Blockaid detects exploit on More Markets' Flow EVM deployment with attacker draining 15.5M WFLOW from mFlowWFLOW lending reserve.
Security & Exploits ·
Blockaid identified an exploit affecting More Markets' Flow EVM deployment, in which an attacker drained 15.5M WFLOW tokens from the mFlowWFLOW lending reserve. The incident underscores operational risks within lending protocols deployed on Flow's EVM rollout, which operates alongside Flow's original Cadence virtual machine.
Flow EVM has emerged as a significant infrastructure addition to the broader EVM ecosystem, enabling developers to deploy smart contracts on the Flow network using EVM-compatible tooling. More Markets appears to have been among the early adopters seeking to offer lending services on this new environment, though the exploit reveals that compatibility with the EVM standard does not automatically ensure the security posture of individual protocols built atop it.
The scope of the attacker's access—drawing directly from the mFlowWFLOW reserve rather than exploiting user wallets—suggests a targeted vulnerability in the protocol's contract logic or access controls. Details regarding the attack vector, whether the vulnerability has been patched, and what recovery measures More Markets has undertaken remain unclear.