More Markets Drains WFLOW, $9.3M on Flow EVM

Blockaid published the exploit transaction details, identifying the primary exploit hash as 0x2b2e6ea6c and noting a related contract deployment trace, with a cluster of post-exploit transfers showing funds moving after the reserve was drained.
External audits for Ankr’s Flow liquid staking contracts on both Cadence and EVM were conducted by Halborn, providing additional context on the LST controls implicated in the incident.
WFLOW is described as the ERC-20-compatible wrapped representation of FLOW used within Flow EVM, the asset involved in the drain.
Blockaid’s disclosures indicate that it did not identify Ankr itself as compromised in relation to the exploit, leaving open questions about where the compromised assets ultimately resided.
More Markets, a lending protocol on Flow EVM, lost approximately 15.5 million WFLOW tokens in an exploit on August 31. Blockaid valued the loss at roughly $9.3 million. The attacker weaponized Ankr's bonded liquid staking token alongside More Markets' E-Mode borrowing feature to manipulate collateral values and extract funds from the mFlowWFLOW reserve.
The attack highlights a critical vulnerability in DeFi protocols that combine liquid staking tokens with complex borrowing mechanics. Blockaid has traced the primary exploit transaction and subsequent asset transfers, though investigators are still mapping the attacker's final holdings and determining the complete scope of losses.
The attacker combined two features to drain the reserve. First, they used Ankr's bonded FLOW staking token (ankrFLOW) alongside WFLOW—Flow's ERC-20 wrapped token—within More Markets' E-Mode borrowing system. E-Mode allows higher borrowing ratios between related assets. WFLOW carries an LTV (loan-to-value) ratio of 81.5% with an 83% liquidation threshold, while ankrFLOW sits at 78.5% LTV and 81% threshold.
By manipulating collateral values between these two assets, the attacker inflated borrowing power and extracted value from the mFlowWFLOW reserve. The protocol's architecture—built on Aave V3 with nine markets—did not adequately safeguard against this collateral manipulation vector. Cryptopolitan reported that the breach exploited the interaction between the liquid staking mechanism and E-Mode settings.
Blockaid identified the primary exploit transaction with hash 0x2b2e6ea6c and documented a related contract deployment trace. The security firm tracked a cluster of post-exploit transfers showing funds moving away from the drained reserve in the hours following the attack. Despite this detective work, the final destination of the stolen assets remains unclear.
Investigators emphasize that the attacker's complete holdings and the final loss amount are still being determined. Blockaid explicitly did not identify Ankr itself as compromised, suggesting the vulnerability lay within More Markets' protocol design rather than in Ankr's liquid staking contracts. External audits of Ankr's Flow staking contracts on both Cadence and EVM had been conducted by Halborn, providing a baseline for assessing the LST controls.
This exploit underscores a systemic risk in DeFi: protocols that layer liquid staking tokens with advanced borrowing features can create unintended attack surfaces. Liquid staking tokens introduce price volatility and potential oracle manipulation. When combined with E-Mode or similar leverage mechanisms, they can amplify borrowing power in ways that developers don't anticipate.
More Markets' loss—whether the final figure exceeds or stays near the initial $9.3 million estimate—serves as a reminder that thorough testing of collateral interactions across multiple asset classes is essential. As investigators continue to trace the stolen WFLOW and reconcile losses, the DeFi community faces renewed pressure to audit interactions between liquid staking mechanisms and borrowing protocols.
Publishers
13
Articles
9
Reach
22