The More Markets lending exploit that circulated on 31 August 2026 was not a $9.3 million drain on Flow EVM: revised figures put actual losses at roughly $410,000 at spot pricing, with the attacker realising approximately $246,000 after slippage. Blockaid deleted its initial post and issued a correction after the Flow Foundation attributed the root cause to a vulnerability in Ankr’s ankrFLOW liquid staking smart contract.
How the Ankr contract flaw enabled the More Markets lending exploit
According to the Flow Foundation’s post-incident statement, an attacker exploited a vulnerability in Ankr’s ankrFLOW contract at approximately 06:18 UTC, minting around 8.6 million unbacked ankrFLOW tokens. Those tokens were then deposited as collateral on More Markets, where E-mode (Aave V3’s Efficiency Mode) amplified their borrowing power against the mFlowWFLOW reserve.
E-mode raises the loan-to-value ceiling for asset pairs the protocol treats as tightly correlated. On More Markets, which is built on Aave V3 architecture, Wrapped Flow (WFLOW) carries a loan-to-value ratio of 81.5% and a liquidation threshold of 83%. ankrFLOW sits at a 78.5% LTV with an 81% liquidation threshold. With unbacked tokens, the attacker overborrowed WFLOW from the reserve before positions could be liquidated.
Blockaid’s alert went out at 07:54 UTC; the exploit transaction itself was timestamped 07:58 UTC, per CryptoNews.net’s reconstruction of on-chain data. The apparent four-minute gap suggests Blockaid’s monitoring flagged preparatory contract deployment activity ahead of the actual drain.
ankrFLOW is a reward-bearing Liquid Staking Token (LST): its fair value relative to FLOW increases over time as staking rewards accumulate inside the token, while the holder’s token balance stays fixed. Ankr’s documentation states that its Flow liquid staking contracts on both Cadence and EVM underwent external audits by Halborn. The vulnerability exploited was apparently not caught by that review.
No depositor losses, but questions remain for LST collateral design
The Flow Foundation confirmed that no depositor lost funds, and said it would coordinate with Ankr to replace the drained WFLOW and rebalance affected liquidity pools. More Markets stated that no smart contract was compromised and that the protocol functioned as designed, a technically accurate but cold comfort given that the design’s interaction with unbacked LST collateral is precisely what the attacker exploited.
DefiLlama classifies the incident under the ‘Ankr’ entity rather than ‘More Markets,’ categorising it as an ‘Unbacked Mint’ attack under ‘Token and Share Accounting.’ That framing matters: the protocol layer held, but the collateral layer did not.
The broader implication for Aave V3 forks is direct. E-mode is designed for assets whose prices are structurally correlated, but correlation assumptions break the moment an LST’s backing becomes fictitious. Any lending market that accepts LSTs in E-mode inherits exposure to the upstream minting logic of the LST issuer’s smart contracts, which sit outside the lending protocol’s own audit perimeter.
August 2026 in context: 50 incidents, $136.3 million lost
The More Markets incident landed in a month that set a grim record for hack frequency. According to PeckShield data reported by Yahoo Finance, August 2026 recorded 50 major crypto hacks, the highest monthly count of the year, with total losses of approximately $136.3 million, down around 49.5% from July. The snippet cited a DefiLlama figure of $139.7 million for August; the PeckShield tally differs, and the PeckShield figure is used here as it comes from a named security firm’s published count.
The dominant event was the Tectonic exploit on Cronos, which reportedly accounted for roughly $74 million of August’s total, making it the fourth-largest crypto theft of 2026 to date. The attacker moved only about $6 million to Ethereum before Cronos validators froze the network.
For broader context: TRM Labs recorded 207 separate crypto hacks across H1 2026, the highest in any six-month period, but total losses of $972 million were less than half the $2.3 billion stolen in H1 2025. The typical incident in that half-year resulted in losses of around $219,000, meaning the More Markets exploit, even at the revised $410,000 figure, sits slightly above the statistical average for 2026 hacks.
The next question is whether Ankr’s post-mortem identifies the specific contract logic that allowed the unbacked mint, and whether other chains running ankrFLOW deployments face the same vector.
