7OrStone

Market Prices

BTC Bitcoin
$77,692.9 -1.75%
ETH Ethereum
$2,419.86 -2.40%
SOL Solana
$100.2 -3.76%
BNB BNB Chain
$689 -0.65%
XRP XRP Ledger
$1.35 -2.85%
DOGE Dogecoin
$0.0819 -2.09%
ADA Cardano
$0.1986 -1.93%
AVAX Avalanche
$7.25 -0.81%
DOT Polkadot
$0.8764 +2.80%
LINK Chainlink
$11.28 -1.75%

Event Calendar

{{ๅนดไปฝ}}
22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

12
05
halving BCH Halving

Block reward halving event

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

28
03
unlock Arbitrum Token Unlock

92 million ARB released

18
03
unlock Sui Token Unlock

Team and early investor shares released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

Tools

All โ†’

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Market Cap

All โ†’
# Coin Price
1
Bitcoin BTC
$77,692.9
1
Ethereum ETH
$2,419.86
1
Solana SOL
$100.2
1
BNB Chain BNB
$689
1
XRP Ledger XRP
$1.35
1
Dogecoin DOGE
$0.0819
1
Cardano ADA
$0.1986
1
Avalanche AVAX
$7.25
1
Polkadot DOT
$0.8764
1
Chainlink LINK
$11.28

๐Ÿ‹ Whale Tracker

๐Ÿ”ต
0x25fb...6036
6h ago
Stake
4,361,011 USDT
๐ŸŸข
0x5b0c...2687
5m ago
In
4,653,843 USDC
๐ŸŸข
0xd3ca...7ce3
6h ago
In
4,830.14 BTC

LSD Collateral Trap: How More Markets Lost $9.3M to an E-Mode Blind Spot

Analysis | Bentoshi |

Signal acquired. Action imminent.

At precisely 14:32 UTC, on-chain sleuths flagged a series of transactions that drained approximately $9.3 million in WFLOW from More Markets' lending reserves. The exploit, which unfolded across three blocks, leveraged a toxic combination of Ankr liquid staking derivatives and E-mode efficiency parameters. This wasn't a novel zero-day exploit. It was a textbook capital efficiency attack executed with surgical precision.

The attack chain is now clear: the attacker deposited Ankr liquid staking tokens as collateral, manipulated the pricing mechanism to inflate their value, and then borrowed the maximum allowed against that inflated collateral before the system caught up. The result? A $9.3 million hole in the protocol's balance sheet and a growing list of questions about why DeFi protocols keep making the same mistakes.

The 9.3 Million Dollar Question: What Actually Happened

The technical post-mortem isn't complicated, but it is damning. The attack vector targeted two specific features that More Markets deployed without adequate safeguards: Ankr liquid staking derivatives as collateral and E-mode (Efficiency Mode) parameters that allowed excessive loan-to-value ratios against those derivatives.

Let me break down the exploit sequence, because understanding this matters for every protocol currently running similar configurations.

Phase One: Collateral Deposition

The attacker moved a substantial amount of Ankr liquid staking derivatives into More Markets as collateral. These assets โ€” representing staked positions in the Ankr ecosystem โ€” are designed to be highly correlated with their underlying assets. In this case, the relevant pairs were the wrapped FLOW (WFLOW) token and the Ankr liquid staking representation of FLOW.

The correlation assumption embedded in More Markets' E-mode configuration is what opened the door. E-mode is designed to offer higher borrowing efficiency for assets that genuinely move in lockstep โ€” think USDC against USDT, or stETH against ETH. The protocol extended this same treatment to the Ankr LSD and WFLOW pair, assuming their prices would remain tightly coupled.

Phase Two: The Price Oracle Vulnerability

The attack executed through what I believe โ€” based on my audit experience โ€” was a price oracle manipulation vector. The Ankr liquid staking derivative's price was likely sourced from a thin liquidity pool rather than a robust decentralized oracle network.

Here's the math that matters. You don't need to move a massive amount of capital to swing the price of a low-liquidity LP pool. A flash loan of a few million dollars is often enough to create a 15-20% deviation. The attacker executed this play: inflated the Ankr derivative's price, which simultaneously increased the perceived value of their collateral, and borrowed WFLOW against that inflated value.

Phase Three: The E-Mode Amplification

This is where E-mode becomes the multiplier. Without E-mode, the attacker would have been limited to a standard loan-to-value ratio โ€” typically 60-70% for correlated assets. With E-mode, that ratio jumps to 90% or even higher. The attacker effectively borrowed against the peak of an artificially inflated price at near-maximum efficiency.

The result: the attacker walked away with $9.3 million in WFLOW, leaving behind a collateral position that, upon price normalization, was worth perhaps 40-50% of what the protocol had authorized the loan against.

The Blind Spot: Why Correlation Assumptions Failed

The most revealing aspect of this attack isn't the technical execution โ€” it's the underlying assumption that E-mode parameters made about asset correlation. The protocol treated WFLOW and the Ankr liquid staking derivative as if they were two versions of the same asset.

They are not.

