TL;DR
- More Markets lost about $9.3 million after an attacker used ankrFLOW and E-mode to overborrow roughly 15.5 million WFLOW from a lending reserve.
- August crypto hack losses reached $139.7 million, making it 2026’s third-largest month by stolen value, though still below July’s $254 million.
- More Markets had not publicly confirmed the exploit or user losses, leaving questions about recovery, while the incident renewed scrutiny of correlated-asset borrowing and lending-risk controls.
More Markets suffered a roughly $9.3 million drain from a lending reserve on Flow EVM after an attacker exploited borrowing mechanics involving Ankr Staked FLOW and E-mode, according to Blockaid. About 15.5 million Wrapped Flow tokens were removed from the mFlowWFLOW reserve. The core issue was an overborrowing setup that combined a liquid staking token with efficiency-mode borrowing power. E-mode, derived from Aave V3, increases borrowing capacity for assets expected to move closely together, such as a liquid staking token and its underlying asset, creating the conditions used in the incident.
🚨 Blockaid detected an exploit on More Markets (More Labs) on Flow EVM. Attacker used Ankr bonded LST + E-mode to drain the WFLOW lending reserve. 15.5M WFLOW emptied from mFlowWFLOW (~$9.3M detector impact). Attack tx cluster includes post-exploit exfil.
More details in🧵— Blockaid (@blockaid_) August 31, 2026
Lending Exploit Adds Pressure to an Already Costly August
The attack adds another costly episode to an already difficult month for decentralized finance security. August crypto hacks have now reached $139.7 million in total losses, making it the third-largest month by value stolen in 2026. The surprising contrast is that August remains severe despite losses falling sharply from July’s $254 million. The Flow EVM incident also arrived just after Cronos halted its blockchain on Sunday following a reported $75 million exploit targeting lending protocol Tectonic, reinforcing concerns around the continued vulnerability of lending infrastructure across multiple networks and ecosystems.

More Markets had not publicly confirmed the incident at the time of publication, nor had it disclosed whether users ultimately suffered losses. Blockaid had not provided additional details beyond its public analysis when contacted. That leaves important operational questions unresolved, including how the reserve was configured and whether affected liquidity can be recovered. What is clear from the disclosed blockchain data is that the attacker extracted approximately 15.5 million WFLOW from the reserve, using ankrFLOW together with E-mode to increase borrowing capacity beyond what the reserve could safely absorb during the exploit.
The case also highlights the tradeoff embedded in efficiency features designed to improve capital use. E-mode can give borrowers greater leverage when two assets are expected to track one another closely, but that same design can magnify losses if assumptions or reserve parameters are exploited. The More Markets drain shows how mechanisms built for efficiency can become attack surfaces when lending configurations fail under adversarial conditions. With August losses already near $140 million and another major lending exploit occurring days earlier, security teams face renewed pressure to scrutinize correlated-asset borrowing, reserve design and risk controls before similar weaknesses are repeated across decentralized finance markets worldwide this month.