When your collateral is more valuable than the rules that govern it, someone will notice.
The Summary
- Security firm Blockaid reported that an attacker drained approximately $9.3 million in Wrapped Flow (WFLOW) from More Markets on Flow EVM using an Ankr liquid staking token and E-mode to overborrow from lending reserves
- More Markets lost 15.5 million WFLOW total but hasn't confirmed the loss, saying the team is reviewing the claim
- The exploit demonstrates how DeFi efficiency modes, designed to maximize capital efficiency, can become attack vectors when collateral valuation gets complex
The Signal
CoinTelegraph identified the attack vector: the attacker used an Ankr liquid staking token combined with E-mode to overborrow from the protocol. E-mode, or efficiency mode, lets users borrow more when their collateral and borrowed assets are correlated. It's a feature that assumes similar assets move in similar directions. The attacker found the gap between that assumption and reality.
BeInCrypto reported the total loss at 15.5 million WFLOW, which Blockaid valued at $9.3 million at the time of the exploit. The protocol itself hasn't confirmed anything, which is telling. When a DeFi protocol goes silent after a reported exploit, it usually means lawyers are in the room and the forensics team is still counting.
"The exploit highlights vulnerabilities in DeFi protocols, emphasizing the need for enhanced security measures."
Here's what makes this different from the typical flash loan exploit: liquid staking tokens. When you stake ETH or FLOW or any proof-of-stake asset, you get a receipt token. Ankr gives you one. Lido gives you one. These tokens represent your staked position plus accrued rewards. They're supposed to track the underlying asset closely. But "closely" isn't "exactly," and in DeFi, that gap is an opportunity.
E-mode was built for situations like stablecoins borrowing stablecoins, or ETH derivatives borrowing ETH. The logic is sound: if you deposit stETH and borrow ETH, the protocol can let you borrow more because your collateral and debt move together. But liquid staking tokens introduce yield, lockup periods, and smart contract risk. The price relationship gets messy. The attacker likely exploited either a pricing oracle delay or a fundamental mispricing of the Ankr token relative to WFLOW.
Key mechanics of the attack:
- Used Ankr liquid staking token as collateral
- Enabled E-mode to increase borrowing capacity
- Borrowed maximum WFLOW against inflated or mispriced collateral
- Drained lending reserves before the protocol could respond
This isn't a smart contract bug in the traditional sense. The code probably worked exactly as written. The vulnerability was in the economic model, in the assumptions about how different tokens correlate and how oracles price complex derivatives of staked assets.
The Implication
If you're building or deploying capital in DeFi, understand that efficiency modes are leverage in disguise. They let you do more with less collateral, which means smaller price dislocations have bigger consequences. Liquid staking tokens are not the same as their underlying assets. They carry yield, smart contract risk, liquidity risk, and redemption mechanics that base assets don't have. Pricing them as if they're equivalent is asking for trouble.
For users of lending protocols: check whether your platform uses E-mode and what assets it treats as correlated. If the answer involves liquid staking derivatives, know that you're taking on second-order risk. More Markets hasn't confirmed the loss, but the silence suggests Blockaid's forensics are accurate. Watch for a postmortem. The details will matter for every other protocol using similar efficiency features.