Flow EVM Protocol More Markets Suffers $9.3M Drain in Sophisticated Liquid Staking Attack
DeFi protocol More Markets experienced a significant security breach on Flow EVM, with attackers draining $9.3 million in wrapped assets by exploiting liquid staking tokens and efficiency mode borrowing mechanics.
A Well-Executed Attack on More Markets
According to Blockaid, a Web3 security platform, the Flow EVM-based DeFi protocol More Markets became the target of an attack that successfully drained its lending reserve. The attacker made off with approximately 15.5 million Wrapped Flow tokens, which Blockaid valued at around $9.3 million. The borrowed assets came from the mFlowWFLOW lending reserve on the Flow network.
The sophistication of the attack lay in its use of an Ankr Staked FLOW liquid staking token paired with E-mode, an Aave V3 feature designed to unlock additional borrowing capacity for correlated assets. By leveraging E-mode—a mechanism intended for assets expected to move in tandem, such as a staking derivative and its underlying token—the attacker was able to overborrow against the reserve’s collateral requirements.
More Markets, which operates as a DeFi vault infrastructure protocol, had not publicly announced the incident or indicated whether affected users experienced losses at the time of reporting on the breach.
August’s Security Crisis Deepens
This attack represents yet another blow to the DeFi ecosystem during an already turbulent month. When combined with other incidents in August, the More Markets exploit contributed to a monthly tally of $139.7 million in cryptocurrency losses due to hacks and exploits, making August the third-worst month for such attacks in 2026 to date. The figure marks a steep decline from July’s $254 million in stolen funds—a silver lining, though hardly comforting to affected users.
The timing underscores an emerging pattern: just one day before the More Markets drainage became public, Cronos suspended its blockchain network following a reported $75 million exploit targeting Tectonic, a DeFi lending protocol on that chain. The back-to-back incidents highlight persistent vulnerabilities in DeFi’s borrowing and lending infrastructure, particularly where advanced features like efficiency modes interact with liquid staking derivatives.
What This Means for Decentralized Finance
Blockaid’s disclosure of the More Markets attack—shared publicly on the social media platform X—demonstrates the critical importance of security monitoring in an ecosystem where new features and composable protocols create novel attack surfaces. The exploitation of E-mode reveals that while such efficiency mechanisms can improve user experience by increasing capital efficiency, they also introduce concentration risks when protocols share too many correlated assets.
For the broader crypto market, these incidents reinforce the need for rigorous testing and monitoring of DeFi protocols, particularly those incorporating Aave V3’s advanced features as they evolve toward greater composability.
The cascading exploits in August underscore why DeFi security vulnerabilities pose systemic risks to the entire cryptocurrency market’s institutional adoption and long-term stability.
Source: Blockaid, via Cointelegraph. Not financial advice.