Follow

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Subscribe

Ankr Contract Flaw Drove More Markets WFLOW Exploit, Actual Loss $410K

More Markets WFLOW exploit More Markets WFLOW exploit

The More Markets WFLOW exploit on Flow EVM drained 15.5 million WFLOW from the protocol’s mFlowWFLOW lending reserve on 31 August, but the headline damage figure has already been revised down sharply: blockchain security firm Blockaid corrected its initial $9.3 million estimate and deleted the original post, with independent analysis from Shattered.io and reporting by Yahoo Finance, citing Flow Foundation, placing the actual value of tokens drained at approximately $410,000, with roughly $246,000 realised by the attacker after slippage.

Ankr Contract Flaw, Not More Markets Code

Flow Foundation’s statement, reported by Yahoo Finance, identifies the root cause as a vulnerability in Ankr‘s ankrFLOW liquid staking contract rather than a flaw in More Markets’ own smart contracts or in Flow EVM itself. The attacker used that vulnerability to mint approximately 8.6 million unbacked ankrFLOW tokens, then deposited them into More Markets as collateral.

What made the collateral go further than it should have is E-Mode, the Efficiency Mode feature More Markets inherited from its Aave V3 architecture. According to BigGo Finance, E-Mode treats ankrFLOW and WFLOW as closely correlated assets, granting enhanced borrowing limits beyond the standard loan-to-value parameters. More Markets lists ankrFLOW at a 78.5% LTV and an 81% liquidation threshold under normal terms; WFLOW sits at 81.5% LTV and an 83% liquidation threshold. With the fraudulent collateral qualifying for E-Mode’s elevated limits, the attacker borrowed WFLOW until the reserve was effectively emptied.

The exploit began at approximately 06:18 UTC. Blockaid published its alert at 07:54 UTC, roughly 90 minutes after the funds had already moved, per Yahoo Finance’s account of the Flow Foundation timeline. Crypto Times reports Blockaid identified the exploiter address as 0xa1E…6A7Cc, a helper wallet at 0xA0C…b3702, and the victim contract as the More Markets Pool at 0xbC92…F2c8d.

More Markets WFLOW Exploit Response: Paused, Solvent, Under Review

Flow Foundation says it will work with Ankr to replace the drained funds and rebalance affected liquidity pools. Both ankrFLOW staking and More Markets lending remain paused pending an Ankr contract upgrade. More Markets has stated the protocol is solvent and that no user funds have been lost, per Yahoo Finance’s reporting on the Flow Foundation statement.

The framing matters: this is an application-layer incident, not a network-level breach. Flow EVM itself was not compromised, and the attack vector disclosed so far traces entirely to the Ankr LST contract and the way More Markets’ E-Mode handled its collateral valuation. Flow has separately promoted both More Markets and Ankr within its DeFi ecosystem, including through its Community Rewards programme, which offered incentives for activity in More Markets and for staking FLOW through Ankr’s liquid staking product.

That context is worth holding alongside Flow’s record. A separate incident in December 2025 exploited a flaw in Flow’s Cadence execution layer, allowing an attacker to duplicate fungible tokens and extract approximately $3.9 million in value. That attack forced validators to halt the chain, prompted a contested rollback debate, and eventually resulted in Flow destroying counterfeit supply and seeking a South Korean court order to prevent Upbit, Bithumb and Coinone from delisting FLOW. The current More Markets incident has not produced anything comparable at the network level.

The August More Markets WFLOW exploit did not occur in isolation. Yahoo Finance, citing DefiLlama data, reports 37 hacks across DeFi in August 2026 totalling roughly $140 million. Cronos halted its blockchain on 30 August after identifying an exploit at Tectonic, its largest lending market. Moonwell lost an estimated $8.7 million the prior week. The pattern is consistent with what the sector sees periodically: LST rehypothecation into lending markets, combined with correlated-asset borrowing modes, remains an exploit surface that audits have not fully closed.

The immediate catalyst to watch is the Ankr contract upgrade. Until that is deployed and audited, ankrFLOW collateral cannot safely re-enter More Markets or any other lending protocol on Flow EVM without the same unbacked-mint vector remaining open.

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use