More Markets, a lending protocol on Flow EVM, has reportedly suffered an exploit involving an Ankr-related liquid staking token and its E-Mode lending system.
Preliminary monitoring identified about 15.5 million WFLOW moving out of the mFlowWFLOW reserve, with the impact estimated at roughly $9.3 million. Investigators are still tracing the funds, so the amount transferred should not yet be treated as the protocol’s final loss.
The early evidence points to a problem within the lending market rather than an attack on the Flow blockchain itself. It also does not prove that Ankr’s staking protocol was compromised.
More Markets is built on Aave V3 architecture. Users supply assets as collateral and borrow other tokens from the protocol’s reserves.
According to the preliminary attack analysis, the attacker used an Ankr-related bound liquid staking token as part of the collateral process. The position was then placed into E-Mode, which appears to have increased the amount of WFLOW that could be borrowed.
The reported path was relatively direct: the attacker obtained or created the relevant staking asset, used it to gain borrowing power, entered E-Mode and withdrew WFLOW from the available lending reserve. The funds were then moved through a group of related transactions.
The exact weakness has not been confirmed. It may have involved the way More Markets counted the staking token, the way E-Mode valued the position or a mismatch between the token’s transfer rules and the protocol’s collateral calculations.
Until More Markets publishes a technical report, describing the incident as an oracle attack or a flaw in the underlying Aave V3 code would be premature.
E-Mode is designed for assets expected to stay close in value. In this case, WFLOW and ankrFLOW both represent exposure to FLOW, so treating them as correlated assets may appear reasonable.
That relationship allows a protocol to give users more borrowing power. The trade-off is a smaller safety margin if the two assets stop behaving as expected.
Liquid staking tokens are not simply wrapped copies of their underlying assets. Ankr describes ankrFLOW as a reward-bearing token whose value against FLOW can increase over time. Its redemption process may also involve an unbonding period.
These differences matter. A lending protocol must understand not only the token’s market price but also how it is minted, transferred, redeemed and recorded in user balances. If one of those behaviors is handled incorrectly, E-Mode can turn an accounting mismatch into real borrowing capacity.
From MEXC’s perspective, this is the central issue. The incident appears less like a broad failure of Flow EVM and more like a failure to account for how a specific collateral asset behaved inside an aggressive lending mode. Reusing audited lending code does not remove the risks created by new collateral integrations.
The reported movement of 15.5 million WFLOW shows the potential size of the incident, but it does not reveal how much money the protocol will ultimately lose.
Some value may remain in the attacker’s collateral position. Funds could also be moved repeatedly between related addresses, making the transaction total larger than the actual amount removed. Recovery efforts, asset freezes and any remaining collateral will affect the final result.
For lenders, the more important number is the bad debt left in the WFLOW reserve. If the attacker borrowed more than the remaining collateral can repay, mFlowWFLOW holders may face a shortfall.
A clear reserve report from More Markets is therefore more useful than another estimate of the attacker’s transfers. It should show the WFLOW still available, the outstanding debt and whether affected deposit claims remain fully backed.
The immediate risk appears concentrated around More Markets and the affected WFLOW market. There is no confirmed evidence that the Flow network or other Flow EVM applications share the same weakness.
Users should now watch for an official post-mortem, the status of deposits and withdrawals, and the location of the transferred funds. It will also be important to learn whether More Markets has frozen the affected collateral, disabled new borrowing or introduced a recovery plan.
The event may also cause other lending protocols to review liquid staking assets placed in high-efficiency collateral groups. Two tokens can follow the same price while still behaving differently at the contract level. That difference becomes dangerous when a protocol allows users to borrow close to the full value of their collateral.
For FLOW traders, the market impact will depend less on the headline attack amount and more on whether the problem remains limited to one protocol. Evidence of wider exposure would increase the risk, while a contained incident with a clear recovery plan would reduce it.
Preliminary monitoring estimated an impact of about $9.3 million and identified roughly 15.5 million WFLOW moving from the mFlowWFLOW reserve. The final loss has not been confirmed.
Current evidence points to an exploit involving More Markets’ lending system. There is no confirmed indication that the Flow blockchain or Flow EVM infrastructure was compromised.
An Ankr-related liquid staking token was reportedly used in the attack path, but this does not prove that Ankr’s protocol was hacked. The weakness may have been in how More Markets integrated and valued the asset.
The attack path, affected balance and final loss remain under investigation. Early on-chain estimates may include repeated transfers or assets that are still recoverable. Users should confirm the operating status of More Markets directly before supplying, borrowing or withdrawing assets. DeFi lending and liquid staking products carry smart-contract, collateral, liquidity and liquidation risks.
Research checked outside article body: More Markets protocol repository and market configuration, More Markets documentation, Ankr Flow liquid staking documentation, Flow ecosystem documentation.


