More Markets Loss Impact Revised to $410K
Blockaid revises the More Markets incident from $9.3M to $410K as Flow traces the exploit to unbacked tokens created through Ankr’s ankrFLOW contract.
The estimated impact of the More Markets incident has been revised from $9.3 million to approximately $410,000, following updated information from blockchain security firm Blockaid and a detailed statement from Flow.
Blockaid initially reported that an attacker had drained 15.5 million WFLOW from the mFlowWFLOW lending reserve on More Markets. While the number of tokens was correct, the security firm’s initial dollar estimate was not.
Blockaid Corrects the $9.3M Estimate
Blockaid’s first alert said that an attacker had used an Ankr bonded liquid staking token alongside More Markets’ E-Mode to empty approximately 15.5 million WFLOW from the protocol’s lending reserve. Its detector initially valued the impact at roughly $9.3 million.
The security firm subsequently corrected that estimate. It said the 15.5 million WFLOW was worth approximately $410,000 based on FLOW’s spot market price, while the attacker realized roughly $250,000 after slippage. Flow’s own statement placed the realized proceeds slightly lower at approximately $246,000.
This leaves three separate figures that should not be confused:
- 15.5 million WFLOW was removed from the More Markets reserve.
- The tokens had an estimated spot value of approximately $410,000.
- The attacker realized approximately $246,000 to $250,000 after selling into limited liquidity.
The original $9.3 million figure was an early detector estimate rather than a verified calculation of the tokens’ market value. Blockaid acknowledged the error, updated its assessment and deleted its original post.
The difference between theoretical value and realizable value has appeared in other DeFi incidents. During the recent Tectonic exploit on Cronos, an illiquid token’s manipulated price became central to the reported impact. Similarly, the Rhea Finance exploit demonstrated how misleading liquidity and pricing information can affect DeFi calculations.
How Unbacked ankrFLOW Enabled the Attack
According to Flow’s official statement, the incident began at approximately 06:18 UTC when an attacker exploited a vulnerability in Ankr’s ankrFLOW liquid staking contract. The vulnerability allowed the attacker to create approximately 8.6 million ankrFLOW without any corresponding FLOW backing.
ankrFLOW is a liquid staking token designed to represent FLOW deposited through Ankr’s staking service. Under normal conditions, users stake FLOW and receive ankrFLOW representing their underlying position. The token can then be transferred or used across decentralized finance without requiring the user to immediately unstake the original assets.
Statement on the Ankr Liquid Staking exploit
— Flow.com (@flow_blockchain) August 31, 2026
At approximately 06:18 UTC this morning, a vulnerability in Ankr's ankrFLOW liquid staking contract allowed an attacker to create approximately 8.6 million ankrFLOW with no backing. This was NOT an exploit of Flow EVM or the Flow…
This model is similar to the broader liquid staking structure described in EtherWorld’s overview of Ethereum staking in 2026. Liquid staking improves capital efficiency because a staked position can continue earning rewards while its representative token is used in lending markets, liquidity pools or other DeFi applications.
EtherWorld has also previously covered how liquid staking tokens can be used as collateral and how Aave integrated Coinbase’s cbETH into its lending market. That composability depends on one crucial assumption: the liquid staking token must remain properly backed.
In this incident, the attacker was reportedly able to mint or create ankrFLOW without depositing the FLOW that should have supported it. The attacker then supplied the unbacked ankrFLOW as collateral on More Markets and borrowed WFLOW against it.
More Markets supports E-Mode, or Efficiency Mode, a lending feature commonly used for assets that are expected to remain closely correlated. It can offer higher borrowing capacity when the supplied collateral and borrowed asset represent economically related positions.
ankrFLOW and WFLOW would ordinarily be treated as closely connected because ankrFLOW represents staked FLOW while WFLOW is a wrapped version of FLOW. However, the attacker’s ankrFLOW did not have the expected backing. The lending system therefore accepted collateral that appeared valid onchain but did not represent the economic value it was supposed to carry.
Flow EVM and More Markets Were Not Compromised
Flow emphasized that the incident was not an exploit of the Flow blockchain, Flow EVM or Flow tokenomics. The underlying vulnerability was located in an Ankr Solidity smart contract.
