The $9.3 million drain on More Markets was executed through a sophisticated exploit involving Ankr liquid staking tokens and the platform’s E-mode functionality. According to security firm Blockaid, the attacker utilized these assets to overborrow Wrapped Flow (WFLOW) from a lending reserve, effectively bypassing standard collateralization limits. By leveraging E-mode—a feature designed to increase capital efficiency for correlated assets—the exploiter was able to extract significantly more value than their collateral should have permitted.
This breach highlights a specific vulnerability in how lending protocols handle Efficiency Mode for liquid staking tokens (LSTs). E-mode typically allows users to access much higher loan-to-value (LTV) ratios because the assets involved are expected to maintain a stable price relationship. However, if the protocol's risk parameters or price feeds for LSTs like those from Ankr are not perfectly synchronized, it creates a window for attackers to manipulate the system and drain liquidity pools.
For the US-based crypto community, this event serves as a stark reminder of the "composable risk" inherent in the DeFi ecosystem. As liquid staking becomes a cornerstone of yield strategies, its integration into complex lending structures introduces new attack vectors. US regulators, who have already expressed concerns regarding the stability and security of decentralized finance, are likely to view such exploits as evidence that current protocol safeguards may be insufficient to protect user capital without stricter oversight.
Investors and DeFi participants should now watch for a formal post-mortem from More Markets and Ankr to determine if the issue stemmed from a configuration error or a more fundamental flaw in the E-mode implementation. The recovery of the $9.3 million in WFLOW remains uncertain, and the incident may prompt other lending platforms to revisit their risk settings for liquid staking assets to prevent similar over-borrowing attacks in the future.