()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.

Ankr ankrFLOW exploit drains $410K from MORE Markets

Rony Roy
Edited by
News
Ankr ankrFLOW exploit drains $410K from MORE Markets - 1

This article was updated to reflect corrected figures from Blockaid and clarify that the underlying vulnerability was in Ankr’s ankrFLOW smart contract.

A vulnerability in Ankr’s ankrFLOW liquid staking contract has allowed an attacker to drain about $410,000 in WFLOW from MORE Markets after creating 8.6 million unbacked ankrFLOW tokens.

Summary
  • More Markets was exploited on Flow EVM, with 15.5 million WFLOW drained from its mFlowWFLOW lending reserve.
  • Blockaid estimated the impact at roughly $9.3 million and linked the attack to an Ankr bonded LST and More Markets’ E Mode mechanism.
  • The security firm identified a cluster of transactions used to move funds after the exploit, while the final losses and destination of the assets remain under investigation.
  • Blockaid has not said Ankr or the Flow blockchain itself was compromised, with its initial disclosure identifying More Markets as the protocol targeted.

Flow said the attack began at approximately 06:18 UTC on Aug. 31, when a vulnerability in Ankr’s ankrFLOW liquid staking contract allowed the attacker to create approximately 8.6 million ankrFLOW without any backing.

The attacker then deposited the unbacked ankrFLOW as collateral on MORE Markets and drained around 15.5 million WFLOW from its lending reserve. The tokens were worth approximately $410,000 at the spot price, while Flow said the attacker realized about $246,000 after slippage.

Blockaid initially estimated the impact at roughly $9.3 million after detecting the attack, but later corrected the figure. The security firm said the $9.3 million figure was an initial detector estimate and put the attacker’s realized proceeds at roughly $250,000 after slippage.

Ankr exploit used MORE Markets to drain WFLOW reserve

More Markets is a decentralized, noncustodial lending protocol deployed on Flow EVM and built using Aave V3 architecture. Its public repository lists nine supported markets and allows users to supply assets for interest, borrow against collateral at variable rates and liquidate positions that fall below required collateral levels.

WFLOW and ankrFLOW are among the assets supported by the protocol. More Markets lists WFLOW with a loan to value ratio of 81.5% and a liquidation threshold of 83%, while ankrFLOW has a 78.5% loan to value ratio and an 81% liquidation threshold.

The protocol’s documentation identifies ankrFLOW as a liquid staking token, or LST, while WFLOW serves as the native wrapped asset within the lending market.

Flow later identified the root cause as a vulnerability in Ankr’s ankrFLOW Solidity contract. The flaw allowed the attacker to create the unbacked ankrFLOW before using the tokens as collateral through MORE Markets’ E Mode borrowing mechanism. Flow said the underlying vulnerability was not in MORE Markets or Flow EVM.

Ankr’s documentation describes ankrFLOW as a reward bearing liquid staking token issued when users stake FLOW through its staking service. Its value relative to FLOW increases as staking rewards accumulate, while the number of ankrFLOW tokens held by the user remains unchanged.

Ankr lists separate smart contracts on Flow EVM for the ankrFLOW token, staking pool, staking configuration and ratio feed. The ratio feed contains the token’s ratio certificate, according to its documentation.

The company’s Flow liquid staking documentation says users can deploy ankrFLOW in DeFi applications, including lending markets, to borrow against the value represented by their staked FLOW. Ankr states that the Flow liquid staking contracts on Cadence and EVM underwent external audits by Halborn.

Blockaid identified the attack path as ankrFLOW combined with E Mode borrowing and noted that MORE Markets said its contracts were not compromised. Flow attributed the root cause to the Ankr Solidity contract used for ankrFLOW.

Flow says its network and MORE Markets were not exploited

Flow said the vulnerability did not affect Flow EVM, the Flow protocol or FLOW tokenomics. The foundation said the underlying exploit was in an Ankr Solidity smart contract and that the Flow network continued operating normally throughout the incident.

No MORE Markets or ankrFLOW depositor lost funds and no FLOW holder was affected, according to Flow. Ankr and MORE Markets paused the affected contracts within hours, while some exchanges temporarily suspended FLOW deposits as a precaution. Flow Foundation said it would work with Ankr to replace the WFLOW drained from the MORE Markets reserve and rebalance the affected ankrFLOW/WFLOW liquidity pool.

Flow EVM provides an Ethereum compatible environment on Flow, allowing applications written for the Ethereum Virtual Machine to operate on the network. More Markets runs its lending contracts in that environment.

Flow has previously promoted both More Markets and Ankr as applications available to users within its DeFi ecosystem. Its Community Rewards program, for example, offered rewards for activity involving lending protocols such as More Markets and for staking FLOW through Ankr’s liquid staking product.

The distinction between the More Markets incident and a network level exploit is particularly relevant because Flow suffered a separate security breach in late 2025.

As crypto.news previously reported, a Dec. 27 attack exploited a vulnerability in Flow’s Cadence execution layer and allowed an attacker to duplicate fungible tokens before extracting approximately $3.9 million in value.

Flow Foundation’s subsequent post mortem said the attacker deployed more than 40 malicious smart contracts in a coordinated sequence. A flaw in Cadence runtime version 1.8.8 allowed a protected asset that should not have been copyable to be disguised as a standard data structure and duplicated.

More than 1 billion counterfeit FLOW tokens were sent to centralized exchanges during that incident. Flow said 484.4 million FLOW were later returned by OKX, Gate.io and MEXC and destroyed, while the network isolated 98.7% of the remaining counterfeit supply.

Flow previously changed its recovery plan after $3.9 million exploit

The December attack forced Flow validators to halt the blockchain within hours of the first malicious transaction. Flow Foundation initially proposed a full chain rollback, which would have returned the network to a checkpoint before the exploit.

The proposed Flow chain rollback faced opposition from bridge operators and other ecosystem participants. Critics warned that reversing confirmed transactions could produce duplicated balances for users who had moved assets through bridges during the affected period and create losses for users who had bridged assets in.

Flow subsequently abandoned the global rollback and adopted an isolated recovery process designed to identify and destroy counterfeit assets while retaining legitimate transaction history.

During the recovery, developers worked on restoring both Cadence and Flow EVM functionality. Accounts linked to suspicious activity faced temporary restrictions while external forensic firms helped verify affected accounts, with Flow estimating that more than 99.9% of accounts would regain full access once the recovery was completed.

The fallout later extended to South Korea, where Flow Foundation and Dapper Labs sought a court order in March to stop Upbit, Bithumb and Coinone from ending trading support for FLOW. The exchanges had moved toward delisting after the December security incident, while Flow maintained that existing user balances had not been compromised.

AnkrFLOW staking and MORE Markets lending remained paused while Ankr prepared a contract upgrade addressing the vulnerability. Flow said users with funds in either protocol would be able to retrieve them once operations resumed and that no action was required from users.