More Markets stolen, Flow EVM trust crisis?

CN
1 hour ago

On August 31, 2026, More Markets, which has always been regarded as part of the Flow EVM lending infrastructure, suddenly exhibited abnormalities on-chain: the lending protocol, belonging to More Labs, had its WFLOW reserve pool represented by mFlowWFLOW swiftly “emptied,” with approximately 15.5 million WFLOW being rapidly transferred out, corresponding to a value of about 9.3 million dollars. Public materials show that the first to identify and disclose this attack on-chain was the blockchain security company Blockaid, followed by multiple Chinese media outlets such as PANews, Jinse Finance, Odaily, Deep Tide TechFlow, and BlockBeats, classifying it as a collateral pricing manipulation-type DeFi attack utilizing the combination vulnerability of Ankr's bound/staking liquid staking tokens and the protocol's E-Mode mechanism. In this collapse of the lending pool with almost no warning, not only was there an asset loss corresponding to 9.3 million dollars destroyed, but the image and trust foundation of Flow EVM's core lending protocol were also directly ripped open, exposing a gaping wound following such an attack.

Ankr LST + E-Mode Empties Lending Pool

In the attackers' script, Ankr's bound/staking liquid staking tokens were first disguised as “almost equivalent to WFLOW” safe collateral. More Markets allocated E-Mode for these types of assets on Flow EVM, defaulting that these collateral closely related to WFLOW could enjoy higher collateral efficiency—allowing for greater borrowing limits at the same nominal value. According to public security materials, the attackers exploited this combination: they first injected a large amount of Ankr LST as collateral, and with E-Mode enhancing collateral efficiency, the protocol exaggerated the value assessment of these LST, permitting them to borrow a large amount of WFLOW far exceeding their actual economic value from the mFlowWFLOW lending pool. The misalignment between overvalued collateral and accurately priced WFLOW ultimately transformed into a direct draining of the mFlowWFLOW reserve pool.

This is a typical path of collateral pricing and value manipulation: in multi-asset collateral scenarios, the protocol bundles a specific type of token that is “highly correlated with the main asset” into E-Mode to enhance capital efficiency, yet overlooks the additional risk layers embedded within. As long as a type of collateral is assigned an excessively high trust weight in pricing logic, attackers can bypass conventional risk control constraints and exchange the distortedly valued LST for accurately priced WFLOW. When More Markets placed Ankr LST and WFLOW into the same high-efficiency collateral group, it inadvertently opened a gap for this value asymmetry at the configuration level, which, under the attackers' operation, ultimately revealed a structural weakness that could not be overlooked in the multi-asset collateral design of Flow EVM's early core lending protocols.

WFLOW Pool Emptied, Flow EVM Trust Undermined

When approximately 15.5M WFLOW, equivalent to about 9.3 million dollars, was drained from the mFlowWFLOW reserve pool, what was left was not a string of cold numbers, but an entire set of disrupted asset relationships. For users who deposited WFLOW into More Markets to exchange for mFlowWFLOW positions, what should have been redeemable “lending reserves” suddenly turned into uncertain book equity; for on-chain participants who layered borrowing, going long, or hedging on this basis, the draining of the underlying collateral pool meant the safety assumptions of the entire strategy failed—whether their positions were safe, and if they could exit as expected, were no longer simple questions answerable with parameters.

This is not just an isolated incident of a single protocol. As one of the core lending protocols on Flow EVM, the security event reported by multiple media outlets directly thrusts the question of whether “lending protocols are reliable” to the forefront of the entire chain. Users evaluating other DeFi protocols on Flow EVM will find it difficult to continue treating the “core lending protocols as default safe” as a premise; they are more likely to increase sensitivity to collateral types and parameter configurations and decrease tolerance for high-leverage, high-efficiency collateral models; developers will have to reexamine the design of LST collateral and E-Mode combinations, reserving more risk control buffers from the project's early stages. Especially in the current context where there is still no publicly confirmed official repair plan or user compensation information, the draining of the WFLOW pool not only constitutes a loss but also tears a clear rupture regarding credit boundaries at the ecological level of Flow EVM.

