We didn't see a re-entrancy attack. We didn't see an integer overflow. We saw something far more dangerous: a textbook exploitation of a protocol's own efficiency features turned against it. The Flow EVM-based lending protocol, More Markets, has been drained of approximately $9.3 million. The initial assessment from security firm Blockaid points to a complex mechanism involving Ankr's bonded liquid staking token and the protocol's E-Mode settings. That is the headline. The structural lesson is far more uncomfortable: a feature designed to maximize capital efficiency became the vector for its complete capitulation.
The cold, hard math is the first place to start. Reports indicate that 15.5 million WFLOW tokens were impacted, with an initial value assessment of $9.3 million. This implies a token price of roughly $0.60. Yet, a concurrent report placed the FLOW token price at a mere $0.026. If the WFLOW/FLOW peg held at 1:1, that 15.5 million token haul would be worth approximately $403,000—a 23-fold discrepancy from the stated loss. This is not a minor data error; it is a massive signal that the original price data was either a typographical error or fundamentally misaligned with market reality. We will proceed with the $0.60 per token market logic, as it is the only internally consistent data point.
The story here is not just about More Markets; it is about the fragility of the DeFi lending narrative in 2025. This is the third significant lending protocol attack in a single week, following incidents involving Tectonic on Cronos and Moonwell on Base. Combined losses are approaching $27 million. The market's aggregate reaction was a mere 3% dip. That numbness is the real danger. It signals that the market is beginning to price in these catastrophic failures as a standard operating cost, which it is not. This is not a software bug; it is a risk-model failure.
Let's dissect the attack vector. Blockaid's assessment is clear: the attacker leveraged the protocol's E-Mode—a feature borrowed directly from Aave V3's design playbook—in concert with Ankr's bonded LST. The E-Mode allows borrowers to achieve higher loan-to-value ratios when their collateral is deemed highly correlated with their borrowed asset. In a standard setup, this might involve borrowing ETH against stETH. That logic relies on the collateral being a robust, deeply liquid, and tightly pegged asset. Ankr's bonded LST is none of those things. It is a long-tail asset with comparatively thin liquidity and higher price volatility.

The attack wasn't an exploit of a single line of code; it was an exploit of an economic relationship. The attacker likely manipulated the price of the Ankr LST upwards, or exploited a temporary liquidity vacuum, to create a false sense of collateral value within the E-Mode's correlation window. This allowed them to borrow against it more aggressively than the underlying asset's true worth could support. The result: the mFlowWFLOW reserve was emptied. This isn't just a hack; it's a forensic indictment of a design philosophy that prioritizes feature adoption over risk mitigation. More Markets adopted Aave V3's E-Mode functionality but failed to implement the corresponding safety rails—specifically, the robust price monitoring, liquidation controls, and borrowing capacity constraints that Aave has built up over years of operation.
The core insight for any DeFi operator is that audit maturity and feature maturity are not synonymous.
This event exposes a critical blind spot in how we assess protocol security. The market often equates the presence of battle-tested features with security. In reality, an unprepared fork can be far more dangerous than a bespoke codebase. The key mechanism is not the E-Mode itself, but its interaction with a non-standard asset. The attack path was a combination of three factors: the availability of a volatile LST, a protocol's allowance for it to be used as collateral in a high-efficiency mode, and an insufficiently robust price oracle mechanism for that specific asset. This is where the next wave of attacks will be focused. This is not a random exploit; it is a systematic discovery of protocol fragility and will be replicated.
The immediate market impact is severe but localized. The TVL has dropped from an estimated $12.9 million to roughly $3.6 million—a 72% contraction. FLOW is down 8%, and the token has suffered a severe confidence shock. This isn't a question of whether More Markets will survive; it's a question of whether the broader Flow EVM ecosystem can absorb this reputational damage. The flow of funds will now be the primary data point to track. The 11 known transfers and the attacker's address are public. The critical signal will be a significant deposit to a KYC-controlled exchange, which would indicate a move toward liquidation.
But Alpha isn't about tracking the stolen funds; it's about recognizing the systemic implication hidden in the collective belief system. The contrarian narrative is that this attack will ultimately be a positive for the security sector. Every event like this, while damaging in the short term, accelerates the demand for adaptive security infrastructure. The current model of static audits is obsolete. We are moving toward a world where continuous on-chain monitoring, threat intelligence, and real-time response are not just nice-to-haves but the primary requirements for institutional capital. Blockaid's contribution here is not just identifying the exploit but proving the value of its real-time monitoring. This will be the primary vector of value creation in the immediate future.

History doesn't reward the pioneers; it rewards the survivors. The immediate signals to watch are simple. First, watch the attacker's wallets for large transfers to exchanges. Second, watch More Labs' response window—if they promise full compensation within 24 hours, the rhetoric is different than if they promise an investigation. Market signals will provide the clearest directional guide: watch the WFLOW/FLOW liquidity depth on DEXs. A 20% drop in liquidity over 48 hours will tell you the market makers have already made their decision.
We are seeing a pattern of lending protocols attacking each other. This isn't a failure of one team. This is the failure of a prevailing narrative. The narrative claimed that by adopting successful features and listing high-yield assets, a project could bootstrap liquidity rapidly. The reality is that liquidity without risk management is not an asset—it is a liability waiting for a smarter actor to claim it.
The takeaway is uncomfortable. We are entering a phase where the market will demand that innovation in capital efficiency be matched by equal innovation in capital protection. The winners in the next cycle will be those who build authenticated data streams, adaptive liquidation mechanisms, and built-in circuit breakers—not those who simply scale the leverage. The next question is not if the market will punish poor risk architecture. It is whether you will be positioned to capture value from the flight to quality when it does. The $9.3 million is gone. The opportunity is in the rebuild.