DeFi lending infrastructure has suffered another high-value breach on Flow EVM, with Blockaid reporting that the protocol More Markets lost roughly $9.3 million in assets from a lending reserve. The incident, described in a Monday post by Blockaid on X, centers on an overborrow strategy using a liquid staking token.
Blockaid said the attacker drained about 15.5 million Wrapped Flow (WFLOW) tokensโvalued at approximately $9.3 millionโfrom the mFlowWFLOW lending reserve. The exploit reportedly involved Ankr Staked FLOW (ankrFLOW), together with Aave V3โs โefficiency modeโ (E-mode), to expand borrowing capacity beyond what the reserve should allow.
Key takeaways
- Blockaid attributes the More Markets Flow EVM reserve drain to an overborrowing approach using Ankr Staked FLOW (ankrFLOW) and Aave V3 E-mode.
- About 15.5 million Wrapped Flow (WFLOW), worth around $9.3 million, were taken from the mFlowWFLOW lending reserve.
- The month-to-date total losses from crypto hacks reached $139.7 million in August, placing the month as the third-largest by stolen value so far in 2026.
- The August figure is sharply lower than Julyโs $254 million in stolen funds, suggesting either fewer major breaches or reduced impact from exploits.
- Cronos paused its network on Sunday following a separate reported $75 million exploit tied to the Tectonic DeFi lending protocol.
How the More Markets reserve was drained
According to Blockaidโs account of the event, the attacker targeted More Marketsโ lending reserve that holds mFlowWFLOW. Blockaid said the stolen amount consisted of 15.5 million Wrapped Flow (WFLOW) tokens, which it valued at approximately $9.3 million based on blockchain data it shared publicly.
Blockaid further claimed that the exploit depended on two linked mechanisms: the use of Ankr Staked FLOW (ankrFLOW) and Aave V3โs E-mode. E-mode is designed to increase borrowing power for specific asset groups when their values are expected to move togetherโcommonly a liquid staking token and its corresponding underlying token.
In practical terms, this means that when the protocolโs configuration treats certain pairs as sufficiently correlated, the borrowing limits can become more permissive. Blockaidโs report indicates the attacker leveraged that increased borrowing power to overextend against the reserve, resulting in the loss of WFLOW tokens from mFlowWFLOW.
E-mode designed for correlationโwhat this incident suggests
E-mode in Aave V3 is intended to make capital more efficient by rewarding users when asset prices track each other closely. Blockaidโs description of this exploit highlights a recurring risk in DeFi: when an attacker can obtain collateral exposure through a token wrapper or staking derivative, the assumed relationship between the assets may be insufficiently protective during the exploit window.
Blockaid specifically tied the strategy to Ankr Staked FLOW (ankrFLOW) in combination with E-mode for correlated assets. While E-mode is not inherently wrongโits goal is to reflect genuine market linkageโincidents like this underscore that protocols still need robust defenses around liquidation mechanics, borrowing limits, and whether the collateralโs behavior under stress matches the assumptions baked into risk parameters.
For investors and users, the takeaway is not that E-mode should be avoided, but that reliance on correlated asset groups can raise the stakes for monitoring. Protocol teams typically need to ensure that their accounting, oracle choices, and validation logic remain resilient when liquidity conditions change quickly.
Broader hack landscape: August losses mount
Blockaidโs reported loss adds to a fast-moving set of crypto-security events. DefiLlamaโs data on hacks shows that total cryptocurrency losses from hacks reached $139.7 million in August, making it the third-largest month by value stolen so far in 2026.
The same DefiLlama dataset cited in the reporting indicates a meaningful change from earlier in the year: July saw approximately $254 million stolen. While August has a lower total than July, the ongoing frequency of incidentsโspanning multiple ecosystems and chainsโsuggests that attackers remain active and that DeFi lending remains a frequent target.
Another DeFi lending event: Cronos halts after Tectonic exploit
Alongside the More Markets issue, the market also digested another major DeFi lending-related disruption. On Sunday, Cronos halted its blockchain network following a reported $75 million exploit targeting the DeFi lending protocol Tectonic.
That earlier incident, reported by Cointelegraph, involved a sizable compromise that prompted an emergency network pause by Cronos. Together, the two stories emphasize how quickly lending platforms can become central points of failureโespecially when borrowing configurations intersect with token derivatives and liquidity-linked assumptions.
At the time of publication, More Markets had not publicly confirmed the incident or disclosed whether users suffered losses. Cointelegraph said it contacted Blockaid for more details but did not receive a response by publication, and it was unable to reach More Markets for comment.
Readers should watch for follow-up disclosures from More Markets regarding the affected reserve, whether funds were fully recovered, and any post-incident changes to collateral or E-mode configuration. For the wider DeFi community, the key uncertainty is how closely future risk models will account for real-world token behavior during fast-moving market or liquidity conditions.






