Another decentralized finance protocol has been gutted by a precision exploit. More Markets, a lending platform built on the Flow blockchain, lost approximately $9.3 million in Wrapped FLOW (WFLOW) after an attacker engineered a borrowing manipulation that emptied one of its core lending reserves. The breach, identified and disclosed by blockchain security firm Blockaid, illustrates how the combinatorial complexity of modern DeFi (decentralized finance) primitives continues to open attack surfaces that individual protocol audits rarely anticipate.
According to Blockaid's findings, the attacker leveraged an Ankr liquid staking token as collateral and combined it with E-mode — a feature borrowed from the Aave lending architecture that allows correlated assets to be used with significantly higher borrowing efficiency — to overborrow against the protocol's reserves. The result was a systematic drain of WFLOW holdings totaling $9.3 million, leaving the lending reserve effectively insolvent.
The E-Mode Vector: Efficiency as a Liability
E-mode, shorthand for efficiency mode, was designed to help sophisticated users unlock tighter collateralization ratios when borrowing assets that are economically correlated — for instance, using a liquid staking derivative to borrow its underlying asset at favorable loan-to-value ratios. The assumption baked into the design is that correlated assets maintain their peg relationship under stress. When that assumption fails — or when it can be exploited by manipulating how the protocol prices or classifies an asset — E-mode transforms from a capital efficiency tool into a mechanism for extracting far more value than the collateral actually backs.
In the More Markets incident, the Ankr liquid staking token appears to have served precisely that role. By positioning the token within E-mode's correlated asset framework, the attacker was able to borrow WFLOW at ratios that the protocol's risk parameters were not designed to withstand. The overborrowing was not a brute-force attack — it was a structural arbitrage against the protocol's own lending logic, executed through features the protocol had deliberately enabled.
Blockaid's Role and the Detection Gap
Blockaid's disclosure of the incident underscores a growing reliance on external security monitoring layers in DeFi. The firm specializes in real-time threat detection for blockchain applications, and its ability to reconstruct and name the attack vector suggests the exploit was identifiable after the fact — even if the on-chain mechanics moved too fast for intervention in real time. That gap between detection and prevention remains one of the most persistent structural problems in decentralized lending: by the time an anomalous borrowing pattern triggers an alert, the funds have typically already been moved.
This is not a failure unique to More Markets. The broader DeFi sector has seen repeated incidents where liquid staking derivatives — assets whose value is algorithmically tethered to an underlying token but which carry their own pricing and liquidity characteristics — are used as attack vectors against lending protocols. The reason is straightforward: liquid staking tokens exist in a gray zone between collateral and the asset being borrowed, and protocols that grant them high efficiency-mode status are effectively trusting that peg stability holds under adversarial conditions. Attackers are paid handsomely to find the moments when it does not.
Flow Ecosystem Implications
The Flow blockchain, originally developed by Dapper Labs, has made deliberate efforts to attract DeFi infrastructure beyond its origins in non-fungible token gaming and collectibles. More Markets represents part of that diversification push — an attempt to build out a lending layer that could anchor broader financial activity on Flow. A $9.3 million reserve drain at this stage of the ecosystem's DeFi buildout is not merely a financial loss for affected depositors; it signals a maturity deficit in how risk parameters are being set for novel collateral types on a network that is still establishing its DeFi credibility.
WFLOW, as the wrapped representation of Flow's native token, is also directly tied to the network's liquidity infrastructure. A reserve drain of this scale affects the perceived safety of collateral markets on the chain more broadly, and may prompt more conservative risk frameworks from any protocols considering deployment on Flow.
What This Means for DeFi Risk Architecture
The More Markets exploit adds to an increasingly uncomfortable pattern: attacks that do not rely on flash loans, reentrancy bugs, or oracle manipulation in the traditional sense, but instead exploit the interaction between legitimate protocol features. E-mode combined with a liquid staking token is not, on its own, a vulnerability — it is a product decision. The vulnerability emerges from the specific parameterization choices made about which tokens qualify for which efficiency levels, and what stress scenarios those parameters were tested against.
For DeFi protocols operating lending markets with multiple collateral types and efficiency tiers, the More Markets incident is a pointed reminder that feature composability requires adversarial stress testing that goes beyond standard audits. The question is no longer whether a contract has a bug — it is whether the economic logic holds when a sophisticated actor optimizes against it with real capital. $9.3 million in WFLOW answers that question for More Markets. The sector should take note before the next protocol finds out the same way.
Written by the editorial team — independent journalism powered by Bitcoin News.