Skip to main content
AVOID.NET

Audit log

Every state-changing event for Ankr (ankrFLOW Collateral Exploit): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-09-13 17:55:50Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 446,765,140
    sig
    5jbCa1Ahhq6H…qFheNHxzexplorer ↗
    hash
    BmkxJbbZ6kqi…tbYGZe34sha256 → base58
    verifying row…full verify ↗
    canonical bytes (20287 B) ▸
    {"actor":"system:backfill","investigation_id":"ef2150fb-7569-488d-9444-177459b7d093","kind":"publish","page_slug":"ankr-ankrflow-collateral-exploit","published_at":"2026-09-13T17:55:50.641Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Ankr (ankrFLOW Collateral Exploit)","sections":[{"content":"On August 31, 2026, at approximately 06:18 UTC, an attacker exploited a vulnerability in Ankr's ankrFLOW Solidity smart contract on Flow EVM. According to an analysis by security firm Blockaid and a subsequent statement by Flow Foundation, the flaw allowed the attacker to mint approximately 8.6 million ankrFLOW tokens without the corresponding FLOW backing those tokens were supposed to represent. The attacker then deposited the unbacked ankrFLOW tokens as collateral on More Markets, an Aave V3-fork lending protocol on Flow EVM. More Markets had placed ankrFLOW and WFLOW in the same E-mode category ('Wrapped native tokens') at a 97% loan-to-value ratio. Because ankrFLOW is a reward-bearing token whose on-chain ratio certificate reflects accrued staking rewards (approximately 1.2x nominal FLOW value), the combination of the inflated collateral oracle value and the high E-mode LTV allowed the attacker to loop-borrow WFLOW against the unbacked certificates — each round extracting more WFLOW than the cost of the collateral — until the WFLOW reserve was emptied. In total, 15.5 million WFLOW was removed from More Markets' mFlowWFLOW reserve. Flow Foundation corrected Blockaid's initial estimate of $9.3 million, stating the actual value of drained tokens at spot price was approximately $410,000, with the attacker realizing roughly $246,000 after market slippage upon liquidating the tokens. Flow Foundation attributed the root cause unambiguously to Ankr's contract: 'The root cause was a vulnerability in Ankr's ankrFLOW Solidity contract, not in Flow EVM or More Markets.' Both Ankr and More Markets paused the affected contracts within hours of detection. Flow Foundation committed to working with Ankr to replace the drained WFLOW and rebalance the affected ankrFLOW/WFLOW liquidity pool. No More Markets depositor, ankrFLOW holder, or FLOW token holder was reported to have lost funds as a result of the exploit. A proof-of-concept recreating the attack was later published to the DeFiHackLabs public repository.","heading":"ankrFLOW Collateral Exploit (August 2026)","severity":"high","sources":[{"credibility":2,"name":"More Markets Hacked for $9.3M on Flow EVM, 15.5M WFLOW Drained — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/31/more-markets-hacked-for-9-3m-on-flow-evm-15-5m-wflow-drained/"},{"credibility":2,"name":"Ankr ankrFLOW Exploit Drains $410K From MORE Markets Reserve — SpendNode","type":"news_article","url":"https://www.spendnode.io/blog/more-markets-flow-evm-lending-exploit-9-3-million-august-2026/"},{"credibility":2,"name":"More Markets Drained Of $9.3M In WFLOW After Attacker Exploits Ankr LST And E-Mode Collateral Pricing — Metaverse Post","type":"news_article","url":"https://mpost.io/more-markets-drained-of-9-3m-in-wflow-after-attacker-exploits-ankr-lst-and-e-mode-collateral-pricing/"},{"credibility":2,"name":"More Markets suffers $9.3m WFLOW exploit on Flow EVM — Crypto.news","type":"news_article","url":"https://crypto.news/more-markets-suffers-9-3m-wflow-exploit-on-flow-evm/"},{"credibility":2,"name":"Add PoC: AnkrMORE ankrFLOW certificate over-mint via bond staking (~$410K, Aug 2026) — DeFiHackLabs GitHub PR #1229","type":"research","url":"https://github.com/SunWeb3Sec/DeFiHackLabs/pull/1229"},{"credibility":2,"name":"More Markets Exploit: E-Mode and LSTs as the Lever — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/more-markets-exploit-lst-collateral/"}]},{"content":"Initial