Jejugin Consensus
Macro

The $9.3 Million Acceptance Test: E-Mode and the False Promise of Correlated Collateral

0xCobie
Truth is not given, it is verified. The freshly minted exploit on More Markets, a Flow-chain lending protocol, verifies an old axiom: parameter configuration is not a design afterthought; it is the security perimeter itself. In a single transaction, an attacker borrowed $9.3 million in WFLOW against Ankr’s liquid staking derivative and vanished. The protocol’s risk engine was engineered to assume correlation. The attacker turned that assumption into liquidity. We do not trust; we verify. That is the axiom. But most protocols fail to verify their own parameters. They verify the code compiles, the functions execute, and the auditors sign off. They do not verify that the economic assumptions underpinning the protocol's health factor can survive a deliberate, coordinated attack. More Markets is now the latest schoolhouse for that lesson. More Markets is not a household name, and that is precisely the point. It sits inside a smaller ecosystem, Flow's nascent DeFi economy, offering leverage against liquid staking derivatives. Its E-mode, modeled after Aave v3's Efficiency Mode, is designed to allow assets that move in lockstep to be borrowed against with reduced collateralization. The theory is simple: if two assets are near-perfect substitutes, a lender is safe with a 95% loan-to-value ratio because a liquidation will never trigger anyway. The practice is more dangerous. Ankr is a major LSD provider. Its liquid staking token for Flow, ankrFLOW, represents staked FLOW plus accrued staking rewards. The token's price is not a hard peg. It floats based on market demand, staking yield, and the redemption queue. Institutions do not treat ankrFLOW as a stablecoin. Individuals treat it as a yield-bearing asset. There is genuine market risk in the daily drift. The attack vector, reconstructed from on-chain data and corroborated by the industry's incident reports, follows a pattern I have seen repeatedly since the first DeFi hacks of 2020. The attacker inflates the price of the collateral asset on a low-liquidity DEX pool, deposits it, borrows the stable-like asset, then lets the price snap back. The difference here is the E-mode multiplier. With standard LTV, a 10% price change triggers liquidation. With E-mode, the buffer shrinks to 2-3%. The attacker didn't need to move the market much. Just enough. Let me get into the technical weeds, because that's where the lesson lives. Based on my own audit experience—I spent three months dissecting Uniswap v2's constant product formula, and later six months on ZK-Rollup math—I've learned that most DeFi attacks are not about clever Solidity tricks. They are about the gap between the developer's mental model and the execution environment. This attack exploits exactly that gap. The price feed for ankrFLOW likely came from a DEX liquidity pool. That pool may have had only a few hundred thousand dollars of liquidity. A flash loan can move the price by 10-20% with negligible slippage. The protocol's oracle contract would read the distorted spot price, see the collateral as being worth more than it was, and allow the borrow. Some protocols use time-weighted average prices to mitigate this. But TWAP doesn't protect you if the manipulation is persistent over multiple blocks. And a sophisticated attacker can simply average out the manipulation across a longer period. The larger failure is the classification itself. E-mode groups assets into "correlated" buckets. The protocol placed ankrFLOW and WFLOW in the same bucket. Why? Because ankrFLOW is a claim on staked FLOW, and WFLOW is a wrapper around FLOW. The underlying is identical. But the wrapped version has direct redeemability to native FLOW, while the LSD has a redemption delay or a blacklist risk. They are not the same asset. They are not even close substitutes in a liquidity crisis. During normal market conditions, their prices might track each other within 1%. In a high-volatility event, the LSD can depeg by 5-10% because redemptions are throttled. That is precisely the event that puts the loan underwater. The exploit sequence, cobbled together from public block explorers and the incident report, likely went like this: the attacker borrowed a large amount of ankrFLOW, sold it in a concentrated pool to push its price up, deposited the now-inflated ankrFLOW into More Markets, used E-mode to borrow WFLOW up to the inflated collateral value, then returned the original loan and kept the WFLOW. The price of ankrFLOW reverted to its fair value, leaving the protocol with bad debt. The attacker didn't need to exit the WFLOW. They just needed the difference. This is not a novel vector. But the scale matters. $9.3 million on a small protocol can wipe out its entire reserve. It also sends a signal to the rest of the industry: any protocol that uses LSDs as collateral with E-mode is a potential target. The question is not if, but when. I have reviewed the code of several such protocols. Most have a similar architecture. Most have the same blind spot. Here is the counter-intuitive part: the attack might have been a net positive for the DeFi ecosystem. Not because theft is good, but because the loss is a data point. It forces the industry to update its priors. The price of a liquid staking derivative is not a simple function of the underlying asset. It's a function of redemption mechanisms, validator risk, and secondary market liquidity. E-mode assumes away those complexities. The attack is nature's way of saying that. We also need to question the protocol's governance. Who set the E-mode parameters? Was there a risk team, or just a developer who copied Aave's configuration file? Aave's E-mode works because the protocol has a trusted oracle infrastructure and a robust risk framework. More Markets did not. Copying the code without copying the risk discipline is like copying a building's blueprint without checking the foundation. The market punishes that. The real injustice is that small retail users will lose funds. They trusted the protocol's "E-mode" feature, assuming it had been stress-tested. It hadn't. The industry's tendency to celebrate innovation without auditing the underlying risk is a systemic failure. We call it "DeFi" but we don't have a "DeFi license" or a "safety inspection". Chaos is just order waiting to be decoded. But we haven't decoded it yet. The takeaway is for builders, not for holders. Modularity is the architecture of freedom. Treat your risk parameters as first-class code. Run adversarial tests against them. Simulate an attacker with infinite capital and a flash loan. If your protocol can't survive a 20% depeg of an LSD, you have no business enabling E-mode on it. Truth is not given, it is verified. Verify your assumptions. Builders' challenge: take the transaction history of the More Markets exploit and write a small Python script that simulates the health factor of a typical over-leveraged position. Test what happens when the LSD's price drops 10%. If the liquidation mechanism cannot protect the protocol, you have found the same bug. Now fix it before your users do. The next bull market will bring more capital, and more sophisticated thieves. Don't be the next More Markets. Logic prevails when emotion fails.

