According to Blockaid, the attacker used the Ankr liquid staking token and E-mode to borrow more funds from More Markets. Approximately $9,3 million in WFLOW was withdrawn from the lending protocol's reserve, as reported in a Cointelegraph article.

The case is significant because it affects not only an individual borrowing operation but also the liquidity of the lending reserve. If Blockaid's description is accurate, the vulnerability may have been related to how the protocol evaluated collateral and limits within E-mode.

The available package is based on metadata and a Cointelegraph retelling rather than the full text of Blockaid's primary report or independent verification. Therefore, the exact mechanics of the attack, the status of the funds, and the scale of impact on More Markets users cannot yet be established.