Crypto News

More Markets Loses $9.3M in Flow EVM Lending Exploit

Published: Aug 31, 2026By Aleksandar Dukic

Key Analysis

A lending protocol on Flow EVM, More Markets, was drained of roughly $9.3M, per Blockaid. Here is what happened and what it means for onchain lenders.

More Markets Loses $9.3M in Flow EVM Lending Exploit

Listen To This Article

More Markets Loses $9.3M in Flow EVM Lending Exploit

5m 8s audio

AI narration. Useful for scanning on the move. Names and tickers may be mispronounced.

A lending protocol on Flow EVM called More Markets was drained of roughly $9.3 million, security firm Blockaid reported on August 31, 2026. The alert, relayed by Cointelegraph, points to the protocol's lending reserve as the source of the loss. It is the latest in a run of DeFi lending incidents this year, and it lands during a stretch when the broader market is calm: bitcoin traded at $78,474 as of August 31, up 0.6% on the day, with the Fear and Greed Index sitting at 75 (Greed).

The scope of the loss

The reported figure is about $9.3 million, drawn from More Markets' lending reserve on Flow EVM, the Ethereum-compatible execution environment that runs alongside Flow's original chain. Blockaid, an onchain security monitoring firm, flagged the drain and is the primary source for the number. As of this writing, More Markets had not published a full post-mortem, so the exact mechanism, whether a smart contract bug, an oracle manipulation, a bad-debt cascade, or a compromised admin key, has not been confirmed publicly.

That gap matters. A $9.3 million figure is the amount moved, not necessarily the final loss borne by users. In past incidents, protocols have recovered part of the funds through negotiation with the attacker, whitehat intervention, or a treasury backstop. Until the team accounts for the reserve and states who is covered, depositors in the affected market should treat their positions as at risk rather than assume a specific outcome.

Lending reserves keep being the target

Lending protocols concentrate value in a way that makes them a recurring target. Users deposit assets into a shared pool, the protocol lets others borrow against collateral, and a reserve absorbs the spread and any shortfalls. That pooled reserve is a single, high-value contract, and if the logic governing it can be tricked, the whole balance is reachable in one transaction.

This year has already produced several examples. Cronos halted its chain after a $75 million exploit tied to its Tectonic lending market, and other reserves have been hit through price-oracle manipulation and reentrancy paths. The pattern is consistent: the attack surface is not the front-end or the token, it is the accounting math that decides how much a borrower can take out against what they put in.

Flow EVM is a newer environment, which adds its own wrinkle. Bridged and freshly deployed markets often run with thinner liquidity, fewer independent audits, and less battle-testing than equivalent pools on Ethereum mainnet or a large L2. That does not make them uniquely unsafe, but it does mean the usual assumption, that a fork of well-known lending code behaves exactly like the original, is not guaranteed to hold once you change the chain, the oracle feeds, and the asset set underneath it.

The custody point most depositors miss

When you supply funds to a lending protocol, you are not holding those assets anymore. Custody moves to the smart contract. You hold a claim, a receipt token or an accounting entry that says the pool owes you a balance. If the contract is drained, that claim can become worthless regardless of how carefully you managed your own wallet keys.

This is the same counterparty risk that sank centralized players like FTX, just relocated on-chain. The difference is that a smart contract is transparent and auditable in principle, but it is also autonomous: there is no support desk that can freeze a withdrawal mid-attack, and a bug executes exactly as written. For anyone spending from DeFi positions, including holders who route funds through self-custody card options that draw on onchain balances, the lesson is that "your keys" protects you from a custodian failing, not from the protocol you deposited into being exploited.

Practical steps for onchain lenders

There is no way to make DeFi lending risk-free, but the exposure is manageable. Spread deposits across protocols rather than parking everything in one high-yield reserve. Favor markets with multiple recent audits, a public track record, and a sizable insurance or treasury backstop over new deployments chasing the highest advertised rate. Check whether a protocol uses a single oracle or several, since single-oracle designs have been behind a large share of manipulation-based drains.

For users who mainly want stable, spendable value rather than lending yield, holding stablecoins for everyday spending and keeping only a working balance in any single lending market limits how much one exploit can take. A card that draws from a wallet you control still exposes whatever sits in a connected DeFi position, so the size of that position is the real dial to turn.

Overview

More Markets, a lending protocol on Flow EVM, lost roughly $9.3 million from its lending reserve, according to Blockaid's August 31, 2026 alert. The full mechanism and the final user impact were not yet public at the time of writing. The incident fits a pattern seen across 2026: pooled lending reserves remain the highest-value, most-targeted contracts in DeFi, and newer execution environments raise the odds that forked code behaves differently once the chain and oracle assumptions change. The takeaway for depositors is unchanged. Supplying assets to a protocol moves custody to a contract, and that contract's security is the ceiling on how safe your deposit can be.

DisclaimerThis article is provided for informational purposes only and does not constitute financial advice. All fee, limit, and reward data is based on issuer-published documentation as of the date of verification.

Have a question or update?

Discuss this analysis with the community on X.

Discuss on X

Comments

Comments are moderated and may take a moment to appear.