More Markets Loses $9.3M in WFLOW After Attacker Exploits Ankr Liquid Staking Collateral
A DeFi lending protocol built on the Flow blockchain was drained of $9.3 million after an attacker combined an Ankr liquid staking token with E-mode functionality to overborrow against the protocol's reserves. Security firm Blockaid identified the exploit.
More Markets Loses $9.3M in WFLOW After Attacker Exploits Ankr Liquid Staking Collateral
A DeFi lending protocol built on the Flow blockchain was drained of $9.3 million today after an attacker combined an Ankr liquid staking token with E-mode functionality to overborrow against the protocol's reserves.
Security firm Blockaid identified and reported the attack, describing the mechanics plainly:
"An attacker used an Ankr liquid staking token and E-mode to overborrow from More Markets and drain about $9.3 million in WFLOW from a lending reserve."
Blockaid
The target was WFLOW, the wrapped version of Flow's native token, held in one of More Markets' lending reserves. E-mode, short for Efficiency Mode, is a feature common in Aave-style lending architectures that lets borrowers access higher loan-to-value ratios when their collateral and debt assets are considered correlated. The idea is to improve capital efficiency for closely related assets. The risk, as this exploit demonstrates, is that misconfigured E-mode parameters can let an attacker borrow far more than their collateral actually supports.
The attack follows a well-worn playbook. An attacker deposits a liquid staking token, in this case an Ankr-issued staking derivative, into a lending market with permissive E-mode settings. Because E-mode reduces collateral requirements, the attacker can borrow significantly more than the collateral's real market value warrants. The protocol's risk parameters, which should cap this exposure, apparently did not account for the specific combination of ANKR as collateral inside E-mode. The result: $9.3 million in WFLOW walked out the door.
This class of exploit is not new. The bZx flash loan attacks in 2020 and the Curve Finance reentrancy vulnerability in 2023 both traced back to edge cases in risk parameter design rather than outright bugs in core logic. Liquid staking tokens have become a particularly sharp edge. They carry layered complexity: the underlying asset, the staking yield accrual, and the derivative's market liquidity all need to be modeled correctly for collateral risk to be priced accurately. When one of those inputs is misconfigured, or when an E-mode grouping treats a liquid staking token as equivalent in risk profile to the asset it tracks, the gap between assumed and actual collateral value becomes exploitable.
More Markets could argue this was an edge case in risk parameter configuration rather than a flaw in the protocol's core architecture. That framing is technically defensible. Ankr's liquid staking token is not itself compromised, and E-mode as a concept is not inherently broken. The failure was in how the two were combined, and how the protocol's risk team assessed that combination. Adjusting collateral factors and E-mode eligibility can prevent recurrence. What it cannot do is recover the $9.3 million already gone.
For lenders sitting in More Markets reserves right now, the more immediate question is whether other reserves carry similar exposure. Protocols built on Aave's architecture typically support multiple isolated and cross-collateral markets, meaning one drained reserve does not automatically implicate others. But confidence in the protocol's risk modeling takes a hit across the board when one configuration fails this badly.
The Flow blockchain, while less trafficked than Ethereum or Solana, has been building out its DeFi layer steadily. A $9.3 million exploit on its largest lending protocol is a meaningful setback for that effort. WFLOW liquidity in lending markets is thin relative to major chains, which likely made it an attractive target: high-value reserve, lower on-chain scrutiny, and a protocol that may not have had the same battle-hardened risk parameter review that older Ethereum-native protocols carry.
More Markets has not issued a post-mortem as of publication. Blockaid's disclosure suggests the security community caught this quickly, but speed of detection does not help depositors who were already exposed. The protocol will need to pause affected markets, assess total losses, and determine whether any recovery mechanism, insurance fund, or governance-led remediation is available to affected users.
Depositors in any More Markets reserve should treat their positions as potentially at risk and monitor official channels closely.