More Markets’ contracts were also not directly compromised, according to the available statements. The protocol was affected because it accepted ankrFLOW as collateral and its lending system recognized the attacker’s unbacked tokens as valid assets.
This distinction matters because reports describing the event simply as a “Flow EVM exploit” can incorrectly suggest that the network’s consensus, execution environment or native token was breached. Instead, the affected components were applications operating on top of the network.
A similar distinction appeared when a Hyperbridge gateway vulnerability affected bridged DOT. The vulnerability affected a particular cross-chain route rather than Ethereum or Polkadot at their base layers.
DeFi applications are composed of contracts, tokens, price feeds, liquidity pools, bridges and external protocols. A failure in one dependency can move through the system even when the receiving application executes exactly as programmed. EtherWorld’s coverage of the KelpDAO rsETH crisis similarly showed how risks connected to a liquid staking asset can spread into lending markets and create bad debt concerns.
Flow said no FLOW holder was affected and that neither More Markets depositors nor ankrFLOW depositors had lost funds. The Flow network continued to operate normally throughout the incident.
Recovery Plan and the Wider DeFi Lesson
The Flow Foundation has said it will replace the funds removed from the More Markets WFLOW reserve. It will also work with Ankr to restore balance to the affected ankrFLOW/WFLOW liquidity pool.
ankrFLOW staking and More Markets lending will remain paused until Ankr deploys a contract upgrade addressing the root cause. Flow said users with funds in either protocol do not need to take immediate action. Their assets are expected to become retrievable after the protocols safely resume operations.
This response could prevent the incident from turning into a long-term solvency problem for More Markets. Previous exploits have shown that technical containment is only the first stage of recovery. Protocols must also restore liquidity, compensate affected positions and rebuild confidence.
For example, Drift’s recovery plan with Tether focused on recapitalization and user compensation after a major exploit. By contrast, Radiant Capital eventually began sunsetting operations after struggling to recover from the longer-term consequences of its security incident.
The wider industry has already seen how oracle manipulation, fake liquidity and weak collateral assumptions can produce losses without directly breaking a protocol’s core contracts. EtherWorld’s review of April 2026 DeFi exploits highlighted how attackers increasingly target the economic assumptions connecting protocols rather than searching only for conventional coding errors.
Onchain tracing remains essential for separating token movements from actual financial proceeds. As explained in EtherWorld’s guide to tracing in Ethereum, investigators can reconstruct contract calls, state changes and fund movements to determine how an attack unfolded and what value the attacker ultimately retained.
The incident was contained without affecting the Flow network, and Flow has committed to restoring the drained reserve. The next critical step will be Ankr’s contract upgrade and a detailed post-mortem explaining how the unbacked ankrFLOW was created, why existing controls did not stop it and what safeguards will prevent the same dependency failure from spreading across Flow’s DeFi ecosystem again.
To promote your Web3 articles, events, and projects, you may reach out anytime via EtherWorld PR for submissions and collaboration.
Related Articles
- April 2026 Worst for DeFi: Over $635M Lost in Exploits
- Rhea Finance Exploit Drains $7.6M
- KelpDAO Exploit Triggers $290M Crisis Across DeFi
- DeFi Unites After KelpDAO $292M Hack
- How $900 Bought Control of an $8.5M DeFi Vault
To follow blockchain news, track Ethereum protocol progress, and read our latest stories, subscribe to our weekly today.
Join the EtherWorld & Avarch Internship Program and build your career in blockchain, content, social media, video, podcast editing, or operations. Send your resume and brief introduction to contact@etherworld.co.
Disclaimer: The information contained in this website is for general informational purposes only. The content provided on this website, including articles, blog posts, opinions, & analysis related to blockchain technology & cryptocurrencies, is not intended as financial or investment advice. The website & its content should not be relied upon for making financial decisions. Read full disclaimer & privacy policy.
To stay updated on blockchain news, Ethereum protocol progress, and our latest stories, subscribe to our weekly digest and YouTube channel for ELI5 content.
To promote your Web3 articles, events, project updates, and Press Releases, reach out anytime via EtherWorld PR for submissions and collaboration. For other queries, email contact@etherworld.co.
If you’d like to support our work, share the content and consider donating at avarch.eth.
Join our community on Discord and follow us on Twitter, Facebook, LinkedIn & Instagram.