reporting on the August 2026 incident, triggered by a Blockaid security alert on X (formerly Twitter), characterized the exploit as a $9.3 million loss, referencing 15.5 million drained WFLOW. This figure circulated widely across crypto news outlets. Flow Foundation subsequently issued a correction, stating that the $9.3 million figure was 'an initial detector estimate rather than the correct spot value.' At the prevailing FLOW spot price of approximately $0.026288 per token, 15.5 million WFLOW was worth roughly $410,000. The attacker's realized proceeds were further reduced to approximately $246,000 after accounting for slippage when the stolen tokens were sold. Blockaid acknowledged the $9.3 million estimate was not the true dollar loss at spot prices. The corrected figure significantly changes the materiality assessment of this incident; it is a meaningful contract vulnerability but not a nine-figure loss event. Sources citing the $9.3 million figure without the correction should be treated as reflecting the initial, inaccurate estimate.","heading":"Disputed Loss Figure: $9.3M vs. $410K","severity":"medium","sources":[{"credibility":2,"name":"Ankr ankrFLOW Exploit Drains $410K From MORE Markets Reserve — SpendNode","type":"news_article","url":"https://www.spendnode.io/blog/more-markets-flow-evm-lending-exploit-9-3-million-august-2026/"},{"credibility":2,"name":"More Markets Hacked for $9.3M on Flow EVM — Crypto Times (notes Blockaid calling figure an initial estimate)","type":"news_article","url":"https://www.cryptotimes.io/2026/08/31/more-markets-hacked-for-9-3m-on-flow-evm-15-5m-wflow-drained/"}]},{"content":"On December 2, 2022, Ankr's aBNBc reward-bearing staked BNB token contract on BNB Chain was exploited. Ankr's post-incident report stated that a former team member conducted a 'combination of a social engineering and supply chain attack,' inserting a malicious code package that compromised Ankr's private deployer key during a legitimate contract update. The compromised key was used to upgrade the aBNBc contract to a malicious version that removed access controls from the mint function, allowing unrestricted token creation. According to reporting by CoinDesk and Cryptonews, the attacker minted approximately 20 trillion aBNBc tokens (some sources citing up to 60 trillion) and swapped them for approximately $5 million in USDC across Uniswap, Tornado Cash, and other platforms. The aBNBc token price collapsed approximately 99.5%. A secondary exploit followed: a separate attacker observed the price collapse and, while Helio Protocol's oracle still reflected the pre-crash aBNBc price, used flash-borrowed aBNBc as collateral to borrow approximately $16 million in Helio's HAY stablecoin, swapping the proceeds for roughly $15 million in BUSD. This Helio oracle attack was enabled by Ankr's contract compromise but was perpetrated independently. Ankr confirmed it was working with law enforcement to pursue the former employee and subsequently committed to deploying $5 million in BNB to reimburse affected liquidity providers. Ankr also announced post-incident security measures including multi-signature authentication requirements for all future contract updates, mandatory background checks for employees and contractors, and the establishment of coordinated incident-response channels with other DeFi protocols.","heading":"2022 aBNBc Infinite-Mint Exploit and Helio Cascade","severity":"critical","sources":[{"credibility":1,"name":"DeFi Protocol Ankr to Reimburse Users Affected by $5M Exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2022/12/02/defi-protocol-ankr-exploited-for-over-5m"},{"credibility":1,"name":"Ankr After-Action Report: Our Findings From the aBNBc Token Exploit — Ankr Official Blog","type":"official","url":"https://www.ankr.com/blog/after-action-report-our-findings-from-abnbc-token-exploit/"},{"credibility":1,"name":"Ankr Confirms $5M Crypto Hack Was An Inside Job — Blockworks","type":"news_article","url":"https://blockworks.com/news/ankr-confirms-5m-crypto-hack-was-an-inside-job"},{"credibility":1,"name":"How