Crypto World

Blockaid Flags $9.3M Lending Reserve Drain via Ankr Tokens, E-Mode

Published

on

Flow-based DeFi lending protocol More Markets suffered a reserve drainage of about $9.3 million in digital assets, according to security firm Blockaid. Blockaid said the attacker extracted roughly 15.5 million Wrapped Flow (WFLOW) tokens from the protocol’s mFlowWFLOW lending reserve on the Flow EVM network.

The incident, outlined in a Monday post on X by Blockaid (see Blockaid’s report), highlights how lending platforms that support liquid staking tokens can be vulnerable when borrowing mechanics are combined with liquidity and efficiency-mode features.

Key takeaways

  • $9.3 million worth of WFLOW was reportedly drained from More Markets’ mFlowWFLOW lending reserve on Flow EVM.
  • Blockaid attributes the attack to the use of ankrFLOW (Ankr Staked FLOW) and Aave V3 E-mode overborrowing conditions.
  • The exploitation contributed to total crypto hack losses of $139.7 million in August 2026, per DefiLlama.
  • While August thefts remain the third-largest month of 2026 so far, they are far below $254 million stolen in July, according to DefiLlama data.
  • More Markets has not publicly confirmed the incident or disclosed potential user losses as of publication.

How Blockaid says the Flow EVM exploit worked

In its analysis, Blockaid linked the theft to the borrowing and collateral logic used inside the protocol. The security firm said the attacker used Ankr Staked FLOW (ankrFLOW), a liquid staking token, together with E-mode—a feature associated with Aave V3.

E-mode (short for efficiency mode) is designed to increase borrowing power for certain asset pairs when their prices are expected to move together. Blockaid’s explanation focuses on the relationship between a liquid staking token and its underlying asset: if the tokenized staking position (ankrFLOW) behaves closely to the underlying FLOW, then the protocol may assign more favorable risk parameters under E-mode.

According to Blockaid, the attacker leveraged those assumptions to overborrow from the mFlowWFLOW reserve and drain liquidity. Blockaid’s public figures point to 15.5 million WFLOW tokens being pulled from the reserve and valued at about $9.3 million in the incident.

Advertisement

What the reserve drainage means for DeFi risk management

Incidents like this tend to raise a difficult question for DeFi lenders: how to balance the capital efficiency benefits of supporting liquid staking derivatives against the edge cases that can emerge when borrowing rules are pushed to their limits.

E-mode is meant to reflect a correlation between assets, but the way correlation is enforced on-chain can be exploited if attackers can find a path where collateral valuation, liquidity availability, or borrowed asset dynamics allow them to extract value faster than the system can correct risk exposure. In this case, Blockaid specifically cited E-mode plus the use of a liquid staking token to achieve an outcome that resulted in reserve depletion.

For users, the immediate practical takeaway is less about the specific tokens involved and more about the mechanics. When a lending market supports efficiency-mode pairings between liquid staking tokens and their underlying assets, traders and depositors should watch for whether the platform can demonstrate robust controls under volatile or abnormal borrowing conditions.

Hack totals for August remain elevated—yet down from July

The Flow EVM theft adds to the broader picture of crypto security losses in 2026. Blockaid’s report comes as overall monthly totals have remained high.

Advertisement

DefiLlama data shows that losses from cryptocurrency hacks reached $139.7 million in August, making it the third-largest month by value stolen so far in 2026. Even so, August’s total represents a substantial drop from $254 million stolen during July, according to the same DefiLlama dataset on hacks (see DefiLlama’s hacks dashboard).

That comparison matters for risk perceptions. A decline from one peak month does not imply fewer vulnerabilities overall—it may instead reflect differences in the types of exploits that surfaced, the speed of mitigation once attacks begin, or the particular concentration of high-value DeFi targets in each month.

Other network disruption: Cronos pauses after Tectonic exploit

Blockaid’s account of the More Markets drainage arrives amid other DeFi-related security actions. On Sunday, Cronos halted its network after a reported $75 million exploit targeting the DeFi lending protocol Tectonic, according to earlier coverage from Cointelegraph (see that report).

Taken together, the two incidents underscore how quickly lending infrastructures can draw attention from attackers and how governance and incident response—whether pausing a chain or adjusting protocol controls—can become a determining factor in whether additional losses are contained.

Advertisement

Unanswered questions for More Markets users

As of the time of publication, More Markets had not publicly confirmed the incident or disclosed whether any user losses occurred. Cointelegraph attempted to obtain additional details by contacting Blockaid, but received no response by publication. The outlet also was unable to reach More Markets for comment.

Readers should watch for a formal More Markets statement, any post-mortem describing which reserve controls were bypassed, and whether the platform (and related integrations) plans to adjust E-mode or liquid staking collateral parameters to reduce the chance of a repeat.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Source link

Advertisement

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version