Flow-based DeFi lending protocol More Markets suffered a reserve drainage of about $9.3 million in digital assets, according to security firm Blockaid. Blockaid said the attacker extracted roughly 15.5 million Wrapped Flow (WFLOW) tokens from the protocolโs mFlowWFLOW lending reserve on the Flow EVM network.
The incident, outlined in a Monday post on X by Blockaid (see Blockaidโs report), highlights how lending platforms that support liquid staking tokens can be vulnerable when borrowing mechanics are combined with liquidity and efficiency-mode features.
Key takeaways
- $9.3 million worth of WFLOW was reportedly drained from More Marketsโ mFlowWFLOW lending reserve on Flow EVM.
- Blockaid attributes the attack to the use of ankrFLOW (Ankr Staked FLOW) and Aave V3 E-mode overborrowing conditions.
- The exploitation contributed to total crypto hack losses of $139.7 million in August 2026, per DefiLlama.
- While August thefts remain the third-largest month of 2026 so far, they are far below $254 million stolen in July, according to DefiLlama data.
- More Markets has not publicly confirmed the incident or disclosed potential user losses as of publication.
How Blockaid says the Flow EVM exploit worked
In its analysis, Blockaid linked the theft to the borrowing and collateral logic used inside the protocol. The security firm said the attacker used Ankr Staked FLOW (ankrFLOW), a liquid staking token, together with E-modeโa feature associated with Aave V3.
E-mode (short for efficiency mode) is designed to increase borrowing power for certain asset pairs when their prices are expected to move together. Blockaidโs explanation focuses on the relationship between a liquid staking token and its underlying asset: if the tokenized staking position (ankrFLOW) behaves closely to the underlying FLOW, then the protocol may assign more favorable risk parameters under E-mode.
According to Blockaid, the attacker leveraged those assumptions to overborrow from the mFlowWFLOW reserve and drain liquidity. Blockaidโs public figures point to 15.5 million WFLOW tokens being pulled from the reserve and valued at about $9.3 million in the incident.
What the reserve drainage means for DeFi risk management
Incidents like this tend to raise a difficult question for DeFi lenders: how to balance the capital efficiency benefits of supporting liquid staking derivatives against the edge cases that can emerge when borrowing rules are pushed to their limits.
E-mode is meant to reflect a correlation between assets, but the way correlation is enforced on-chain can be exploited if attackers can find a path where collateral valuation, liquidity availability, or borrowed asset dynamics allow them to extract value faster than the system can correct risk exposure. In this case, Blockaid specifically cited E-mode plus the use of a liquid staking token to achieve an outcome that resulted in reserve depletion.
For users, the immediate practical takeaway is less about the specific tokens involved and more about the mechanics. When a lending market supports efficiency-mode pairings between liquid staking tokens and their underlying assets, traders and depositors should watch for whether the platform can demonstrate robust controls under volatile or abnormal borrowing conditions.
Hack totals for August remain elevatedโyet down from July
The Flow EVM theft adds to the broader picture of crypto security losses in 2026. Blockaidโs report comes as overall monthly totals have remained high.
DefiLlama data shows that losses from cryptocurrency hacks reached $139.7 million in August, making it the third-largest month by value stolen so far in 2026. Even so, Augustโs total represents a substantial drop from $254 million stolen during July, according to the same DefiLlama dataset on hacks (see DefiLlamaโs hacks dashboard).
That comparison matters for risk perceptions. A decline from one peak month does not imply fewer vulnerabilities overallโit may instead reflect differences in the types of exploits that surfaced, the speed of mitigation once attacks begin, or the particular concentration of high-value DeFi targets in each month.
Other network disruption: Cronos pauses after Tectonic exploit
Blockaidโs account of the More Markets drainage arrives amid other DeFi-related security actions. On Sunday, Cronos halted its network after a reported $75 million exploit targeting the DeFi lending protocol Tectonic, according to earlier coverage from Cointelegraph (see that report).
Taken together, the two incidents underscore how quickly lending infrastructures can draw attention from attackers and how governance and incident responseโwhether pausing a chain or adjusting protocol controlsโcan become a determining factor in whether additional losses are contained.
Unanswered questions for More Markets users
As of the time of publication, More Markets had not publicly confirmed the incident or disclosed whether any user losses occurred. Cointelegraph attempted to obtain additional details by contacting Blockaid, but received no response by publication. The outlet also was unable to reach More Markets for comment.
Readers should watch for a formal More Markets statement, any post-mortem describing which reserve controls were bypassed, and whether the platform (and related integrations) plans to adjust E-mode or liquid staking collateral parameters to reduce the chance of a repeat.






