A wallet linked to the 2022 Pando Rings oracle hack was reactivated on August 18 after two months of inactivity, as reported by on-chain analytics provider Onchain Lens. The hacker swapped 3 million $DAI for approximately 1,570 $ETH, worth around three million dollars, via the CoW Protocol. It is known that about 800 $ETH, roughly 1.52 million dollars, has already been deposited into Tornado Cash from this wallet in eight transactions.
While the action itself may seem relatively minor, the history of this event is anything but. Nearly four years after the hack, which involved manipulating price data to drain Pando Rings, the perpetrator is still moving funds that can be traced back to the original exploit.
You can track this hacker at: https://t.co/BzkSa9GenR
— Onchain Lens (@OnchainLens) August 18, 2026
Oracle manipulation, once a major source of losses in DeFi, has been effectively eliminated from common occurrences thanks to improvements in protocol design.
The Oracle That Misinterpreted Its Own Collateral
On November 5, 2022, Pando Rings was hacked. The hacker managed to alter the price of the sBTC-WBTC liquidity token on Pando's automated market maker, 4swap, and used this price manipulation in an attempt to withdraw $70 million worth of cryptocurrency.
By the time the team took action, approximately $21.9 million worth of $ETH, EOS, and BTC had already been withdrawn from two Mixin wallets controlled by the hacker.
Not all assets were lost. Pando, in collaboration with Mixin Network and cybersecurity firm SlowMist, froze the remaining funds. The frozen assets include 2,022,662 EOS coins, valued at approximately $2.36 million, as well as other tokens with a total value exceeding $50 million.
The company suspended its services—namely Pando Rings, 4swap, Pando Leaf, and Pando Lake—until the oracle bug was fixed and assured it would compensate all affected clients.
From Buying the Dip to Using a Mixer
The same address has periodically resurfaced since then. According to a report by Lookonchain published on June 6, the same individual spent 10 million $DAI to buy a total of 6,243 $ETH at an average price of $1,602. The report added that "even a hacker is buying the $ETH dip."
The purchase and swap made this week point to a well-known strategy: converting stolen stablecoins into Ethereum at an opportune moment and waiting for the best time for further moves. Only the final destination changed on August 18.
Instead of holding onto the Ether, the criminal began sending it through Tornado Cash—a service used to obscure the link between deposited and withdrawn funds. So far, deposits through the mixer amount to 800 ETH, made in eight transactions.
Why Mixed Funds Remain Visible
Even if someone sends money through Tornado Cash, it doesn't mean the trail is lost. TRM Labs traced an attack in June where someone withdrew about 664 $ETH from Tornado Cash and used them to seize control of a small Ethereum project known as TOP. This case shows how mixer operations can signal risk even if the direct transaction trail is difficult to follow.
The legal status of Tornado Cash has changed. While it was under U.S. Treasury sanctions in August 2022, on March 21, 2025, it was delisted from the sanctions list following a federal appeals court ruling that immutable smart contracts cannot be classified as "property" subject to sanctions law.
Using the protocol as an Ethereum mixer means that large transfers moving through it attract attention rather than simply disappearing.
Protocol Winds Down as Its Attacker Moves
The timing is notable. Just three days before the wallet's activity, on August 15, Pando announced the sunsetting of its protocol and the transition of its DeFi products to a maintenance-only mode under Mixin's management. As of now, Pando Rings only supports loan repayments and collateral withdrawals.
Meanwhile, incidents like the Pando hack are no longer common. An analysis of losses by Immunefi over six years showed that attack types like oracle manipulation lending protocol exploits decreased from nearly 19% of DeFi loss incidents in 2022 to less than 1% in 2025.
As a result, the Pando exploiter is a relic of an older era in DeFi security, still profiting from a vulnerability the industry at large has largely managed to circumvent using blockchains.
The Broader Security Perspective
The timing of Pando's August 15 announcement about ending protocol support is noteworthy, as is the resumption of the attacker's activity. This is not merely a resurfacing of an old 2022 hack. It illustrates the long-term persistence of DeFi exploiters, where stolen assets can remain dormant for years and reactivate when market conditions, liquidity, or money laundering pathways change.
| Date | Development |
|---|---|
| November 5, 2022 | Pando Rings service was hacked. Pando announced halting Pando Rings and other services and collaborated with SlowMist to trace stolen funds. (Pando Proto) |
| June 2026 | The identified exploiter resurfaced, swapping 10 million $DAI for 6,243 $ETH. (CryptoBriefing) |
| ~June-August 2026 | The wallet remained relatively inactive afterward. |
| August 18, 2026 | The wallet swapped 3 million $DAI for ~1,570 $ETH and then sent 800 $ETH to Tornado Cash. (Blockchain News) |
| August 15, 2026 | Pando announced the end of support for its protocol and migration to a new service, which could be important context for timing. |
These transactions demonstrate how stolen cryptocurrency can remain dormant for extended periods before being converted, aggregated, or moved through privacy-enhancing infrastructure. This is a path that defenders are likely to follow.





