T
iTokenly

More Markets hack — August 2026

Verified — 3 sourcesLast checked September 1, 2026

Incident facts

Date of incident
Target typeLending protocol
Loss$9,300,000Price at time of incident
MethodOracle or price manipulationAn Ankr bonded liquid staking token was used together with the protocol's high-leverage E-Mode, letting the attacker borrow real WFLOW against collateral the protocol priced too generously
ChainsOther
OutcomeUnresolved

What happened

The mFlowWFLOW lending reserve of More Markets, a lending protocol built by More Labs on Flow EVM, was emptied of 15.5 million WFLOW at about 07:58 UTC on 31 August 2026. Security firm Blockaid disclosed the incident the same day and put the detected impact at roughly $9.3m.

The attacker combined an Ankr bonded liquid staking token with More Markets' E-Mode, the high-leverage mode that lets correlated assets be borrowed against each other at generous ratios. That let them borrow genuine WFLOW against collateral the protocol valued more highly than the market would have, and drain the reserve outright.

What is not yet established is where the fault sits. Blockaid's own disclosure leaves open whether the problem originated in More Markets' implementation, in how the Ankr asset was handled inside the lending protocol, in its pricing assumptions, or in the interaction between them. The vector recorded here reflects the collateral being priced above what it could be sold for, which is the part that is clear; the precise cause is not.

The figure is Blockaid's detected impact and is explicitly preliminary. More Markets and More Labs had not confirmed the incident or a loss figure, and no post-mortem had been published. This is a different incident from the December 2025 Flow blockchain entry recorded elsewhere in this registry.

Sources

  1. crypto.newsSecondary · retrieved 2026-09-01
  2. The Crypto BasicSecondary · retrieved 2026-09-01
  3. The CryptonomistSecondary · retrieved 2026-09-01

Changes to this entry

  • Recorded the day after the incident from a security firm's preliminary detection figure, with no confirmation from More Markets and no post-mortem. Both the amount and the attribution of fault between the protocol, the Ankr asset and their interaction will be corrected once the protocol publishes its own accounting.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "More Markets hack — August 2026", iTokenly, accessed 2026-09-01, https://itokenly.com/hacks/more-markets-wflow
https://itokenly.com/hacks/more-markets-wflow

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.