A lending reserve on More Markets, a DeFi vault infrastructure protocol, was drained of approximately $9.3 million in digital assets on Flow EVM on Monday, August 31, according to on-chain analysis by Web3 security platform Blockaid.
The attacker drained roughly 15.5 million Wrapped Flow (WFLOW) tokens from the mFlowWFLOW lending reserve, according to blockchain data shared by Blockaid.
The Suspected Mechanism
According to Blockaid, the attacker used ankrFLOW — Ankr's liquid staking token for staked FLOW — alongside E-mode to overborrow from the reserve.
E-mode, short for efficiency mode, is an Aave V3 feature designed to increase borrowing power for assets whose prices are expected to move together. A liquid staking token and its underlying asset are the canonical example: because ankrFLOW should track the value of FLOW closely, the protocol allows higher loan-to-value ratios between them than it would for unrelated assets.
The suspected attack pattern is a corruption of that logic. By treating a staking derivative and the reserve asset as tightly correlated, E-mode increases the leverage available per unit of collateral — and if the correlation or the valuation path can be distorted, that same leverage multiplies what can be extracted. Blockaid has not published a full technical breakdown, and More Markets has not publicly confirmed the incident, disclosed the root cause, or said whether users suffered losses.
Cointelegraph reported it was unable to reach More Markets for comment and received no response from Blockaid by its publication time.
August's Running Total
The incident pushed total losses from cryptocurrency hacks to $139.7 million for August, making it the third-largest month by value stolen so far in 2026, according to DefiLlama data. The figure marks a significant decrease from July, when $254 million was stolen.
The month closed with two lending-market incidents inside 24 hours: the More Markets drain on Flow EVM on Monday, and the estimated $74–75 million exploit of lending protocol Tectonic on Cronos that led to a network halt on Sunday. Both suspected attacks, if confirmed, would involve borrowing mechanics rather than a compromised private key or bridge signature — continuing a pattern this publication has tracked all year, in which the exploitable surface is increasingly economic parameterization rather than raw code theft.
Verification Status
This incident is currently supported by a single primary source — Blockaid's on-chain analysis — with independent reporting by Cointelegraph. More Markets has not confirmed the incident, and no attacker attribution exists. The $9.3 million figure reflects Blockaid's token valuation at the time of its analysis.
TrustGrade tracks the security posture of DeFi protocols and infrastructure. Security scans with verified, registry-backed scores arrive with TrustGrade Code Scoring in December 2026.