A DeFi lending protocol called More Markets lost roughly $9.3 million on August 31 after attackers found a way to exploit its lending reserve on the Flow EVM blockchain. Security firm Blockaid detected and disclosed the incident, which drained 15.5 million WFLOW tokens from the mFlowWFLOW reserve.

The method was surgical. Attackers paired Ankr’s bonded liquid staking token, ankrFLOW, with the efficiency mode feature baked into Aave V3, a mechanism designed to let borrowers extract more capital against correlated assets. In this case, that efficiency became a liability: combining the two allowed attackers to overborrow far beyond what the protocol’s safeguards were built to handle.

How the exploit worked

Aave V3’s E-mode, short for efficiency mode, is meant to increase capital efficiency for asset pairs that move closely together in price. When assets are correlated, the logic goes, there’s less liquidation risk, so the protocol can extend higher loan-to-value ratios.

AnkrFLOW, a liquid staking token representing staked FLOW, introduced a vector the protocol wasn’t designed to catch. By using ankrFLOW as collateral inside an E-mode configuration, the attacker unlocked borrowing capacity that exceeded what the underlying collateral could actually support.