Security firm Blockaid identified the drain of a lending reserve tied to wrapped FLOW tokens on the Flow EVM network.
More Markets, a decentralized lending protocol operating on Flow EVM, suffered a $9.3 million exploit targeting one of its lending reserves. The affected reserve held WFLOW, the wrapped version of Flow’s native FLOW token used within EVM-compatible smart contracts.
Security firm Blockaid identified and reported the drain, according to coverage from crypto.news, Cointelegraph, and CryptoBriefing. Blockaid specializes in monitoring on-chain activity for malicious transactions and has previously flagged exploits across various blockchain networks.
Flow EVM is an Ethereum Virtual Machine-compatible environment built on the Flow blockchain, designed to let developers deploy Solidity-based smart contracts while tapping into Flow’s underlying infrastructure. WFLOW exists to bridge Flow’s native asset into this EVM-compatible ecosystem, allowing it to function within lending markets, decentralized exchanges, and other DeFi applications built for EVM standards.
Lending protocols like More Markets allow users to deposit crypto assets as collateral and borrow against them, or supply liquidity to earn yield. Reserves within these protocols hold pooled user funds and represent a common target for attackers seeking to exploit weaknesses in smart contract logic, price oracle configurations, or liquidity mechanisms.
The specific technical vector behind the More Markets exploit was not detailed in initial reports. DeFi hacks of this size often stem from flaws such as oracle manipulation, reentrancy bugs, or flash loan attacks that exploit pricing discrepancies between assets. Without confirmation of the root cause, the exact mechanism used against More Markets remains unclear.
The incident adds to a long list of DeFi protocol exploits in 2026, many of which have targeted lending platforms and their collateral reserves. Flow EVM, as a newer entrant among EVM-compatible chains, has been working to attract developers and liquidity, making security incidents on its network particularly notable for ecosystem growth.
The response from More Markets, including whether the protocol has paused operations, contacted the attacker, or outlined a plan to reimburse affected users, was not specified in the initial reporting. Such follow-up actions are common after major DeFi exploits and often shape how quickly a protocol can rebuild user trust.
A $9.3 million loss represents a significant blow to a lending protocol operating on a still-developing EVM-compatible network like Flow EVM. Exploits of this scale can trigger immediate liquidity withdrawals from affected protocols and broader caution toward other applications built on the same chain.
For Flow EVM specifically, the incident may prompt closer scrutiny of smart contract audits and reserve management practices among protocols building on the network. Broader DeFi markets have shown sensitivity to high-profile hacks, with capital sometimes rotating toward platforms perceived as having stronger security track records following such events.
The More Markets exploit underscores persistent security risks within DeFi lending protocols, even as newer EVM-compatible networks like Flow EVM work to expand their ecosystems. Further details on the attack’s cause and any recovery steps are likely to emerge as investigations continue.
More Markets is a decentralized lending protocol that operates on Flow EVM, an Ethereum Virtual Machine-compatible layer built on the Flow blockchain.
WFLOW is a wrapped version of Flow’s native FLOW token, created so it can be used within EVM-compatible smart contracts and DeFi applications.
Security firm Blockaid identified and reported the $9.3 million drain of More Markets’ lending reserve.
The specific technical cause has not been disclosed in initial reporting. DeFi exploits of this kind often involve smart contract vulnerabilities, oracle issues, or flash loan attacks.
Details on any official response, including possible reimbursement plans or protocol pauses, were not specified in the reports covering the incident.
Original source: AltcoinGordon
Syndicated coverage. Originally reported by altcoingordon.com.