
More Markets has suffered a significant exploit on Flow EVM, with blockchain security firm Blockaid estimating the impact at roughly $9.3 million. According to Blockaid's latest disclosure, an attacker drained 15.5 million WFLOW from the protocol's lending reserves using an Ankr bonded liquid staking token (LST) and the protocol's E Mode mechanism. The security firm identified the mFlowWFLOW lending reserve as the source of the drained tokens and published exploit transactions, contract deployment transactions, and a cluster of 11 follow-up transfers used to move funds after the reserve was drained. However, More Markets has not officially confirmed the amount lost, stating that their team is currently investigating the claim and will share findings shortly. The $9.3 million figure represents the initial detector impact, with final bad debt and recoverable assets still to be established.
More Markets is a decentralized, noncustodial lending protocol developed by More Labs deployed on Flow EVM built using Aave V3 architecture. As reported by Blockaid, the protocol supports nine markets and allows users to supply assets for interest, borrow against collateral at variable rates, and liquidate positions. WFLOW and ankrFLOW are among the supported assets, with WFLOW listed at a loan to value ratio of 81.5% and liquidation threshold of 83%, while ankrFLOW has a 78.5% loan to value ratio and 81% liquidation threshold. According to Blockaid, the attacker exploited the protocol's handling of liquid staking tokens (LSTs) through its E-Mode system, which allows users to borrow more against assets considered closely related in value. The attacker reportedly combined an Ankr bonded LST with E-Mode and exploited how More Markets calculated borrowing limits, allowing them to take out loans against manipulated collateral and repeatedly withdraw WFLOW from the protocol's mFlowWFLOW reserve.
The August 31 incident specifically targeted an application running on Flow EVM, with no indication in the initial disclosure that the Flow blockchain itself had been compromised. According to Blockaid's assessment, Flow EVM provides an Ethereum compatible environment on Flow, allowing applications to operate on the network. This distinction is particularly relevant given that Flow suffered a separate security breach in late 2025, when a December 27 attack exploited a vulnerability in Flow's Cadence execution layer and allowed an attacker to duplicate approximately $3.9 million in value. The Flow Foundation subsequently abandoned a proposed full chain rollback and adopted an isolated recovery process to identify and destroy counterfeit assets. As of publication, Flow's EVM Gateway and core block-production infrastructure remained operational throughout the More Markets attack, with mainnet core components including block finalization, transaction execution, block sealing and the network's EVM Gateway remaining operational.
The security incident quickly affected Flow ecosystem tokens, with Wrapped Flow (WFLOW) dropping around 9% within an hour while FLOW fell about 8.7% to $0.0262. The decline came as traders reacted to the exploit rather than a broad crypto market sell-off. On-chain activity showed that the attacker began moving the stolen assets shortly after the exploit, with some funds transferred toward external wallets and bridged away from the Flow EVM ecosystem. More Markets was carrying about $3.64 million in TVL after the exploit surfaced, alongside roughly $3.67 million in active loans. The initial $9.3 million detector impact is therefore substantially larger than the protocol's remaining reported locked value. As of now, there is no confirmed recovery plan or recovered amount from More Markets. The final losses and destination of the assets remain under investigation, with Blockaid noting that more details are still being investigated after identifying the WFLOW outflow and subsequent transaction cluster used to move funds after the exploit.