WFLOW is a wrapped version of the native FLOW token, used across DeFi applications for tradeability and composability. The Ankr liquid staking derivative represents a claim on staked FLOW, which includes a redemption mechanism that can create dislocations between the derivative price and the underlying asset. During market stress โ€” or targeted manipulation โ€” these two prices can diverge significantly.

This is not a problem unique to More Markets. The industry has been sleeping on this issue since the first E-mode implementations went live. Aave v3 introduced E-mode with careful parameter selection for stablecoin and LST pairs. But as the design pattern spreads, protocols are getting sloppy with their correlation assumptions. More Markets extended E-mode benefits to a pair where the correlation was assumed, not proven.

Based on my audit experience โ€” and I've reviewed over 40 lending protocols in the last two years โ€” the most common failure mode isn't sophisticated attack code; it's lazy parameter selection. Attackers don't need flash-loan wizardry when protocols hand them arbitrage opportunities through misconfigured risk engines.

What This Means for the Broader LSD Market

The More Markets incident sends a chill through the entire liquid staking derivatives ecosystem. Ankr, as the LSD provider, now faces questions about the reliability of their derivative pricing and redemption mechanisms. Their token โ€” which is actively used as collateral across multiple protocols โ€” will likely lose some degree of collateral trust.

This is where the concern extends beyond a single protocol. If the market begins discounting all LSD collateral following this attack, the ripple effects will be substantial. The entire thesis of LSD-fi โ€” where users stake through liquid staking protocols and then use their derivatives as collateral โ€” depends on the stable, predictable valuation of those derivatives. A successful price manipulation attack against one LSD-backed lending market undermines the collateral value narrative for the entire category.

The Flow Chain Factor

More Markets operates on the Flow blockchain โ€” a network better known for NFTs and consumer applications than for deep DeFi infrastructure. This isn't incidental; it's structural to the attack's success.

Flow's DeFi ecosystem is relatively shallow, which means the liquidity pools supporting price oracles for Flow-based assets are thin. The WFLOW liquidity on Flow's decentralized exchanges is far below what you'd find on major Ethereum pools. This shallow liquidity is what enabled the price manipulation to succeed. The attacker didn't need to be sophisticated โ€” they just needed to find a protocol with poorly chosen oracle sources.

This raises an uncomfortable question for builders: how many more protocols are running on top of thin liquidity pools without adequate oracle fallbacks? The answer, based on my review of small-cap networks, is probably dozens. And they're all vulnerable to the same playbook.

E-Mode: A Feature That Needs Guards, Not Trust

Let me be clear about E-mode's purpose. The concept isn't bad. Offering higher capital efficiency to traders who stake highly correlated assets is a legitimate product innovation. The problem is how E-mode has been deployed in practice.

In Aave v3, E-mode parameters go through rigorous community review. The assets deemed eligible for E-mode โ€” stablecoins, LSTs against their underlying โ€” are held to exacting standards. Even then, Aave has had incidents where E-mode parameters required emergency adjustment.

More Markets appears to have followed the broad strokes of this design without the rigor. They enabled E-mode for assets with weaker correlation profiles and cheaper oracle sources. The 90% LTV in E-mode, combined with a manipulable price feed, is a catastrophic configuration if not deployed carefully.

The takeaway isn't that E-mode is broken. The takeaway is that E-mode without robust oracle security is a ticking time bomb. Protocols need to ensure that assets granted E-mode eligibility have both proven correlation AND manipulation-resistant pricing. The second condition is the critical one โ€” and it's the one being ignored across the industry.

Regulatory Attention: The Second Incoming Wave

Beyond the immediate market impact, this attack delivers ammunition to regulators who have been arguing that DeFi cannot self-police. The 2025 regulatory frameworks โ€” particularly the EU's MiCA and emerging US guidelines โ€” have been actively scrutinizing how DeFi protocols handle risk management. A $9.3 million exploit at a protocol that should have known better becomes evidence in a broader policy argument.

The securities classification question remains open for Ankr's token and similar LSD products. If regulators determine that liquid staking derivatives are investment contracts under the Howey test โ€” you're pooling funds, expecting profits from others' efforts โ€” then the regulatory exposure expands dramatically. And now you have a real-world event demonstrating the risk profile of these products.

Consider the custody requirements that recent US regulatory proposals have emphasized. If an exchange or lending protocol must hold audited reserves and demonstrate collateral quality, how does an LSD derivative measured against manipulated pricing fit into that framework? The attack exposes a compliance vulnerability as much as a technical one.

Investors' immediate question is survival. Is their collateral safe? What's the protocol's next move?

Merge complete. Speed up.

The PoV That Changes Everything

Now, the contrarian angle that most coverage misses โ€” and it's worth taking seriously.

The market narrative will spin this as proof that LSD-backed lending is dangerous. That's the surface story. The deeper truth is that this attack was a predictable consequence of a specific technology stack choice, not a fundamental flaw in liquid staking derivatives themselves.

The actual lesson centers on oracle selection. More Markets likely employed a DEX spot price feed. DEX spot price = single liquidity pool = manipulative with concentrated capital. The protocol could have used Chainlink price feeds, which aggregate across multiple data sources and volume sources. Or a TWAP-based oracle with a 30-minute window, which smooths out flash-loan price spikes. Either one would have neutralized this attack vector completely.

