defi2 min readAug 31, 2026

Attacker Exploits Ankr Token Vulnerability to Drain $9.3M From More Markets

Security firm Blockaid has identified a sophisticated attack on More Markets that resulted in the theft of approximately $9. 3 million in WFLOW tokens from the protocol's lending reserves.

Via CoinTelegraph
Attacker Exploits Ankr Token Vulnerability to Drain $9.3M From More Markets

Security firm Blockaid has identified a sophisticated attack on More Markets that resulted in the theft of approximately $9.3 million in WFLOW tokens from the protocol's lending reserves.

The Attack Vector

Here's what went down: an attacker leveraged an Ankr liquid staking token combined with E-mode functionality to execute an overborrowing exploit. This wasn't a brute-force hack—it was a calculated manipulation of the protocol's lending mechanics.

The attacker used the Ankr token as collateral, triggering More Markets' E-mode feature (a high-efficiency mode that allows users to borrow more aggressively against approved collateral). By stacking this strategy, they were able to overborrow significantly beyond normal parameters, then systematically drained WFLOW reserves before the protocol could react.

Why This Matters for Crypto Markets

This exploit highlights a critical vulnerability in lending protocols: the interaction between liquid staking tokens and aggressive leverage modes. We've seen this pattern before—attackers probe the edges of DeFi design, looking for gaps where collateral valuation and borrowing limits don't align.

More Markets, like most modern lending platforms, uses E-mode to let sophisticated traders access better rates and higher loan-to-value ratios on approved asset pairs. But this creates attack surface. When a less-understood asset like an Ankr liquid staking derivative enters the equation, the math can break down fast.

The $9.3 million drain represents real capital loss for platform users and liquidity providers. In the broader crypto analysis context, this underscores why due diligence on collateral acceptance matters enormously for protocol security. One miscalibrated risk parameter can cascade into major losses.

Broader Implications for Portfolio Management

For traders and portfolio managers monitoring crypto market intelligence, this incident serves as a reminder: lending protocols aren't risk-free yield sources. They carry smart contract risk, governance risk, and parameter risk. E-mode features are powerful tools, but they're only as secure as their weakest collateral link.

Blockaid's detection of this attack is noteworthy too. The security firm's ability to identify the specific exploit vector—Ankr token + E-mode combination—suggests the crypto security landscape is maturing. Protocols now have better tools to catch attacks mid-execution or post-incident.

Alpha Take

The More Markets exploit reveals that liquid staking tokens remain a vector for sophisticated attacks on lending platforms. When protocols enable high-leverage borrowing (E-mode), they need bulletproof collateral validation—especially for newer or less-liquid assets. Traders should treat any platform offering extreme leverage with proportional skepticism, and lending protocols should audit their approved collateral lists against real-world attack scenarios. This attack will likely trigger protocol reviews across the DeFi space, potentially restricting E-mode access or tightening collateral parameters.

Originally reported by

CoinTelegraph

View source
#defi#regulation#altcoins#market

Not financial advice. Crypto investing involves significant risk. Past performance does not guarantee future results. Always do your own research.

Want deeper crypto analysis?

Get full access to Alpha Factory — daily market briefs, coin analysis, DCA tools, and AI-powered portfolio intelligence.

Explore More