Inside the More Markets Protocol Exploit

The decentralized lending protocol More Markets, operating on the FlowEVM blockchain, has been hit by a sophisticated security breach. Monitoring data from Blockaid reveals that attackers successfully drained the protocol's WFLOW lending reserves, making off with 15.5 million tokens.

The Attack Vector: Exploiting Mechanism Interaction

This was not a straightforward code bug exploit. The attack targeted a specific interaction point within the protocol's design: the interface between Ankr's bonded Liquid Staking Token and the E-Mode borrowing feature.

E-Mode typically allows for high-leverage borrowing between correlated assets to increase capital efficiency. Bonded LSTs represent a specific type of staking derivative. The exploiters identified a flaw in the pricing or collateral logic when these two features were combined.

  • Step 1: Likely by manipulating the perceived value of the LST or its relationship within E-Mode, the attackers obtained disproportionately large borrowing power.
  • Step 2: This borrowing power was then used to draw massive amounts of WFLOW from the protocol's reserves.
  • Step 3: Before any internal risk controls could react, the drained assets were moved off-chain.

The result was the near-total depletion of the WFLOW lending pool, translating to an estimated loss of $9.3 million.

Implications and Industry Wake-Up Call

The incident deals a significant blow to the More Markets protocol and its users. Beyond the substantial financial loss, which undermines user trust, it highlights the latent dangers in DeFi's composable "money Lego" model.

When multiple complex protocols and derivatives are stacked, their interaction surfaces can create unforeseen vulnerabilities. Attackers increasingly target these "composability risks." This event serves as a stark warning for the broader DeFi sector, especially for protocols integrating multiple derivative products and complex borrowing mechanics. It underscores the need for security audits to focus intensely on cross-component logic, moving beyond the safety of individual smart contracts.