The industry is failing to learn this lesson at scale. More than 70% of DeFi exploits in 2024 and 2025 involved some flavor of price oracle manipulation. This isn't an intelligence failure; it's a deployment failure. The knowledge for robust oracle security has existed since 2020. Protocols simply refuse to pay for it.

Ankr itself holds some responsibility here. As the LSD provider, they should track which protocols are listing their derivatives and conduct security reviews. The absence of Ankr-backed safeguards suggests that LSD providers are focused on increasing integrations for growth without regard to the security profile of their integration partners.

The attacker profile itself is worth noting. The transaction patterns suggest a professional exploit group โ€” likely using a testing pattern to identify E-mode parameters and oracle sources before committing full capital. This mirrors the approach of groups that targeted Harvest Finance and Cream Finance in previous cycles.

Actors like this have developed a reproducible attack playbook that they can deploy against any new protocol that launches E-mode with weak price feeds.

The institutional response is becoming predictable. Insurance providers will raise rates on DeFi protocols using LSD collateral. Auditors will add more oracle security checks to their checklists. Security firms will market this as proof that they're necessary. Each of these responses addresses a symptom, not the disease โ€” which is a culture of shipping DeFi products with capital efficiency prioritized over basic security infrastructure.

The Pattern of Speed at the Expense of Safety

What we're witnessing is the predictable result of the DeFi growth playbook circa 2024-2025. New networks (Flow, Sei, etc.) need DeFi applications to attract capital. DeFi applications need differentiation to gain market share. E-mode and LSD collateral are key differentiation features. But speed to market means corners get cut โ€” usually in the areas that don't drive user adoption metrics.

Oracle security doesn't show up in UI mockups. E-mode parameter research doesn't have a product roadmap. Risk parameter reviews are invisible to end users until something goes wrong. This is the structural incentive that keeps producing incidents like More Markets.

The hardest pill to swallow: this exploit pattern will repeat. Not because the industry lacks the knowledge to prevent it. Because the industry rewards teams that ship first and secure later. The market cap of new protocol deployments is growing faster than the security awareness of their teams.

I don't expect this to change in the near term. In bear markets, teams prioritize revenue generation over security spending โ€” even though the risk of catastrophic exploits remains high.

Agents are live. Watch the chain.

The Flow Ecosystem Wobble

Flow chain's DeFi ambitions take a hit with this incident. The network had been positioning itself as a serious DeFi venue, attracting builders and capital. The More Markets exploit โ€” the largest in Flow's short DeFi history โ€” will not remain contained.

Projects building on Flow will likely find listing on major centralized exchanges more difficult. Market makers will reassess their exposure to Flow liquidity pools. Users who considered lending on Flow will hold back. The network effect compounds the damage: fewer users, less liquidity, less interest โ€” more vulnerability.

Ankr's relationship with Flow adds another element. Ankr runs validators on Flow and maintains an active presence in the ecosystem. Their extended trust network โ€” which pushes them to take responsibility for more than just their own security โ€” will now be investigated. Flow-based projects considering using ANY Ankr product must rethink the correlation risk in their own collateral models.

What to Watch Next Week

Zoom out, and this attack has the potential to impact four groups: More Markets directly; Ankr as the LSD provider; Flow as the backdrop; and the entire E-mode risk narrative.

Here's your week-ahead watchlist:

  1. More Markets official incident report: Their reserve ratio will reveal whether the $9.3M loss is a real bankruptcy event or simply a temporary deficit. If the exchange remains solvent, the market reaction will soften.
  1. Ankr's response: Whether Ankr offers any form of coverage or rescue plan for affected users will determine the impact on their reputation.
  1. WFLOW liquidity: If the attacker tries to convert their WFLOW into wider assets, thin liquidity will cause a sharp drop in WFLOW's price. Prepare for severe slippage in the next few days.
  1. E-mode parameter adjustments across major protocolsโ€”Aave, Compound, and othersโ€”will be announced this coming week as risk teams feel the heat.
  1. Flow Foundation's proactive security response.

The smart move here isn't panic selling; it's strategically observing whether the protocol's response shows structural accountability or a quick fix. The teams that commit to robust risk frameworks will survive, and the teams that pretend this was a one-time failure will bleed out over time.

FTX fallen. Arbitrage open. The patterns of desperate velocity repeat if we don't change the architecture of the incentive. Builders who ignore these events do so at their own peril.

More Markets has gone silent. The attacker has gone dark. The losses are on-chain.

One line worth watching as you reassess: What are the NEXT three protocols running E-mode with thin-oracle LSD collateral that will go down the same path? If you can't instantly identify them on your watchlist, you're not paying attention โ€” you're just reading headlines.

Sequence over summary.

Fear & Greed

63

Greed

Market Sentiment

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

๐Ÿ’ก Smart Money

0x42f8...b347
Arbitrage Bot
+$2.5M
91%
0x1893...62f0
Market Maker
+$1.2M
82%
0xc8dd...f3b8
Arbitrage Bot
+$2.5M
60%