquid-staking tokens to drain 15.5 million WFLOW from a lending reserve on Flow EVM.
Blockchain security company Blockaid initially valued the outflow at approximately $9.3 million, triggering widespread reports of a major exploit. It later corrected that estimate, saying the 15.5 million of WFLOW was worth closer to $410,000 at FLOW’s spot price, while the attacker ultimately realized roughly $250,000 after slippage.
Flow said the attacker exploited a vulnerability in Ankr’s ankrFLOW liquid-staking contract rather than Flow itself or More Markets’ underlying contracts. The vulnerability allowed about 8.6 million unbacked ankrFLOW to be created.
Those tokens were then deposited into More Markets as collateral and used with its higher-leverage E-Mode configuration to borrow WFLOW from the mFlowWFLOW reserve.
FLOW fell around 8% as initial reports of the exploit spread, although the token’s decline came amid broader weakness across crypto markets.
A lending protocol called More Markets just got drained for $9.3 MILLION by turning its own borrowing feature against it
It ran on Flow and used a tool called E-mode, which lets you borrow more when your assets move together in price, meant to make lending more efficient
The… pic.twitter.com/DgKfR2tp5d
— Jeremy (@Jeremybtc) August 31, 2026
E-Mode amplified a failure originating outside More Markets
E-Mode, or efficiency mode, allows lending protocols to offer higher borrowing limits when collateral and borrowed assets are expected to remain closely correlated.
A liquid-staking token such as ankrFLOW would ordinarily be expected to track FLOW because it represents staked FLOW underneath.
That assumption broke once the attacker created ankrFLOW without the corresponding backing.
More Markets’ lending system then accepted those tokens as collateral, allowing the attacker to borrow genuine WFLOW against assets that should never have existed.
Flow stressed that the incident did not compromise Flow EVM, the Flow protocol, or FLOW’s tokenomics. Ankr and More Markets paused the affected products, while Flow said the foundation would work with Ankr to replenish the drained WFLOW reserve and rebalance affected liquidity pools.
The episode also illustrates how initial dollar-loss estimates can become distorted when attacks involve thinly traded assets. Blockaid’s first automated estimate valued the drain at $9.3 million, but limited liquidity meant the actual market value and realizable proceeds were substantially lower.
Three lending exploits hit within days
More Markets arrives at the end of a particularly damaging week for decentralized finance (DeFi) lenders.
On Aug. 30, the Cronos blockchain halted after an exploit targeting Tectonic, its largest lending protocol. Onchain researcher Weilin Li estimated $75 million was affected after an attacker manipulated the price of the illiquid TONIC token and borrowed against the inflated collateral.
The attacker reportedly managed to bridge only around $6 million to Ethereum before Cronos stopped the network. Tectonic had not confirmed the final loss when the incident was initially reported.
Three days earlier, Moonwell was hit for approximately $8.7 million on Base.
Security companies CertiK and PeckShield said the attacker manipulated the price of the relatively illiquid MAMO token and used the inflated collateral value to borrow assets, including cbBTC. Moonwell responded by effectively shutting down new borrowing across its Base Core Markets while investigating the incident.
August consequently recorded around $139.7 million in crypto hack losses, according to DefiLlama data, although that remained below July’s roughly $254 million.
The latest incidents share a common weakness. Attackers did not necessarily need to break the lending contracts themselves. Instead, they attacked the assumptions those contracts relied on: whether collateral was genuinely backed, whether its quoted price reflected real liquidity, and whether closely related assets were safe enough to support higher borrowing limits.
For More Markets, the immediate financial impact now appears far smaller than the original $9.3-million headline. The attack still exposes a larger DeFi problem: One faulty asset or external contract can become valid collateral elsewhere and turn a localized vulnerability into a lending-market drain.
Unlock premium content
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share


