LIVE
BTC$78,590 0.49%ETH$2,454 0.25%SOL$103.67 1.63%XRP$1.38 0.89%BNB$688.21 0.81%ADA$0.1975 2.04%DOGE$0.0829 2.46%AVAX$7.23 2.04%LINK$11.31 0.71%MATIC$0.1262 0.00%BTC$78,590 0.49%ETH$2,454 0.25%SOL$103.67 1.63%XRP$1.38 0.89%BNB$688.21 0.81%ADA$0.1975 2.04%DOGE$0.0829 2.46%AVAX$7.23 2.04%LINK$11.31 0.71%MATIC$0.1262 0.00%
LF Wallet promotional banner offering up to 1,000,000 LF rewards with Google Play and App Store download options.Sponsored
Bitcoin World News
LF Wallet promotional banner offering up to 1,000,000 LF rewards with Google Play and App Store download options.Sponsored
DeFi

More Markets Loses $9.3M in DeFi Lending Exploit

More Markets reportedly suffered a $9.3 million exploit after an attacker used ankrFLOW and E-mode to overborrow WFLOW from a lending reserve on Flow EVM.

4 min read
More Markets Loses $9.3M in DeFi Lending Exploit

DeFi lending protocol More Markets reportedly suffered a major exploit on Flow EVM, with an attacker draining approximately $9.3 million worth of Wrapped Flow (WFLOW) from one of its lending reserves.

Blockchain security firm Blockaid said the attacker exploited the protocol's collateral system using Ankr Staked FLOW (ankrFLOW) and E-mode to borrow more assets than the reserve could safely support.

The incident adds to a series of major DeFi exploits recorded across the cryptocurrency market in August.

LF Wallet promotional banner offering up to 1,000,000 LF rewards with Google Play and App Store download options.Sponsored

Attacker Drained 15.5M WFLOW

According to Blockaid, approximately 15.5 million WFLOW, worth around $9.3 million at the time, was removed from the mFlowWFLOW lending reserve.

The attacker reportedly used ankrFLOW as collateral and took advantage of the protocol's E-mode configuration to increase borrowing power.

E-mode is designed for assets that are expected to maintain a close price relationship. It can allow users to borrow more against certain correlated assets than under standard collateral parameters.

However, this increased capital efficiency can also introduce additional risk if asset pricing, liquidity or collateral assumptions are exploited.

How the Exploit Worked

Blockaid's analysis indicates that the attacker leveraged the relationship between ankrFLOW and WFLOW to obtain excessive borrowing capacity.

The basic attack involved:

  1. Using ankrFLOW as collateral.

  2. Taking advantage of E-mode's more favorable borrowing parameters.

  3. Borrowing WFLOW from the lending reserve.

  4. Draining approximately 15.5 million WFLOW from the pool.

The incident highlights an important DeFi security issue: a protocol can be vulnerable even when its smart contracts operate as designed if its economic parameters create an exploitable imbalance.

More Markets Has Yet to Confirm the Loss

At the time of reporting, More Markets had not publicly confirmed the incident or disclosed the final amount lost.

Blockaid's figure is therefore an estimate based on its security monitoring and blockchain analysis.

It also remains unclear whether the protocol will be able to recover any of the stolen assets or compensate affected users.

Further details are expected if More Markets publishes an official investigation or post-mortem.

August Crypto Hacks Near $140M

The exploit comes during another challenging month for cryptocurrency security.

DefiLlama's hack tracker shows that approximately $139.7 million worth of cryptocurrency had been lost to hacks during August, making the month one of the largest by stolen value in 2026.

However, the figure remains below July's approximately $254 million in losses.

The latest More Markets incident demonstrates that DeFi lending protocols remain a major target because they often control substantial pools of immediately accessible liquidity.

Cronos Tectonic Exploit Highlights Wider DeFi Risks

The More Markets incident also follows the reported $75 million Tectonic exploit on Cronos.

Cronos halted its blockchain after the attack, while Tectonic warned users not to interact with the protocol during its investigation.

The two incidents highlight similar concerns around decentralized lending: attackers can exploit collateral factors, liquidity conditions and asset pricing mechanisms to extract significantly more value than they initially provide.

Why This Matters for Bitcoin

The More Markets exploit did not directly target Bitcoin, but it remains relevant to the broader BTC ecosystem.

Bitcoin is increasingly being used across decentralized finance through wrapped BTC, bridges, lending protocols and tokenized representations.

That means Bitcoin holders interacting with DeFi can face risks beyond Bitcoin's underlying blockchain.

Native BTC and BTC deposited into a DeFi lending protocol have very different risk profiles. Once Bitcoin exposure enters a smart contract, users also become exposed to the protocol's code, collateral rules, liquidity and oracle mechanisms.

As Bitcoin's role in DeFi expands, these risks are likely to become increasingly important.

The Bigger DeFi Security Problem

The incident highlights why DeFi security cannot depend solely on traditional smart-contract audits.

Protocols must also stress-test their economic models under extreme conditions.

Important factors include:

  • Collateral factors

  • Asset liquidity

  • Price oracles

  • Borrowing limits

  • Liquidation mechanisms

  • Correlation assumptions

  • E-mode configurations

A system that appears safe during normal market conditions can behave very differently when an attacker deliberately targets its weakest assumptions.

What to Watch Next

The next developments will focus on three areas:

More Markets' Investigation

An official statement could reveal exactly how the attacker exploited the lending reserve and whether the protocol considers the incident a confirmed loss.

Movement of Stolen Funds

Blockchain analysts will continue monitoring the attacker's addresses for swaps, bridges or transfers to centralized exchanges.

DeFi Risk Controls

Other lending protocols may review collateral parameters for liquid staking tokens and correlated assets following the incident.

Bottom Line

More Markets reportedly lost approximately $9.3 million in WFLOW after an attacker exploited its lending reserve on Flow EVM.

Blockaid said the attacker used ankrFLOW and E-mode to obtain excessive borrowing power and drain approximately 15.5 million WFLOW.

The incident adds to nearly $140 million in cryptocurrency hack losses recorded during August, underscoring the continuing security challenges facing decentralized finance.

For Bitcoin investors, the key takeaway is broader: using BTC within DeFi introduces additional smart-contract and protocol risks that do not exist when holding native Bitcoin directly.

As Bitcoin becomes increasingly connected to decentralized finance, the security of the protocols handling BTC liquidity will become just as important as the security of the Bitcoin network itself.

Disclaimer

This article is for informational purposes only and does not constitute financial, investment, or trading advice. Cryptocurrency markets are highly volatile and carry significant risk. Always conduct your own research (DYOR) and consult a qualified financial advisor before making investment decisions. Past performance does not guarantee future results.

The crypto brief, in your inbox

BTC, markets, and the stories that moved crypto — daily, no noise.

No spam, ever. Unsubscribe in one click.

Related DeFi News

Comments (0)

Comments are reviewed before publishing.

No comments yet. Be the first.

LF Wallet promotional banner offering up to 1,000,000 LF rewards with Google Play and App Store download options.Sponsored