Build with CoinStats’ all-in-one API. Learn more

Deutsch한국어日本語中文EspañolFrançaisՀայերենNederlandsРусскийItalianoPortuguêsTürkçePortfolio TrackerCryptocurrenciesPricingCrypto APIIntegrationsNewsEarnBlogNFTWidgetsDeFi Portfolio TrackerCrypto Gaming24h ReportPress KitAPI Docs
CoinStats

Pando Rings oracle exploiter resurfaces, routes ETH into Tornado Cash

1h ago
bullish:

0

bearish:

0

The wallet associated with the 2022 Pando Rings oracle hack was reactivated on August 18 after two months of inactivity, as reported by blockchain tracker Onchain Lens, The hacker exchanged 3 million DAI for about 1,570 ETH, worth approximately three million dollars, through CoW Protocol.

Approximately 800 ETH worth around 1.52 million are known to have already reached Tornado Cash via eight transactions from this wallet.

Although the action itself may be comparatively minor, the history of the event is anything but. Nearly four years after the incident in which a price feed was manipulated to drain Pando Rings, the fraudster is continuing to move the money, which can still be traced back to the original fraud.

Once a serious cause of losses in DeFi, oracle manipulation has been effectively eliminated from occurring frequently due to improvements in protocol development.

An oracle that misread its own collateral

On November 5, 2022, Pando Rings was hacked. The hacker was able to change the price of sBTC-WBTC liquidity provider token at 4swap, which is Pando’s automated market maker, and used this price manipulation in an attempt to pull out $70 million worth of crypto.

By the time the team took action, around $21.9 million worth of ETH, EOS, and BTC had already flown out of two Mixin wallets controlled by the hacker.

Some assets were not lost. Pando collaborated with Mixin Network and cybersecurity firm SlowMist to lock the rest of the funds. The frozen assets include 2,022,662 EOS coins that were worth approximately $2.36 million, as well as other tokens with a total valuation surpassing $50 million.

The company discontinued its services, namely Pando Rings, 4swap, Pando Leaf, and Pando Lake until the oracle gets fixed and they assured to reimburse all customers.

From buying the dip to reaching for the mixer

The same address has reemerged at intervals since that time. According to a Lookonchain report published on June 6, the same person conducted a transaction worth 10 million DAI to buy a total of 6,243 ETH at an average price of $1,602. It was then added that “even the hacker is buying the $ETH dip.”

The purchase that took place and this week’s swap indicates a well-known strategy: turning stolen stablecoins into Ether when the time is right, and waiting for the best moment to move on. What has changed on August 18 is the final location.

Instead of remaining in possession of the Ether token, the criminal started sending the Ether through Tornado Cash, a service that is used to conceal the connection between deposited and withdrawn funds. As of now the amount of mixer deposits stands at 800 Ether, made in eight transactions.

Why mixed funds stay visible

Even if a person sends money via Tornado Cash, that does not mean the trail will be lost. TRM Labs tracked the attack in June in which a person withdrew around 664 ETH from Tornado Cash and used it to take control of a small Ethereum protocol project known as TOP. This case reveals how mixer operations may still signal risk even if the direct transaction trail is difficult to follow.

The legal standing of Tornado Cash has altered. While being sanctioned by US Treasury in August 2022, it was taken off the sanctions list on March 21, 2025, due to the federal appeals court’s ruling that immutable smart contracts cannot be classified as “property” subject to sanctioning legislation.

Its use as an Ethereum mixer means that big transfers going through the protocol would attract some attention instead of just disappearing.

A protocol winding down as its attacker moves

The timing is interesting. Just three days prior to the wallet’s activity, Pando announced on August 15 that it was discontinuing the protocol and putting its DeFi products into its maintenance mode under the supervision of Mixin. At this point, Pando Rings only serves to support the repayment of loans and the withdrawal of collateral.

In the meantime, incidents like that of Pando are no longer common. Immunefi’s six-year loss analysis found that ecosystem-type attacks, such as flash-loan oracle manipulation, dropped from almost 19% of DeFi loss incidents in 2022 to less than 1% in 2025.

As a result, the Pando exploiter is a remnant of an older time in DeFi security, still profiting from a weakness that the industry as a whole has been able to engineer around while using blockchains.

Broader security angle

The timing of Pando’s Aug. 15 announcement that it was sunsetting the protocol is worth investigating alongside the exploiter’s renewed activity. This isn’t simply an old 2022 hack resurfacing. It illustrates the long tail of DeFi exploits, where stolen assets can remain dormant for years and become active again when market conditions, liquidity, or laundering routes change.

Date Development
Nov. 5, 2022 Pando Rings was exploited. Pando said it halted Pando Rings and other services and worked with SlowMist to trace the stolen funds. (Pando Proto)
June 2026 The linked exploiter wallet resurfaced, swapping $10M DAI for 6,243 ETH. (CryptoBriefing)
~June-Aug. 2026 Wallet subsequently remained relatively dormant.
Aug. 18, 2026 Wallet swapped $3M DAI for ~1,570 ETH, then sent 800 ETH to Tornado Cash. (Blockchain News)
Aug. 15, 2026 Pando announced its protocol sunset and service transition, which is potentially relevant context for the timing.


The transactions illustrate how stolen crypto can remain dormant for extended periods before being converted, consolidated, or moved through privacy infrastructure. That’s a pathway the defenders could well follow through.



The smartest crypto minds already read our newsletter. Want in? Join them.

1h ago
bullish:

0

bearish:

0

Manage all your crypto, NFT and DeFi from one place

Securely connect the portfolio you’re using to start.