An attacker exploited Ankr's ankrFLOW liquid-staking contract on August 31, 2026, creating approximately 8.6 million unbacked ankrFLOW. The attacker then supplied those tokens as collateral on MORE Markets and removed about 15.5 million WFLOW from its lending reserve. Flow Foundation valued the WFLOW at roughly $410,000 at the spot price and said the attacker realized approximately $246,000 after slippage.
Correction, September 2, 2026: This article originally repeated Blockaid's initial estimate of $9.3 million and described the event as a MORE Markets or Flow EVM exploit. Blockaid subsequently corrected the amount and attribution. The vulnerable component was an Ankr Solidity contract, not Flow EVM or a MORE Markets smart contract. The article has been rewritten throughout.
What Happened
Flow Foundation places the start of the incident at approximately 06:18 UTC. A flaw in Ankr's ankrFLOW contract allowed the attacker to create about 8.6 million ankrFLOW without the FLOW backing those tokens were supposed to represent.
The attacker took the unbacked tokens to MORE Markets, where ankrFLOW was accepted as collateral. That position was then used to borrow approximately 15.5 million WFLOW from the protocol's reserve. The transaction occurred through MORE Markets on Flow EVM, but that does not make either system the source of the vulnerability.
This distinction is important. MORE Markets processed collateral that appeared valid according to the integrated token contract. The failure began upstream, where the attacker created collateral that should not have existed.
Why Three Different Numbers Appeared
The incident produced three figures that describe different things:
| Figure | What it represents |
|---|---|
| 8.6 million ankrFLOW | Unbacked liquid-staking tokens created through the Ankr contract flaw |
| 15.5 million WFLOW, about $410,000 | Assets removed from the MORE Markets WFLOW reserve, valued at the spot price |
| About $246,000 | Amount Flow says the attacker realized after market slippage |
Blockaid's original alert valued the impact at approximately $9.3 million. Its correction says that was an initial detector estimate rather than the correct spot value of the WFLOW removed. The original post was deleted after the correction.
Slippage explains the difference between the reserve value and the attacker's proceeds. A token balance can have one value at the quoted market price while producing substantially less when sold into limited liquidity. For this incident, roughly $410,000 is the better measure of assets removed and approximately $246,000 is the reported realized amount.
What Was and Was Not Exploited
Flow Foundation says the Flow network and Flow EVM were not exploited. It also says the underlying problem was not a vulnerability in MORE Markets. The faulty component was Ankr's Solidity contract for ankrFLOW.
MORE Markets was still part of the attack path because it accepted ankrFLOW as collateral and its WFLOW reserve supplied the assets taken. That makes the incident relevant to MORE users, but it is different from an attacker bypassing MORE's own contract controls.
According to Flow's statement, no MORE Markets or ankrFLOW depositor lost funds and no FLOW holder was affected. Ankr staking and MORE Markets lending were paused while the affected contracts were addressed. Flow also said it would work with Ankr to replace the drained WFLOW and rebalance affected liquidity pools.
The Risk Was in the Integration
Lending protocols depend on more than their own code. Every accepted collateral asset brings another contract, pricing process, liquidity profile, and governance system into the security model.
If a collateral token can be created without backing, a lending market may treat worthless or impaired assets as legitimate collateral. The lending contract can behave exactly as configured while the reserve still loses money. Auditing the lending protocol alone does not remove that dependency.
Liquid-staking tokens add another layer because their value depends on both the underlying stake and the contract that issues the receipt token. A lending market must assess whether the token can be minted improperly, whether redemptions can fail, how quickly liquidity disappears under stress, and whether its collateral parameters remain appropriate when one of those assumptions breaks.
What Onchain Lenders Should Check
Depositors cannot inspect every integrated contract themselves, but they can check how much dependency risk a market carries. Useful questions include:
- Which collateral assets can borrow from the reserve?
- Who controls or can upgrade those token contracts?
- Are supply anomalies or sudden minting events monitored automatically?
- Can the protocol pause borrowing without trapping ordinary withdrawals?
- Is there a treasury, insurance fund, or named remediation process?
Concentration also matters. Keeping most of a portfolio in one lending reserve exposes it to failures in the protocol and every major asset integrated into that market. A self-custodial wallet protects control of assets that remain in the wallet; it cannot remove the contract risk of funds deposited into an external protocol.
Overview
The August 31 incident was an exploit of Ankr's ankrFLOW Solidity contract. The attacker created approximately 8.6 million unbacked ankrFLOW, used it as collateral on MORE Markets, and removed around 15.5 million WFLOW from the reserve. The WFLOW was worth roughly $410,000 at spot prices, while Flow estimates that the attacker realized about $246,000 after slippage.
The corrected account does not support calling this a $9.3 million Flow EVM or MORE Markets exploit. It instead shows how an upstream collateral-token failure can pass through a lending integration even when the chain and lending protocol are not themselves compromised.



