E-Mode Exploit Hits More Markets, Wipes $9.3M from Flow Lending Market
A non-custodial lending market called More Markets on the Flow EVM was exploited on August 31, 2026. The attacker drained around 15.5 million WFLOW worth roughly $9.3 million from the mFlowWFLOW reserve.
The security firm Blockaid reported that the attack used a bonded liquid staking token from Ankr and E-Mode to empty the reserve. This exploit highlights the risks associated with liquid staking tokens as collateral in lending markets, particularly when combined with E-Mode.
E-Mode is a setting in Aave V3 that treats two assets as equivalent, allowing for higher borrowing limits. However, this also means that if one asset's value drops, it can trigger liquidation in E-Mode, even if the other asset's value remains stable. The incident raises concerns about the potential for similar exploits in other lending markets that use E-Mode.
The exact cause of the exploit remains open, and More Markets is investigating the incident. Blockaid's assessment emphasizes that neither Ankr nor the Flow blockchain was compromised, but rather a weakness in the More Markets application running on Flow EVM.