More Markets protocol on Flow EVM chain exploited for $9.3M.
Security & Exploits ·
Security firm Blockaid identified an exploit targeting More Markets on the Flow EVM chain that drained approximately $9.3 million in value. The attacker leveraged Ankr's bonded liquid staking token alongside E-mode functionality to empty 15.5 million WFLOW from the mFlowWFLOW lending reserve, with the victim contract identified as the More Markets Pool.
The attack relied on a specific mechanism combining collateral and borrowing mode configurations to access funds. Transaction records show the exploiter address and a helper address involved in moving assets post-breach, indicating a multi-step execution and subsequent fund movement across exchanges or bridges.
What remains unclear is whether the protocol has halted operations, recovered funds, or identified measures to prevent recurrence. The full scope of user impact and whether insurance mechanisms exist to cover losses have not been detailed.