Attackers Made $15M From Staking Platform Helio After Ankr Exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2022/12/02/how-attackers-made-15m-from-staking-platform-helio-after-ankr-exploit"},{"credibility":2,"name":"Explained: The Ankr and Helio Hacks — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-ankr-and-helio-hacks-november-2022"},{"credibility":2,"name":"DeFi Protocol Ankr Suffers Infinity Minting Exploit — CryptoNews","type":"news_article","url":"https://cryptonews.com/news/defi-protocol-ankr-suffers-infinity-minting-exploit-heres-what-happened/"},{"credibility":2,"name":"Ankr deploys $15M to make users whole as Helio stablecoin recovers — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/ankr-deploys-15m-to-make-whole-users-as-helio-stablecoin-recovers-after-exploit"}]},{"content":"Ankr has commissioned multiple external security audits across its liquid staking product suite. Documented audits include: an ETH Liquid Staking audit by Salus (May 2023), a FLOW Liquid Staking audit by Halborn covering both Cadence and EVM contracts (August 2024), and earlier BNB Chain liquid staking audits by Beosin for FTM Liquid Staking (March 2022) and POL Liquid Staking (June 2022). The Halborn FLOW audit specifically covered the StakingManager, FlowStakingConfig, and AnkrRatioFeed contracts — the last of which governs the ratio certificate mechanism that was implicated in the August 2026 exploit. The existence of the Halborn audit predating the 2026 exploit by approximately two years raises questions about whether the over-mint vulnerability was introduced or present in the audited version of the contract. No public post-mortem from Ankr specifically addressing the ankrFLOW vulnerability had been published at the time of this investigation. CertiK's Skynet platform reports a security score of 91.19/100 for Ankr based on one recorded audit, though this score predates the 2026 incident. Following the 2022 aBNBc incident, Ankr announced the implementation of multi-signature controls for contract upgrades, which, if properly maintained, would have mitigated an insider-key-compromise attack similar to the 2022 vector. Whether these controls were fully applied to the ankrFLOW contracts on Flow EVM is not confirmed in available public sources.","heading":"Audit History and Security Posture","severity":"medium","sources":[{"credibility":1,"name":"Audit Reports — Ankr Official Documentation","type":"official","url":"https://www.ankr.com/docs/staking-extra/audit-reports/"},{"credibility":1,"name":"Liquid Staking Cadence & EVM Audit by Halborn — Ankr","type":"official","url":"https://www.ankr.com/docs/pdf/smart_contract_security_audit_flow_halborn.pdf"},{"credibility":2,"name":"Ankr (ANKR) Security Score & Audit — CertiK Skynet","type":"research","url":"https://skynet.certik.com/projects/ankr"},{"credibility":2,"name":"Hack Track: Analysis of Ankr Exploit — Merkle Science","type":"research","url":"https://www.merklescience.com/blog/hack-track-analysis-of-ankr-exploit"}]},{"content":"Ankr is a multi-chain Web3 infrastructure provider offering RPC node services, liquid staking, and developer tooling across more than 50 blockchains. In 2025, Ankr reported handling over 1 trillion RPC requests per month across its global bare-metal infrastructure network. As of mid-2026, the protocol's TVL in liquid staking products was reported in the range of $24 million to $52 million depending on the measurement methodology, according to DeFiLlama and Stelareum data. In July 2026, Ankr launched its Forge platform to incentivize ecosystem activity and link the ANKR token more directly to protocol revenue. In August 2026, Ankr joined the Stacks sBTC Signer Set and launched public RPC access to the XRP Ledger. The ankrFLOW liquid staking product and More Markets lending were both paused following the August 2026 exploit pending contract remediation. No regulatory actions against Ankr by the SEC, CFTC, or other regulators have been identified in available public sources.","heading":"Protocol Overview and Current Status","severity":"low","sources":[{"credibility":2,"name":"Ankr TVL, Fees & Revenue — DeFiLlama","type":"on_chain","url":"https://defillama.com/protocol/ankr"},{"credibility":2,"name":"Latest Ankr News — CoinMarketCap","type":"news_article","url":"https://coinmarketcap.com/cmc-ai/ankr/latest-updates/"},{"credibility":1,"name":"Flow Liquid Staking — Ankr Official Documentation","type":"official","url":"https://www.ankr.com/docs/liquid-staking/flow/overview/"}]}],"sources_used":[{"credibility":2,"name":"More Markets Hacked for $9.3M on Flow EVM — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/31/more-markets-hacked-for-9-3m-on-flow-evm-15-5m-wflow-drained/"},{"credibility":2,"name":"Ankr ankrFLOW Exploit Drains $410K From MORE Markets Reserve — SpendNode","type":"news_article","url":"https://www.spendnode.io/blog/more-markets-flow-evm-lending-exploit-9-3-million-august-2026/"},{"credibility":2,"name":"More Markets Drained Of $9.3M In WFLOW — Metaverse Post","type":"news_article","url":"https://mpost.io/more-markets-drained-of-9-3m-in-wflow-after-attacker-exploits-ankr-lst-and-e-mode-collateral-pricing/"},{"credibility":2,"name":"More Markets suffers $9.3m WFLOW exploit on Flow EVM — Crypto.news","type":"news_article","url":"https://crypto.news/more-markets-suffers-9-3m-wflow-exploit-on-flow-evm/"},{"credibility":2,"name":"More Markets Exploit: E-Mode and LSTs as the Lever — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/more-markets-exploit-lst-collateral/"},{"credibility":2,"name":"DeFiHackLabs PoC — ankrFLOW certificate over-mint PR #1229","type":"research","url":"https://github.com/SunWeb3Sec/DeFiHackLabs/pull/1229"},{"credibility":1,"name":"DeFi Protocol Ankr to Reimburse Users Affected by $5M Exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2022/12/02/defi-protocol-ankr-exploited-for-over-5m"},{"credibility":1,"name":"How Attackers Made $15M From Staking Platform Helio After Ankr Exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2022/12/02/how-attackers-made-15m-from-staking-platform-helio-after-ankr-exploit"},{"credibility":1,"name":"Ankr After-Action Report: Our Findings From the aBNBc Token Exploit — Ankr Official Blog","type":"official","url":"https://www.ankr.com/blog/after-action-report-our-findings-from-abnbc-token-exploit/"},{"credibility":1,"name":"Ankr Confirms $5M Crypto Hack Was An Inside Job — Blockworks","type":"news_article","url":"https://blockworks.com/news/ankr-confirms-5m-crypto-hack-was-an-inside-job"},{"credibility":2,"name":"Explained: The Ankr and Helio Hacks — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-ankr-and-helio-hacks-november-2022"},{"credibility":2,"name":"Ankr deploys $15M to make users whole as Helio recovers — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/ankr-deploys-15m-to-make-whole-users-as-helio-stablecoin-recovers-after-exploit"},{"credibility":2,"name":"DeFi Protocol Ankr Suffers Infinity Minting Exploit — CryptoNews","type":"news_article","url":"https://cryptonews.com/news/defi-protocol-ankr-suffers-infinity-minting-exploit-heres-what-happened/"},{"credibility":1,"name":"Audit Reports — Ankr Official Documentation","type":"official","url":"https://www.ankr.com/docs/staking-extra/audit-reports/"},{"credibility":1,"name":"Liquid Staking Cadence & EVM Audit by Halborn — Ankr","type":"official","url":"https://www.ankr.com/docs/pdf/smart_contract_security_audit_flow_halborn.pdf"},{"credibility":2,"name":"Ankr (ANKR) Security Score & Audit — CertiK Skynet","type":"research","url":"https://skynet.certik.com/projects/ankr"},{"credibility":2,"name":"Ankr TVL, Fees & Revenue — DeFiLlama","type":"on_chain","url":"https://defillama.com/protocol/ankr"},{"credibility":1,"name":"Flow Liquid Staking — Ankr Official Documentation","type":"official","url":"https://www.ankr.com/docs/liquid-staking/flow/overview/"},{"credibility":3,"name":"More Markets on Flow EVM Becomes Third DeFi Lending Exploit in Five Days — BitRss","type":"news_article","url":"https://bitrss.com/more-markets-on-flow-evm-becomes-third-defi-lending-exploit-in-five-days-246796"}],"summary":"Ankr is a multi-chain Web3 infrastructure and liquid staking protocol that has experienced two significant security incidents: a December 2022 insider-enabled infinite-mint exploit of its aBNBc token on BNB Chain (approximately $5 million drained directly, with a secondary $15 million oracle attack on Helio Protocol), and an August 2026 ankrFLOW contract vulnerability that enabled an attacker to mint approximately 8.6 million unbacked ankrFLOW tokens and drain roughly $410,000 in WFLOW (corrected from an initially reported $9.3 million) from the More Markets lending protocol on Flow EVM. In both incidents Ankr's own smart contracts were identified as the vulnerable component, though in the 2026 incident no depositors ultimately lost funds and Flow Foundation committed to replacing the drained reserves.","timeline":[{"date":"2022-03-01","event":"Ankr commissions Beosin audit of FTM Liquid Staking contracts.","source":"Ankr Audit Reports Documentation","source_url":"https://www.ankr.com/docs/staking-extra/audit-reports/"},{"date":"2022-12-02","event":"aBNBc infinite-mint exploit on BNB Chain: a former Ankr employee allegedly compromised the deployer private key via a supply-chain attack, enabling unrestricted minting of aBNBc tokens. Approximately $5 million in USDC extracted. aBNBc token price collapses ~99.5%.","source":"CoinDesk; Ankr Official Blog","source_url":"https://www.coindesk.com/markets/2022/12/02/defi-protocol-ankr-exploited-for-over-5m"},{"date":"2022-12-02","event":"Helio Protocol oracle attack: a separate attacker exploits stale oracle pricing of aBNBc on Helio to borrow approximately $16 million in HAY stablecoin, swapping for ~$15 million BUSD. The attack was enabled by but separate from the Ankr exploit.","source":"CoinDesk; Helio Protocol Exploit — Crypto Times","source_url":"https://www.coindesk.com/tech/2022/12/02/how-attackers-made-15m-from-staking-platform-helio-after-ankr-exploit"},{"date":"2022-12-20","event":"Ankr publishes after-action report attributing the exploit to a former team member and announcing security improvements including multi-sig upgrade controls and enhanced employee background checks.","source":"Ankr Official Blog — After-Action Report","source_url":"https://www.ankr.com/blog/after-action-report-our-findings-from-abnbc-token-exploit/"},{"date":"2023-05-01","event":"Ankr commissions Salus security audit of ETH Liquid Staking contracts.","source":"Ankr Audit Reports Documentation","source_url":"https://www.ankr.com/docs/staking-extra/audit-reports/"},{"date":"2024-08-01","event":"Ankr commissions Halborn security audit of FLOW Liquid Staking (Cadence and EVM) contracts, covering StakingManager, FlowStakingConfig, and AnkrRatioFeed.","source":"Ankr — Liquid Staking Cadence & EVM Audit PDF","source_url":"https://www.ankr.com/docs/pdf/smart_contract_security_audit_flow_halborn.pdf"},{"date":"2026-08-31","event":"ankrFLOW collateral exploit on Flow EVM: attacker exploits vulnerability in Ankr's ankrFLOW Solidity contract to mint approximately 8.6 million unbacked ankrFLOW. Tokens used as collateral on More Markets via Aave V3 E-mode to drain 15.5 million WFLOW (approximately $410,000 at spot price; attacker realizes ~$246,000 after slippage). Blockaid detects and discloses incident. Both Ankr and More Markets pause affected contracts.","source":"Crypto Times; SpendNode; Crypto.news; Metaverse Post","source_url":"https://www.cryptotimes.io/2026/08/31/more-markets-hacked-for-9-3m-on-flow-evm-15-5m-wflow-drained/"},{"date":"2026-08-31","event":"Flow Foundation corrects Blockaid's initial $9.3 million estimate, confirming actual WFLOW value at spot price was approximately $410,000. Foundation commits to replacing drained WFLOW and rebalancing affected liquidity pool. No depositor losses reported.","source":"SpendNode; Crypto.news","source_url":"https://www.spendnode.io/blog/more-markets-flow-evm-lending-exploit-9-3-million-august-2026/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision bffb9f62-98e7-4569-aeae-ff2b933d5e9f
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.