The $9.3 Million Acceptance Test: E-Mode and the False Promise of Correlated Collateral

The $9.3 Million Acceptance Test: E-Mode and the False Promise of Correlated Collateral

Market Prices

Coin Price 24h
BTC Bitcoin
$79,707.4 -1.78%
ETH Ethereum
$2,454.43 -1.60%
SOL Solana
$101.7 -2.33%
BNB BNB Chain
$718.2 -0.48%
XRP XRP Ledger
$1.4 -3.70%
DOGE Dogecoin
$0.0847 -3.27%
ADA Cardano
$0.2108 -4.01%
AVAX Avalanche
$7.35 -2.07%
DOT Polkadot
$0.8710 -1.77%
LINK Chainlink
$11.64 -1.61%

Fear & Greed

74

Greed

Market Sentiment

Event Calendar

{{年份}}
30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

18
03
unlock Sui Token Unlock

Team and early investor shares released

28
03
unlock Arbitrum Token Unlock

92 million ARB released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

12
05
halving BCH Halving

Block reward halving event

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

🧮 Tools

All →

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$79,707.4
1
Ethereum ETH
$2,454.43
1
Solana SOL
$101.7
1
BNB Chain BNB
$718.2
1
XRP Ledger XRP
$1.4
1
Dogecoin DOGE
$0.0847
1
Cardano ADA
$0.2108
1
Avalanche AVAX
$7.35
1
Polkadot DOT
$0.8710
1
Chainlink LINK
$11.64

🐋 Whale Tracker

🟢
0x659d...cd22
30m ago
In
3,642 ETH
🟢
0xfe32...f8bf
1d ago
In
4,533.06 BTC
🔴
0x14a1...1632
12m ago
Out
4,979,008 USDC

💡 Smart Money

0xbad5...1816
Market Maker
+$2.8M
60%
0x931c...9671
Institutional Custody
+$3.6M
76%
0xe507...59f1
Experienced On-chain Trader
+$3.2M
74%