More Markets lending reserve exploit

More Markets $9.3M Lending Reserve Drained: DeFi Security Breakdown Explained

A sophisticated attack on More Markets drained $9.3 million in WFLOW tokens from a lending reserve, exposing critical vulnerabilities in DeFi protocol design. The attacker exploited a combination of liquid staking mechanics and enabled E-mode borrowing to overborrow far beyond safe limits—a pattern that highlights structural risks across the entire lending ecosystem.

More Markets $9.3M Exploit: How DeFi Vulnerabilities Expose User Funds

What Happened: The More Markets Attack

More Markets, a decentralized lending protocol, lost approximately $9.3 million in WFLOW tokens when an attacker exploited a flaw in how the platform manages collateral and borrowing limits. Security firm Blockaid traced the attack to a coordinated use of Ankr liquid staking tokens combined with E-mode borrowing—a feature designed to allow higher leverage between similar assets but instead became a vector for fund extraction.

The attacker did not use traditional hacking or private key theft. Instead, they exploited the protocol's own rules to create an arbitrage opportunity that drained the lending reserve. This type of attack is particularly dangerous because it operates within the legitimate transaction framework of the blockchain, making it harder to prevent retroactively.

Understanding the Attack Vector: Liquid Staking and E-Mode

Liquid staking tokens (LSTs) like Ankr's derivatives allow users to earn staking rewards while maintaining liquidity. The vulnerability emerged from how More Markets valued and accepted these tokens as collateral.

The attack sequence likely followed this pattern:

  1. Attacker deposits a liquid staking token (Ankr token) as collateral
  2. Protocol assigns an inflated or misaligned collateral value to the deposit
  3. E-mode is activated, which allows increased borrowing ratios between correlated assets
  4. Attacker borrows far more WFLOW than prudent risk management would allow
  5. Over time or through price manipulation, the attacker extracts value and drains the reserve

The core issue: E-mode was designed to let traders borrow heavily when assets are highly correlated (reducing perceived risk), but the protocol failed to account for the fact that the collateral itself could lose value or become illiquid, leaving the lending reserve undercapitalized.

Why This Matters for Crypto Users and Traders

This incident reveals a structural weakness in many DeFi protocols: collateral valuation lag. When a lending platform accepts a liquid staking token as collateral without proper redundancy checks and price feed validation, it creates a gap that attackers can exploit.

The ripple effects include:

  • Users who deposited WFLOW to earn lending interest face potential losses
  • Confidence in the More Markets platform erodes, affecting deposit flows
  • Other protocols using similar logic face renewed scrutiny
  • Regulatory pressure on DeFi platforms intensifies

For anyone holding funds in lending protocols, this attack demonstrates that platform reputation alone is not sufficient protection. Even audited smart contracts can contain logical vulnerabilities that only manifest under specific market conditions or attacker innovation.

Distinguishing Risk: DeFi Protocols vs. Regulated Exchanges

The More Markets incident highlights key differences between decentralized finance and centralized crypto exchanges:

FactorDeFi ProtocolsRegulated Exchanges
Insurance coverageOften none; user assumes lossCustodial insurance; regulated liability
Counterparty trustSmart contract code; permissionlessLicensed operators; compliance audits
Withdrawal controlUser self-custody (keys); protocol riskExchange custody; operational risk
Reserve transparencyOn-chain visible (sometimes)Periodic audits; regulatory reporting
Recourse after lossCommunity governance vote (slow)Regulatory complaint; recovery process

Neither is inherently safer—the risk model is fundamentally different. DeFi offers permissionless access and self-custody; this comes with direct exposure to protocol risk. Centralized exchanges offer operational security but require trusting an institution.

Protecting Your Crypto Holdings from DeFi Exploits

If you actively use lending protocols, follow these principles:

  1. Diversify across multiple platforms rather than concentrating funds in one lending reserve
  2. Use only established, frequently audited protocols with significant total value locked (TVL) and transparent governance
  3. Monitor collateral ratios and protocol parameters actively—don't set and forget
  4. Avoid exotic assets or newest tokens as collateral; stick to major stablecoins and established blockchain primitives
  5. Never use E-mode or other leverage features unless you fully understand the liquidation mechanics
  6. Keep emergency withdrawal plans in place; understand how to exit before a protocol fails
  7. Verify that your holdings are not locked in a vulnerable position by checking on-chain data directly

For additional verification of counterparty security and to screen addresses before sending funds, consult AML screening tools that check against darknet and stolen-funds databases.

Frequently Asked Questions

Q: Could More Markets have prevented this attack through code audits alone?

A: Not entirely. Smart contract audits catch programming errors but often miss logical vulnerabilities that emerge under specific market conditions. Continuous monitoring and tiered withdrawal limits could have reduced the damage once the drain began.

Q: Is my crypto safer in a regulated exchange than in DeFi?

A: It depends on your threat model. Exchanges offer insurance and compliance oversight; DeFi offers self-custody and censorship resistance. More Markets' loss was a protocol failure, not a custody failure—your private keys were never compromised.

Q: Should I withdraw all funds from DeFi lending platforms?

A: No. Instead, size your DeFi exposure appropriately. Use these platforms only for amounts you can afford to lose, and only in protocols you've studied in depth.

Q: How do I check if a lending protocol is vulnerable to similar attacks?

A: Review the protocol's collateral pricing mechanism, check if recent audits mention E-mode or leverage risks, and monitor community discussions for reported vulnerabilities. Look for transparency in reserve composition and liquidation procedures.

Key Takeaways

The More Markets $9.3 million drain demonstrates that DeFi security is not a binary property—safe or unsafe. Instead, protocols operate on a spectrum of risk, with vulnerabilities often hiding in the interaction between multiple features rather than in any single component.

If you routinely interact with lending protocols or other smart contract platforms, treat each one as an experiment with limited funds. Verify the legitimacy of any platform before depositing, use AML screening for counterparty verification where available, and maintain operational security practices tailored to blockchain-specific threats.

For users seeking regulated alternatives with custodial insurance, review our Verified Marketplaces page to evaluate exchanges with transparent security practices and regulatory compliance.

Source: Cointelegraph