An attacker drained the mFlowWFLOW lending reserve on More Markets, pulling out 15.5 million Wrapped Flow tokens worth approximately $9.3 million. Web3 security firm Blockaid identified the exploit on Aug. 31 through on-chain data and disclosed the mechanics publicly.

The attack combined two components: Ankr Staked FLOW (ankrFLOW), a liquid staking token representing staked FLOW on Ankr's platform, and E-mode — efficiency mode — an Aave V3 feature that raises borrowing limits for correlated asset pairs. Because ankrFLOW and WFLOW are expected to track each other in price, E-mode treats them as near-equivalent collateral, unlocking higher loan-to-value ratios than standard borrowing. The attacker used that elevated borrowing power to pull more WFLOW from the reserve than the position's underlying collateral justified — a classic overborrow exploit.

More Markets describes itself as a DeFi vault infrastructure protocol and runs its lending market on Flow EVM, the Ethereum-compatible execution layer on Flow's blockchain. The mFlowWFLOW reserve is the specific lending pool that held the drained assets. At the time of publication, More Markets had not confirmed the incident or disclosed whether user funds are recoverable.

Blockaid's disclosure did not include the attacker's wallet address or a breakdown of how the borrowed assets were routed out.

The More Markets incident pushed total losses from crypto exploits in August to $139.7 million, according to DefiLlama data. That puts August third among 2026's months by value stolen. It is also a substantial drop from July, when hackers took $254 million — meaning August's total is roughly 45 percent lower than the prior month despite including two large protocol drains.

The second major exploit of the weekend hit Cronos. On Sunday, Aug. 30, Cronos halted its blockchain entirely after a reported $75 million exploit targeting Tectonic, a DeFi lending protocol on the network. The Cronos chain halt was a direct operational response to the attack — a move that centralized-chain critics note is unavailable to truly permissionless networks. The Tectonic incident alone accounts for more than half of August's cumulative losses.

E-mode exploits follow a recognizable pattern. The feature was designed for pairs like stETH and ETH, or USDC and DAI, where prices rarely diverge. The risk is that when a liquid staking token's peg slips — or when an attacker manipulates the price oracle that reports the peg — the protocol extends credit based on inflated collateral value. The borrower walks away with more than the collateral is actually worth, and the reserve absorbs the shortfall. More Markets has not disclosed whether an oracle manipulation was involved here or whether the exploit was purely a consequence of E-mode's elevated LTV parameters.

More Markets is not alone in running E-mode on liquid staking assets. The same configuration exists across Aave V3 deployments on Ethereum mainnet, Arbitrum and other chains. Aave's risk parameter committees have historically debated E-mode LTV ceilings for newer or lower-liquidity LSTs specifically because thinner markets make oracle attacks cheaper to execute. ankrFLOW's liquidity profile on Flow EVM is narrower than established LSTs on mainnet, which raises the cost of defense but lowers the cost of attack.

For More Markets specifically, the loss comes at a difficult moment for Flow EVM's broader DeFi ecosystem, which has been working to attract TVL and lending depth away from more established EVM chains. A nine-figure reserve drain — even at the $9.3 million scale — reduces available liquidity and raises the risk premium lenders assign to the chain's protocols. Depositors in the mFlowWFLOW reserve are the direct counterparty to the loss; whether More Markets holds an insurance fund or backstop mechanism to cover the shortfall has not been disclosed.

The incident is the latest in a string of lending-protocol exploits that trace back to collateral configuration rather than smart contract code bugs. Euler Finance lost $197 million in March 2023 through a donation attack on its donation mechanism. Mango Markets lost $117 million in October 2022 when an attacker manipulated MNGO's oracle price to borrow against inflated collateral. The More Markets attack fits the same category: the contracts likely executed as written, but the risk parameters left the reserve exposed to a borrower willing to push the system to its designed limits.

Humanity Protocol disclosed a separate $36 million hack earlier in August, further compressing the month's security record.