More Markets lending reserve drained for $9.3M: Blockaid
Decentralized finance (DeFi) protocol More Markets experienced a $9.3 million drain from its lending reserve on Flow EVM, as reported by Web3 security platform Blockaid.
Intelligence analysis by Gemini 2.5 Flash

The exploit involved an attacker using an Ankr liquid staking token (ankrFLOW) and an Aave V3 feature called E-mode to overborrow from More Markets' mFlowWFLOW lending reserve, resulting in the theft of approximately 15.5 million Wrapped Flow (WFLOW) tokens.
Imagine a special bank where you can borrow money using your toys as collateral, and if you have two toys that are usually worth the same amount, the bank lets you borrow even more. Someone figured out a trick to make the bank think their special 'Flow' toy was worth more than it was, letting them borrow and run off with about $9.3 million worth of other people's 'Flow' toys from a place called More Markets.
Analysis
More Markets
The decentralized finance (DeFi) vault infrastructure protocol, More Markets, recently suffered a significant security breach, leading to the drainage of approximately $9.3 million in digital assets. The incident, first reported by Web3 security platform Blockaid, involved the mFlowWFLOW lending reserve on the Flow EVM. Specifically, the attacker managed to siphon off about 15.5 million Wrapped Flow (WFLOW) tokens, a substantial sum that underscores the financial risks inherent in the DeFi space.
At the time of the report's publication, More Markets had not yet publicly acknowledged the incident or provided details regarding potential user losses. This lack of immediate communication from the affected protocol can exacerbate concerns among users and the wider community, highlighting the challenges in incident response within decentralized environments. The reliance on third-party security firms like Blockaid for initial disclosures often leaves stakeholders in a state of uncertainty.
E-mode
The method of attack leveraged a combination of an Ankr Staked FLOW (ankrFLOW) liquid staking token and a specific feature known as E-mode. E-mode, or efficiency mode, is an integral component of the Aave V3 protocol, designed to enhance borrowing power for assets that are expected to exhibit correlated price movements. This feature is particularly relevant for liquid staking tokens and their underlying assets, as their values typically move in tandem.
In this exploit, the attacker seemingly manipulated the E-mode functionality in conjunction with ankrFLOW to overborrow from the More Markets reserve. This suggests a sophisticated understanding of the protocol's mechanics and the interplay between different DeFi primitives. The incident serves as a stark reminder that features intended to optimize capital efficiency can, if not rigorously secured and monitored, become vectors for exploitation, leading to substantial financial losses.
August
The More Markets exploit contributed significantly to the total value stolen from cryptocurrency hacks in August, pushing the month's cumulative losses to $139.7 million. This figure positions August as the third-largest month by value stolen so far in 2026, indicating a persistent and substantial threat landscape for the crypto industry. While this amount represents a notable decrease from the $254 million stolen in July, it still signifies a concerning trend of large-scale security breaches.
This incident was not isolated, as the article also references another major exploit that occurred just days prior. On Sunday, the Cronos blockchain network was temporarily halted following a reported $75 million exploit targeting the DeFi lending protocol Tectonic. The proximity of these two high-value hacks within the same month underscores the ongoing challenges faced by DeFi platforms in safeguarding user funds and maintaining the integrity of their protocols against determined attackers.
Key points
- More Markets' lending reserve on Flow EVM was drained of approximately $9.3 million in Wrapped Flow (WFLOW) tokens.
- Web3 security platform Blockaid reported the exploit, identifying the use of an Ankr liquid staking token (ankrFLOW) and Aave V3's E-mode feature.
- The attacker leveraged E-mode to overborrow from the mFlowWFLOW lending reserve.
- This incident contributed to August 2026's total crypto hack losses reaching $139.7 million, making it the third-largest month for stolen value.
- More Markets had not publicly confirmed the incident or user losses at the time of publication.
The repeated occurrence of multi-million dollar exploits, such as the More Markets incident, erodes trust in DeFi protocols and could lead to increased regulatory scrutiny. This persistent security risk may deter new users and institutional investors from entering the decentralized finance space, hindering its growth and adoption.



