Flow EVM Lending Protocol Suffers Estimated $9.3M Exploit
The Flow EVM lending protocol built by More Labs has been hit by an estimated $9.3 million exploit, draining 15.5M WFLOW from More Markets' lending reserve in the early hours of August 31, 2026.
Blockaid security firm reported the incident and estimated that the attack could have come from one of two key components: Ankr-bonded liquid staking token or More Markets' E-Mode setting, which lets borrowers take on higher leverage against correlated assets.
An alternative theory suggests that this is a cross-protocol liquidity extraction that runs deeper than a simple bug. However, the incident does not seem to have had a significant impact on DeFi, with More Markets' combined total value locked at $5.6 million and active loans worth about $3.41 million.
This incident follows a series of security breaches in DeFi, including Moonwell's loss of as much as $9 million due to a MAMO price-manipulation attack on its Base market.