How did the More Markets exploit affect 15.5 million WFLOW on Flow EVM?

Security firm Blockaid reported a $9.3 million exploit at the More Markets lending protocol involving 15.5 million Wrapped Flow (WFLOW) on the Flow EVM. This incident highlights critical security vulnerabilities in emerging DeFi ecosystems and remains under investigation by the protocol team.
How did the More Markets exploit affect 15.5 million WFLOW on Flow EVM?

The More Markets lending protocol on Flow EVM reportedly suffered a significant security breach on Monday, resulting in the loss of 15.5 million Wrapped Flow (WFLOW). According to initial tracking by security firm Blockaid, the total impact of the exploit is estimated at approximately $9.3 million. The incident targeted liquidity within the protocol, marking a high-profile setback for the newly launched Flow EVM environment.

Following the reports from Blockaid, the More Markets team stated they are actively investigating the claims. While the protocol has not yet officially confirmed the final loss amount or the technical root cause, they have committed to publishing a full report once their internal review is complete. This proactive stance is essential as the community waits to see if any user funds can be recovered or if a compensation plan will be initiated.

For US-based DeFi participants, this exploit serves as a stark reminder of the risks associated with providing liquidity to protocols on relatively new network extensions like Flow EVM. While EVM compatibility allows for easier porting of applications, it also introduces a familiar attack surface that malicious actors are quick to exploit. Security auditors and US regulators are increasingly focusing on these types of smart contract vulnerabilities as part of broader consumer protection efforts within the decentralized finance sector.

In the short term, the market may see increased volatility for FLOW as investors react to the news of the $9.3 million drain. The incident underscores the importance of rigorous, multi-firm audits before protocols scale their Total Value Locked (TVL). Moving forward, investors should watch for the official post-mortem from More Markets to understand if the vulnerability was a logic error or a broader issue within the Flow EVM architecture that could affect other projects.