A decentralized finance lending protocol known as More Markets suffered a targeted exploit that drained approximately $9.3 million in Wrapped FLOW (WFLOW) from one of its lending reserves, according to blockchain security firm Blockaid, which identified and disclosed the attack. The incident represents one of the more technically sophisticated DeFi exploits of 2026, combining a liquid staking token manipulation with an efficiency-mode borrowing loophole to extract funds that should have been protected by standard collateral constraints.
According to Blockaid's analysis, the attacker leveraged a liquid staking token issued by Ankr as the primary instrument of the exploit. Liquid staking tokens derive their value from underlying staked assets, and their price feeds, collateral ratios, and redemption mechanics can create edge cases in lending protocols that are not always anticipated during smart contract audits. In this case, the attacker appears to have used the Ankr liquid staking token as collateral to initiate borrowing positions within More Markets, exploiting the token's characteristics to gain leverage beyond what the protocol's risk parameters were designed to allow.
The second pillar of the attack was E-mode, or Efficiency Mode — a lending mechanism popularized by Aave and subsequently adopted by a growing number of DeFi protocols that allows users to borrow at elevated loan-to-value ratios when their collateral and debt assets belong to correlated or paired categories. E-mode is designed to enable capital efficiency in stable or tightly correlated asset pairs, such as liquid staking tokens against their base layer assets. However, as this incident illustrates, E-mode can also dramatically amplify the damage of a collateral manipulation attack, because the same mechanics that allow legitimate users to borrow more per dollar of collateral also allow bad actors to overborrow if the underlying collateral price or redeemability can be manipulated or misrepresented to the protocol.
The combination of the two vectors — a potentially mispriced or manipulable Ankr liquid staking token and the elevated borrowing ceilings of E-mode — allowed the attacker to overborrow WFLOW far beyond what properly functioning collateral constraints should have permitted, ultimately draining approximately $9.3 million from the lending reserve entirely. The swiftness and precision of the operation suggest a well-prepared actor with deep familiarity with both the Ankr token mechanics and the specific implementation of E-mode within More Markets' smart contract architecture.
For the broader DeFi lending ecosystem, the More Markets incident should serve as a pointed reminder that E-mode, while powerful as a capital efficiency tool, introduces a concentrated category of risk that demands exceptional diligence in collateral whitelisting and price oracle design. The mechanism's effectiveness depends entirely on the assumption that correlated assets remain correlated and that the price feeds governing collateral values are tamper-resistant and manipulation-proof. When liquid staking tokens — which carry layered complexity around redemption queues, slashing risks, and secondary market liquidity — are admitted into E-mode categories, that assumption becomes structurally fragile.
Blockaid's rapid identification of the exploit is noteworthy. The firm's ability to detect and attribute the attack shortly after it occurred reflects a maturing layer of on-chain threat intelligence infrastructure that the DeFi sector has been building over the past several years. However, detection after funds have been extracted offers limited recourse to protocol depositors who have already suffered losses. The $9.3 million drained from More Markets underscores a persistent tension in decentralized finance: the transparency of public blockchains aids forensic investigation but cannot undo losses once an exploit has been executed and assets have been moved.
More Markets' incident also renews debate around how lending protocols should approach the onboarding of novel or derivative collateral types. Liquid staking tokens from protocols such as Ankr occupy a unique risk profile — they are not simple ERC-20 tokens backed by fiat reserves, nor are they direct representations of a single underlying asset. Their value is contingent on multiple layers of smart contract security, validator behavior, staking reward mechanics, and secondary market depth. Admitting such instruments as E-mode-eligible collateral, without extraordinarily conservative parameter settings and robust, manipulation-resistant oracle infrastructure, creates exploitable surface area that sophisticated attackers are demonstrably capable of finding and monetizing.
What This Means for DeFi Lending Protocols
The $9.3 million WFLOW drainage from More Markets is not merely a loss event for one protocol's depositors — it is a stress test result that the entire DeFi lending sector must study carefully. Any protocol currently operating E-mode categories that include liquid staking tokens, rebasing assets, or other derivative collateral instruments should treat this incident as an urgent signal to re-examine collateral risk parameters, oracle configurations, and the interaction between E-mode multipliers and non-standard token mechanics. The attack vector Blockaid identified — using an Ankr liquid staking token in combination with E-mode to overborrow — is not unique to More Markets' codebase; it is a category of exploit that can be replicated wherever similar conditions exist. Capital efficiency and protocol security are not mutually exclusive, but achieving both simultaneously demands a level of adversarial scenario planning that, clearly, remains insufficient across significant portions of the DeFi lending landscape.
Written by the editorial team — independent journalism powered by Codego Press.