Ankr ankrFLOW (More Markets reserve) hack — August 2026
Incident facts
| Date of incident | |
|---|---|
| Target type | Lending protocol |
| Loss | $410,000Price at time of incident |
| Method | Contract logic errorA flaw in Ankr's ankrFLOW contract let the attacker mint about 8.6 million unbacked liquid staking tokens, which were supplied as collateral on More Markets and borrowed against under its high-leverage E-Mode |
| Chains | Other |
| Outcome | Unresolved |
What happened
At about 06:18 UTC on 31 August 2026 an attacker emptied 15.5 million WFLOW from the mFlowWFLOW lending reserve of More Markets, a lending protocol on Flow EVM. The tokens were worth roughly $410,000 at spot, and after slippage the attacker realised somewhere around $246,000 to $250,000. The amount removed is what this entry records; the smaller realised sum is noted because the two differ.
The defect was in neither the chain nor the lending protocol. Flow stated at 19:24 UTC the same day that the root cause was a vulnerability in Ankr's ankrFLOW Solidity contract, and that this was not an exploit of Flow EVM, the Flow protocol, or More Markets. The attacker used that flaw to create about 8.6 million unbacked ankrFLOW — liquid staking tokens representing staked FLOW that no staked FLOW stood behind — then supplied them as collateral on More Markets. Because E-Mode lets closely correlated assets be borrowed against each other at generous ratios, and because ankrFLOW is meant to track FLOW, the unbacked collateral unlocked borrowing capacity nothing actually backed.
The incident was first reported at $9.3m, a figure that circulated widely and appears in much of the coverage. That was a detector estimate, and the security firm that issued it withdrew it at 20:12 UTC on 31 August in favour of the spot valuation recorded here. The gap between the two is a factor of twenty-two, and this registry corrected downward rather than leave the larger number standing.
This is a different incident from the December 2025 Flow blockchain entry, and from the December 2022 Ankr entry, both recorded elsewhere in this registry.
Sources
- The Crypto TimesSecondary · retrieved 2026-09-03
- EtherWorldSecondary · retrieved 2026-09-03
- crypto.news (original $9.3m report, superseded)Secondary · retrieved 2026-09-03
Changes to this entry
- Recorded the day after the incident from a security firm's preliminary detection figure, with no confirmation from More Markets and no post-mortem. Both the amount and the attribution of fault between the protocol, the Ankr asset and their interaction will be corrected once the protocol publishes its own accounting.
- Loss corrected down from $9,300,000 to $410,000 and the cause reattributed. Blockaid withdrew its $9.3m detector estimate at 20:12 UTC on 31 August 2026, valuing the 15.5m WFLOW drained at about $410,000 at spot with roughly $250,000 realised after slippage. Flow stated at 19:24 UTC the same day that the root cause was a vulnerability in Ankr's ankrFLOW contract, through which about 8.6m unbacked tokens were minted, and that neither Flow EVM, the Flow protocol nor More Markets was exploited. The entry name and attack vector were changed to match; the slug is unchanged so the permalink continues to resolve.
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Ankr ankrFLOW (More Markets reserve) hack — August 2026", iTokenly, accessed 2026-09-09, https://itokenly.com/hacks/more-markets-wflowhttps://itokenly.com/hacks/more-markets-wflowPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.