A Slightly Unpleasant Alert: A lending protocol called More Markets, under More Labs and deployed on Flow EVM, has been attacked. According to monitoring by Blockaid, the attacker used Ankr bonded LST and the E-mode mechanism to siphon approximately 15.5 million WFLOW (worth about $9.3 million) from the WFLOW lending reserves.
Let’s break down the mechanism: E-mode allows a protocol to set more aggressive liquidation parameters for specific pools to attract liquidity. However, if the underlying asset’s real risk (here, a secondary wrapper product like Ankr bonded LST) is underestimated, then once the price deviates or if the oracle or liquidity behaves abnormally, those aggressive parameters become the attacker’s leverage—effectively emptying the pool. This is also a common thread across multiple lending-protocol thefts this year: the single point of code didn’t “break”; instead, a combination of parameter settings stacked with asset selection created the composite risk.
$9.3 million isn’t especially large compared to the overall DeFi theft ledger, but it is a clear hit to borrowing activity in the Flow ecosystem. Risk controls for Flow EVM protocols will likely tighten in the short term, and $FLOW will face near-term pressure. A reminder as well: in DeFi lending, those “higher-looking returns” tied to E-mode, bonded LST, and wrapped staked tokens are fundamentally built on parameter and price assumptions. The more aggressive the position, the more you need to understand the liquidation conditions first—don’t just chase the APY.
#DeFi安全 #安全事件
Let’s break down the mechanism: E-mode allows a protocol to set more aggressive liquidation parameters for specific pools to attract liquidity. However, if the underlying asset’s real risk (here, a secondary wrapper product like Ankr bonded LST) is underestimated, then once the price deviates or if the oracle or liquidity behaves abnormally, those aggressive parameters become the attacker’s leverage—effectively emptying the pool. This is also a common thread across multiple lending-protocol thefts this year: the single point of code didn’t “break”; instead, a combination of parameter settings stacked with asset selection created the composite risk.
$9.3 million isn’t especially large compared to the overall DeFi theft ledger, but it is a clear hit to borrowing activity in the Flow ecosystem. Risk controls for Flow EVM protocols will likely tighten in the short term, and $FLOW will face near-term pressure. A reminder as well: in DeFi lending, those “higher-looking returns” tied to E-mode, bonded LST, and wrapped staked tokens are fundamentally built on parameter and price assumptions. The more aggressive the position, the more you need to understand the liquidation conditions first—don’t just chase the APY.
#DeFi安全 #安全事件