In a recent security breach that has sent shockwaves through the decentralized finance community, an exploit involving an Ankr liquid staking token and Aave’s efficiency mode (E‑mode) allowed a malicious actor to over‑borrow from the More Markets protocol and drain approximately $9.3 million worth of Wrapped Flow (WFLOW) from its lending reserve. The incident underscores the growing sophistication of DeFi attacks and highlights the need for rigorous risk management across multi‑chain lending platforms.
More Markets, a rapidly expanding lending platform that leverages Aave V3 technology, offers users the ability to earn interest on a wide range of assets, including emerging tokens such as WFLOW. The protocol’s integration of E‑mode is designed to boost capital efficiency by allowing users to borrow at higher loan‑to‑value ratios when the collateral and borrowed assets share similar risk profiles. While E‑mode can improve capital utilization, it also reduces the safety buffer that protects against market volatility, creating a potential vector for exploitation.
The attacker’s strategy centered on the Ankr liquid staking token, a derivative asset that represents staked tokens on the Ankr network. By depositing this token as collateral and simultaneously activating E‑mode, the malicious actor was able to bypass conventional borrowing limits. The protocol’s risk parameters did not adequately account for the unique price dynamics of liquid staking derivatives, allowing the attacker to inflate the perceived value of the collateral and extract more WFLOW than the reserve could sustain.
Security analysts have identified several contributing factors to the breach. First, the oracle feeds used to price the Ankr liquid staking token were not sufficiently decentralized, leaving the protocol vulnerable to price manipulation. Second, the E‑mode configuration for the WFLOW market was set at a loan‑to‑value ratio that did not reflect the token’s historical volatility, effectively lowering the collateralization threshold. Finally, the lack of real‑time monitoring for abnormal borrowing patterns meant that the exploit went undetected until the reserve was significantly depleted.
In response to the incident, More Markets has initiated a comprehensive review of its risk parameters and is working closely with external auditors to reinforce its oracle architecture. The protocol plans to introduce tighter controls on the use of liquid staking tokens as collateral, including higher collateralization requirements and stricter E‑mode caps for high‑risk assets. Additionally, the platform is exploring the implementation of automated anomaly detection tools that can flag suspicious borrowing activity in real time.
The broader DeFi ecosystem can draw several lessons from this event. Developers must recognize that novel token types, such as liquid staking derivatives, introduce new risk dimensions that traditional risk models may not capture. Integrating diversified oracle networks and conducting regular stress tests on collateral configurations can mitigate the likelihood of similar exploits. Moreover, while efficiency mechanisms like E‑mode provide attractive capital efficiency benefits, they must be balanced with robust safeguards to prevent over‑leveraging.
Investors who held WFLOW in the More Markets lending pool have reported varying degrees of loss, depending on the timing of their deposits and withdrawals. The incident has reignited discussions around insurance solutions in DeFi, with several protocols now evaluating coverage options for liquidity providers facing smart contract or oracle failures. As the sector continues to mature, the demand for reliable risk mitigation products is expected to rise.
Regulatory observers are also taking note, as the breach illustrates the challenges of supervising cross‑chain lending platforms that operate without a centralized authority. While DeFi remains largely unregulated, the incident may prompt policymakers to consider frameworks that encourage transparency in risk parameter disclosures and enforce standards for oracle security.
In summary, the More Markets exploit serves as a stark reminder that the convergence of innovative tokenomics and efficiency‑driven borrowing mechanisms can create unforeseen vulnerabilities. By addressing the identified gaps in collateral valuation, oracle reliability, and real‑time monitoring, the DeFi community can strengthen the resilience of lending protocols and restore confidence among participants.