Blockaid Warning: Attack Details Rapidly Amplified

On the day the WFLOW reserve pool was suddenly drained, it was not the users who first sensed the abnormality, but the security company Blockaid, which had been closely monitoring Flow EVM for a long time. It captured the abnormal interactions related to the mFlowWFLOW lending pool on More Markets through on-chain monitoring and quickly judged it as an exploit of the lending protocol's vulnerability, issuing a warning: the attack targeted More Markets' WFLOW reserves, with losses estimated at approximately 15.5M WFLOW, corresponding to about 9.3 million dollars. In subsequent technical analyses, Blockaid categorized this incident as a collateral pricing/value manipulation attack, pointing out that the attack exploited the combination vulnerability of Ankr’s bound/staking LST and the protocol's E-Mode mechanism, translating a risk path visible only in on-chain data into an attack narrative that the industry could quickly understand.

Following this warning, several Chinese media outlets such as PANews, Jinse Finance, Odaily, Deep Tide TechFlow, and BlockBeats synchronously followed up, using Blockaid's on-chain monitoring as the core information source, providing consistent descriptions of the attack protocol, exploitation methods, and loss scale. However, during this period, there were still no confirmed formal statements from the project party or foundation in the published reports. Security companies act like frontline radars, marking risk locations and technical characteristics in real time; media act like loudspeakers, amplifying this signal into a public opinion event and ecological alert among different reader circles. This warning system built by security companies and media, while rapidly disseminating risk awareness, also clearly exposed the high dependency of Flow EVM's ecology on third-party information when official responses were absent.

LST Collateral Explodes, A Demonstration of DeFi Risks

The attack categorized by security companies on More Markets as “collateral pricing/value manipulation” truly ripped open the collective neglect of LST collateral risks within the entire DeFi narrative. The attackers did not simply “borrow more and repay less,” but specifically exploited the unique properties of bound and staking liquid staking tokens like Ankr, further compounded by More Markets' parameter settings on positions like mFlowWFLOW under the E-Mode model, leading to a distortion in the protocol's assessment of collateral value under specific combinations. The result was that approximately 15.5M units of WFLOW reserves were drawn out in an almost “legitimate” manner, exposing structural gaps in the classification of collateral assets, risk weightings, and extreme scenario assumptions within Flow EVM's core lending protocols.

This is not an isolated sporadic bug, but a typical weak link beneath the multi-chain, multi-asset collateral narrative: once an asset possesses multiple attributes such as “staking yield + binding relationship + cross-protocol circulation,” any erroneous assumption in one link may be magnified into systemic risk through lending parameters, liquidation rates, or special modes (such as E-Mode). There have been past cases where “collateral price input issues” led to liquidations and bad debts; while the failure mode of More Markets superficially resembles these incidents, public materials are still sorting through specific technical details, making it imprudent to hastily categorize it entirely within an existing paradigm. Even more alarming is that, as of now, the industry still lacks a unified standard or regulatory framework addressing LST collateral risks, making this explosion on Flow EVM a striking sample: until parameter designs and asset classifications are reexamined, similar risks will not passively disappear due to a single incident.

More Markets Theft: A Security Lesson for Flow EVM

Against the backdrop of a lack of unified LST collateral risk standards, the attack on More Markets on Flow EVM on August 31, 2026, has become an unavoidable security lesson for this emerging chain. According to AiCoin data, the attack surrounding the mFlowWFLOW reserve pool resulted in approximately 15.5M WFLOW being transferred out, amounting to a loss of about 9.3 million dollars. As of the current public information, details regarding fund recovery, protocol repairs, or official handling plans remain unconfirmed, forcing questions that should have been answered during the design phase—such as “how should parameters be configured,” “what kind of collateral to select,” and “what to really watch in risk control”—to be redone post-facto at a cost. For lending protocols on Flow EVM, the next steps must return to the root of mechanisms: first, to bring E-Mode related parameters and asset grouping logic into a falsifiable audit scope, preventing the reoccurrence of fragile configurations that can be “flipped” by a small number of highly correlated assets; second, to clearly define collateral discounts, borrowing limits, and price source boundaries for bound/staking LSTs like Ankr, reducing the space for collateral pricing manipulation; third, to establish transparent links before and after incidents, allowing audit reports, risk assessments, and post-attack reviews to be publicly verifiable. It is worth ongoing observation whether More Markets and subsequent core lending protocols deployed on Flow EVM will respond to this incident with more rigorous parameter audits, more restrained LST access strategies, and a publicly accountable safety rectification path, as this series of actions will determine whether Flow EVM can rebuild its foundational trust in lending safety after losing WFLOW equivalent to 9.3 million dollars.

Join our community to discuss and become stronger together!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink