Skip to main content
Sign in
More Markets1 decision on this page

Audit log

Every state-changing event for More Markets: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-09-01 12:05:15Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    DnBptfA5mmuz…3JYVKQZ4sha256 → base58
    verifying row…
    canonical bytes (20790 B) ▸
    {"actor":"system:backfill","investigation_id":"3bc40226-b428-428b-b2ef-cb5f01f547a3","kind":"publish","page_slug":"more-markets","published_at":"2026-09-01T12:05:15.303Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"More Markets","sections":[{"content":"On August 31, 2026, blockchain security firm Blockaid detected an exploit on More Markets' mFlowWFLOW lending reserve on the Flow EVM blockchain. The attacker drained approximately 15.5 million Wrapped Flow (WFLOW) tokens from the reserve. Blockaid initially characterized the loss at approximately $9.3 million USD, though it later described that figure as a preliminary detector estimate. More Markets' own subsequent statement disputed the total, claiming that attackers were able to bridge out less than 5% of the value announced by Blockaid from Flow — a claim that had not been independently verified at the time of this report. Blockaid identified two attacker-associated addresses (primary exploiter: 0xa1E...6A7Cc; helper wallet: 0xA0C...b3702) and a cluster of post-exploit fund-transfer transactions. The affected reserve — the interest-bearing deposit market for WFLOW — was fully drained. The Flow EVM network itself was not affected; the vulnerability was at the application layer.","heading":"August 31, 2026 Exploit Overview","severity":"critical","sources":[{"credibility":2,"name":"More Markets loses $9.3M in lending reserve exploit, Blockaid reports — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/more-markets-9m-lending-reserve-exploit-blockaid/"},{"credibility":2,"name":"More Markets Hacked for $9.3M on Flow EVM, 15.5M WFLOW Drained — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/31/more-markets-hacked-for-9-3m-on-flow-evm-15-5m-wflow-drained/"},{"credibility":2,"name":"More Markets Drained Of $9.3M In WFLOW After Attacker Exploits Ankr LST And E-Mode Collateral Pricing — Metaverse Post","type":"news_article","url":"https://mpost.io/more-markets-drained-of-9-3m-in-wflow-after-attacker-exploits-ankr-lst-and-e-mode-collateral-pricing/"},{"credibility":2,"name":"More Markets suffers $9.3m WFLOW exploit on Flow EVM — crypto.news","type":"news_article","url":"https://crypto.news/more-markets-suffers-9-3m-wflow-exploit-on-flow-evm/"}]},{"content":"The exploit took advantage of the interaction between two components of More Markets' lending design. First, ankrFLOW — Ankr's bonded liquid staking token representing staked FLOW — was accepted as collateral within an E-Mode (Efficiency Mode) configuration inherited from Aave V3. E-Mode raises permissible loan-to-value (LTV) ratios for asset pairs whose prices are expected to move in lockstep, on the premise that correlated assets provide tighter collateral coverage. More Markets had assigned WFLOW an 81.5% LTV with an 83% liquidation threshold, and ankrFLOW a 78.5% LTV. Second, the attacker reportedly created approximately 8.6 million unbacked ankrFLOW tokens and deposited them as collateral against this E-Mode pairing. Because ankrFLOW's value is tied to a staking position that can only be unwound after a waiting period, its market price can diverge materially from underlying FLOW under stress — contradicting the correlated-asset assumption E-Mode depends on. By posting inflated or fabricated collateral in E-Mode, the attacker unlocked borrowing capacity that exceeded what genuine collateral could support and withdrew real WFLOW from the reserve. Blockaid stated that the precise technical sequence remained undisclosed and that it was unclear whether the root vulnerability originated in More Markets' implementation, Ankr's asset handling, pricing assumptions, or their interaction. Ankr stated its Flow liquid staking contracts had undergone external audits by Halborn and that Ankr itself was not identified as compromised.","heading":"Attack Mechanism: E-Mode and LST Collateral Pricing","severity":"critical","sources":[{"credibility":2,"name":"More Markets Exploit: E-Mode and LSTs as the Lever — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/more-markets-exploit-lst-collateral/"},{"credibility":2,"name":"More Markets Drained Of $9.3M In WFLOW After Attacker Exploits Ankr LST And E-Mode Collateral Pricing — Metaverse Post","type":"news_article","url":"https://mpost.io/more-markets-drained-of-9-3m-in-wflow-after-attacker-exploits-ankr-lst-and-e-mode-collateral-pricing/"},{"credibility":2,"name":"More Markets Hacked for $9.3M on Flow EVM — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/31/more-markets-hacked-for-9-3m-on-flow-evm-15-5m-wflow-drained/"}]},{"content":"Following Blockaid's disclosure, More Markets posted an initial statement on X (formerly Twitter) at approximately 06:18 UTC on August 31, 2026, acknowledging: 'Our team is currently investigating a claim that MORE Markets was exploited. We will share our findings shortlhy [sic].' In subsequent posts the team stated: 'Our initial investigation reveals that MORE was not exploited. MORE's contracts are secure. MORE is solvent. The protocol is paused.' The team further stated that 'the exploit appears to be due to a vulnerability associated with a third party on which MORE relies' and that 'while there is no loss to MORE's users, an attacker was able to bridge out less than 5% of the value announced by Blockaid from Flow.' These claims — particularly regarding user losses and the scale of bridged funds — had not been independently verified at the time of this report. Coverage published simultaneously by multiple outlets reported that after the drain, More Markets' total value locked fell to approximately $3.64 million against active loans of approximately $3.67 million, a near-parity state representing virtually no buffer between held assets and outstanding liabilities. One outlet citing DefiLlama data placed pre-exploit deposits at approximately $27.9 million against $19.6 million in loans. No formal post-mortem had been published as of the date of this report.","heading":"Protocol Response and Solvency Position","severity":"critical","sources":[{"credibility":3,"name":"More Markets statement on X — @MORE_DeFi","type":"social_media","url":"https://x.com/MORE_DeFi/status/2094337707753222313"},{"credibility":2,"name":"DeFi lending exploit drains $9.3M from More Markets, leaves reserves razor-thin — CoinDesk","type":"news_article","url":"https://coindesk.cc/defi-lending-exploit-drains-9-3m-from-more-markets-leaves-reserves-razor-thin-107854.html"},{"credibility":2,"name":"More Markets on Flow EVM Becomes Third DeFi Lending Exploit in Five Days — BitRss","type":"news_article","url":"https://bitrss.com/more-markets-on-flow-evm-becomes-third-defi-lending-exploit-in-five-days-246796"},{"credibility":2,"name":"More Markets Lending Reserve Drained of $9.3 Million — The Crypto Basic","type":"news_article","url":"https://thecryptobasic.com/2026/08/31/more-markets-lending-reserve-drained-of-9-3-million-on-flow-evm-blockaid-says/"}]},{"content":"More Markets is developed by More Labs and operates as a fork of Aave V3 on the Flow EVM blockchain. The protocol launched on Flow's Crescendo mainnet and supports nine asset markets. The protocol's documentation describes a security model built around a 'small, battle-tested' governance-controlled core, modular facets to isolate strategy risk, and timelocks on privileged actions. The documentation states that 'the DAO funds yearly audits of the core' but does not name specific auditing firms, and that a standing bug bounty program 'will soon' be offered — indicating that, at the time of the exploit, a live bug bounty program was not in place. The documentation further states that static analysis reports are published for each approved facet or oracle. The specific E-Mode and LST parameter settings at the time of the exploit — WFLOW at 81.5% LTV and 83% liquidation threshold, ankrFLOW at 78.5% LTV — were described by analysts as aggressive for a thinner liquidity market such as Flow EVM, where the assumptions defensible on deep-liquidity networks like Ethereum become materially more dangerous.","heading":"Protocol Architecture and Risk Parameters","severity":"high","sources":[{"credibility":2,"name":"Security and Risks — More Markets Documentation","type":"official","url":"https://docs.more.markets/more-vaults/security-and-risks"},{"credibility":2,"name":"More Markets Exploit: E-Mode and LSTs as the Lever — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/more-markets-exploit-lst-collateral/"},{"credibility":3,"name":"MORE Markets launch announcement on X — @More_Protocol","type":"social_media","url":"https://x.com/More_Protocol/status/1841399622016643491"}]},{"content":"The More Markets exploit was the third time in five days that a decentralized lending protocol was drained through collateral pricing manipulation. On August 27, 2026, Moonwell on Coinbase's Base network lost approximately $8.7 million after an attacker manipulated the price of MAMO, a thinly traded token, to borrow real assets against it. On approximately August 30, 2026, Tectonic on the Cronos chain lost an estimated $66 to $75 million after the TONIC governance token's price was inflated roughly 100 times in approximately 20 minutes, forcing Cronos validators to halt the entire chain. More Markets followed on August 31. Analysts noted that the three attacks targeted unrelated chains using three different attacker wallets and no shared exploit code, but each exploited the same structural weakness: how a lending market prices a correlated or thinly traded collateral token. August 2026 crypto hack losses across all platforms reached approximately $139.7 million, making it the third-largest month for stolen funds in 2026, below July's approximately $254 million.","heading":"Broader Exploit Pattern: Third DeFi Lending Attack in Five Days","severity":"high","sources":[{"credibility":2,"name":"More Markets on Flow EVM Becomes Third DeFi Lending Exploit in Five Days — BitRss","type":"news_article","url":"https://bitrss.com/more-markets-on-flow-evm-becomes-third-defi-lending-exploit-in-five-days-246796"},{"credibility":2,"name":"DeFi Lending Exploit Impacts More Markets with $9.3M Loss — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/08/31/defi-lending-exploit-more-markets/"}]},{"content":"The More Markets exploit occurred on the application layer of Flow EVM and did not involve a vulnerability in the Flow protocol itself. However, the Flow ecosystem has a prior security incident on record. On December 27, 2025, an attacker exploited a type confusion vulnerability in Flow's Cadence execution layer, enabling fungible token duplication and the extraction of approximately $3.9 million in value via cross-chain bridges including Celer, deBridge, Stargate, and Relay. Flow validators halted the network within hours. Flow Foundation initially proposed a full chain rollback but subsequently abandoned that approach in favour of an isolated recovery process designed to identify and destroy counterfeit assets while preserving legitimate transaction history. That prior incident is distinct from the More Markets event and does not directly implicate More Markets' development team.","heading":"Flow Blockchain Prior Security History","severity":"medium","sources":[{"credibility":1,"name":"Flow Security Incident 27th December: Technical Post-Mortem — Flow Foundation","type":"official","url":"https://flow.com/post/dec-27-technical-post-mortem"},{"credibility":2,"name":"Flow Foundation moves to phase two of $3.9M exploit recovery — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/flow-foundation-moves-to-phase-two/"},{"credibility":2,"name":"Flow Reports $3.9 Million Loss in December Security Breach — Phemex","type":"news_article","url":"https://phemex.com/news/article/flow-reports-39-million-loss-in-december-security-breach-51744"}]},{"content":"At the time of the exploit and as of the date of this report, More Markets had not published a formal post-mortem. The team's initial public statement contained a typographical error ('shortlhy') and was followed by a series of posts that disputed Blockaid's loss estimate without providing verifiable on-chain data to support the lower figure. The protocol was paused after the incident, but the initial response included no operational guidance to depositors or borrowers regarding their positions. The team attributed the root cause to an unspecified third party without identifying that party by name in public communications. The documentation's description of security measures — including an annual audit programme, a forthcoming bug bounty, and static analysis reports — was not accompanied by publicly accessible audit reports or audit firm names at the time of the exploit. This combination of factors — delayed and disputed disclosures, absence of a post-mortem, and a security documentation page that does not name auditors or link to completed reports — represents a material transparency gap relative to standard practice in the DeFi sector.","heading":"Transparency and Communication Assessment","severity":"high","sources":[{"credibility":3,"name":"More Markets statement on X — @MORE_DeFi","type":"social_media","url":"https://x.com/MORE_DeFi/status/2094337707753222313"},{"credibility":2,"name":"More Markets loses $9.3M in lending reserve exploit, Blockaid reports — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/more-markets-9m-lending-reserve-exploit-blockaid/"},{"credibility":2,"name":"Security and Risks — More Markets Documentation","type":"official","url":"https://docs.more.markets/more-vaults/security-and-risks"}]}],"sources_used":[{"credibility":2,"name":"More Markets loses $9.3M in lending reserve exploit, Blockaid reports — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/more-markets-9m-lending-reserve-exploit-blockaid/"},{"credibility":2,"name":"More Markets Hacked for $9.3M on Flow EVM, 15.5M WFLOW Drained — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/31/more-markets-hacked-for-9-3m-on-flow-evm-15-5m-wflow-drained/"},{"credibility":2,"name":"More Markets Exploit: E-Mode and LSTs as the Lever — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/more-markets-exploit-lst-collateral/"},{"credibility":2,"name":"More Markets Drained Of $9.3M In WFLOW After Attacker Exploits Ankr LST And E-Mode Collateral Pricing — Metaverse Post","type":"news_article","url":"https://mpost.io/more-markets-drained-of-9-3m-in-wflow-after-attacker-exploits-ankr-lst-and-e-mode-collateral-pricing/"},{"credibility":2,"name":"More Markets suffers $9.3m WFLOW exploit on Flow EVM — crypto.news","type":"news_article","url":"https://crypto.news/more-markets-suffers-9-3m-wflow-exploit-on-flow-evm/"},{"credibility":2,"name":"More Markets on Flow EVM Becomes Third DeFi Lending Exploit in Five Days — BitRss","type":"news_article","url":"https://bitrss.com/more-markets-on-flow-evm-becomes-third-defi-lending-exploit-in-five-days-246796"},{"credibility":2,"name":"DeFi lending exploit drains $9.3M from More Markets, leaves reserves razor-thin — CoinDesk","type":"news_article","url":"https://coindesk.cc/defi-lending-exploit-drains-9-3m-from-more-markets-leaves-reserves-razor-thin-107854.html"},{"credibility":2,"name":"More Markets Lending Reserve Drained of $9.3 Million — The Crypto Basic","type":"news_article","url":"https://thecryptobasic.com/2026/08/31/more-markets-lending-reserve-drained-of-9-3-million-on-flow-evm-blockaid-says/"},{"credibility":2,"name":"DeFi Lending Exploit Impacts More Markets with $9.3M Loss — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/08/31/defi-lending-exploit-more-markets/"},{"credibility":2,"name":"More Markets' Lending Reserve Drained of $9.3 Million in Wrapped Flow (WFLOW) — COINOTAG","type":"news_article","url":"https://en.coinotag.com/more-markets-reserve-drained-9-3m-wrapped-flow-wflow"},{"credibility":3,"name":"More Markets statement on X — @MORE_DeFi","type":"social_media","url":"https://x.com/MORE_DeFi/status/2094337707753222313"},{"credibility":3,"name":"MORE Markets launch announcement on X — @More_Protocol","type":"social_media","url":"https://x.com/More_Protocol/status/1841399622016643491"},{"credibility":2,"name":"Security and Risks — More Markets Documentation","type":"official","url":"https://docs.more.markets/more-vaults/security-and-risks"},{"credibility":2,"name":"More Markets homepage — more.markets","type":"official","url":"https://www.more.markets/"},{"credibility":1,"name":"Flow Security Incident 27th December: Technical Post-Mortem — Flow Foundation","type":"official","url":"https://flow.com/post/dec-27-technical-post-mortem"},{"credibility":2,"name":"Flow Foundation moves to phase two of $3.9M exploit recovery — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/flow-foundation-moves-to-phase-two/"},{"credibility":2,"name":"More Markets Lending Reserve Drained for $9.3M: Blockaid — Ground News","type":"news_article","url":"https://ground.news/article/more-markets-lending-reserve-drained-for-93m-blockaid"}],"summary":"More Markets is a DeFi lending protocol built on the Flow EVM blockchain by More Labs, operating as a fork of Aave V3. On August 31, 2026, an attacker exploited the protocol's E-Mode mechanism using Ankr's ankrFLOW liquid staking token as collateral to drain approximately 15.5 million WFLOW tokens, valued at roughly $9.3 million according to security firm Blockaid's initial estimate. The protocol subsequently paused operations and disputed the scale of losses reported by Blockaid, attributing the root vulnerability to a third party, though a post-mortem had not been published as of the date of this report.","timeline":[{"date":"2024-10-02","event":"More Markets announced launch on Flow blockchain's Crescendo mainnet with two initial lending markets and ecosystem incentives.","source":"More Markets X announcement","source_url":"https://x.com/More_Protocol/status/1841399622016643491"},{"date":"2025-12-27","event":"Separate incident: Flow network Cadence execution layer exploited via type confusion vulnerability; approximately $3.9 million drained before validators halted the chain. More Markets was not directly implicated.","source":"Flow Foundation Post-Mortem","source_url":"https://flow.com/post/dec-27-technical-post-mortem"},{"date":"2026-08-27","event":"Moonwell on Coinbase Base drained of approximately $8.7 million via MAMO token price manipulation — first of three DeFi lending exploits in five days.","source":"BitRss — More Markets on Flow EVM Becomes Third DeFi Lending Exploit in Five Days","source_url":"https://bitrss.com/more-markets-on-flow-evm-becomes-third-defi-lending-exploit-in-five-days-246796"},{"date":"2026-08-30","event":"Tectonic on Cronos drained of an estimated $66 to $75 million after TONIC token price was inflated approximately 100 times in 20 minutes; Cronos validators halted the chain.","source":"BitRss — More Markets on Flow EVM Becomes Third DeFi Lending Exploit in Five Days","source_url":"https://bitrss.com/more-markets-on-flow-evm-becomes-third-defi-lending-exploit-in-five-days-246796"},{"date":"2026-08-31","event":"At approximately 06:18 UTC, Blockaid detected and disclosed an exploit on More Markets' mFlowWFLOW reserve on Flow EVM. An attacker used ankrFLOW as collateral in E-Mode to drain approximately 15.5 million WFLOW tokens, initially valued at approximately $9.3 million.","source":"More Markets Hacked for $9.3M on Flow EVM — Crypto Times","source_url":"https://www.cryptotimes.io/2026/08/31/more-markets-hacked-for-9-3m-on-flow-evm-15-5m-wflow-drained/"},{"date":"2026-08-31","event":"More Markets posted initial X statement acknowledging an investigation into exploit claims, followed by subsequent posts asserting contracts were secure, the protocol was solvent, and that actual bridged losses were less than 5% of Blockaid's reported figure. The protocol was paused. More Markets attributed root cause to an unspecified third party.","source":"More Markets X — @MORE_DeFi","source_url":"https://x.com/MORE_DeFi/status/2094337707753222313"},{"date":"2026-08-31","event":"Multiple outlets reported post-exploit TVL at approximately $3.64 million against active loans of approximately $3.67 million, representing near-zero buffer between assets and liabilities. No formal post-mortem had been published.","source":"More Markets on Flow EVM Becomes Third DeFi Lending Exploit in Five Days — BitRss","source_url":"https://bitrss.com/more-markets-on-flow-evm-becomes-third-defi-lending-exploit-in-five-days-246796"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 44ac238f-31ec-4567-87b8-2315427e20cf
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.