Oracle Hacker of Pando Rings Resurfaces and Redirects ETH to Tornado Cash

cryptonews.ruPublicado a 2026-08-18Actualizado a 2026-08-18

Resumen

The wallet associated with the 2022 Pando Rings oracle hack was reactivated on August 18, 2026, after two months of inactivity. The hacker exchanged 3 million DAI for approximately 1,570 ETH (worth ~$3 million) via the CoW Protocol. Subsequently, about 800 ETH (worth ~$1.52 million) was deposited into the Tornado Cash mixer through eight transactions. This event revisits the November 2022 hack, where the attacker manipulated the price of a liquidity token on Pando's 4swap AMM, initially attempting to steal around $70 million. While $21.9 million was withdrawn, Pando, with Mixin Network and SlowMist, froze remaining assets valued over $50 million. The hacker has been periodically active since, including a major purchase of 6,243 ETH for 10 million DAI in June 2026. The recent conversion of stolen stablecoins to ETH and subsequent movement to Tornado Cash follows a known strategy of timing the market and laundering funds. The reactivation coincided with Pando's announcement on August 15, 2026, to sunset its protocol and transition services to maintenance mode. The case underscores how stolen crypto assets can lie dormant for years before being moved through privacy infrastructure. While oracle manipulation attacks have significantly declined in DeFi since 2022, this incident represents a legacy exploit from an earlier security era.

A wallet linked to the 2022 Pando Rings oracle hack was reactivated on August 18 after two months of inactivity, as reported by on-chain analytics provider Onchain Lens. The hacker swapped 3 million $DAI for approximately 1,570 $ETH, worth around three million dollars, via the CoW Protocol. It is known that about 800 $ETH, roughly 1.52 million dollars, has already been deposited into Tornado Cash from this wallet in eight transactions.

While the action itself may seem relatively minor, the history of this event is anything but. Nearly four years after the hack, which involved manipulating price data to drain Pando Rings, the perpetrator is still moving funds that can be traced back to the original exploit.

You can track this hacker at: https://t.co/BzkSa9GenR

— Onchain Lens (@OnchainLens) August 18, 2026

Oracle manipulation, once a major source of losses in DeFi, has been effectively eliminated from common occurrences thanks to improvements in protocol design.

The Oracle That Misinterpreted Its Own Collateral

On November 5, 2022, Pando Rings was hacked. The hacker managed to alter the price of the sBTC-WBTC liquidity token on Pando's automated market maker, 4swap, and used this price manipulation in an attempt to withdraw $70 million worth of cryptocurrency.

By the time the team took action, approximately $21.9 million worth of $ETH, EOS, and BTC had already been withdrawn from two Mixin wallets controlled by the hacker.

Not all assets were lost. Pando, in collaboration with Mixin Network and cybersecurity firm SlowMist, froze the remaining funds. The frozen assets include 2,022,662 EOS coins, valued at approximately $2.36 million, as well as other tokens with a total value exceeding $50 million.

The company suspended its services—namely Pando Rings, 4swap, Pando Leaf, and Pando Lake—until the oracle bug was fixed and assured it would compensate all affected clients.

From Buying the Dip to Using a Mixer

The same address has periodically resurfaced since then. According to a report by Lookonchain published on June 6, the same individual spent 10 million $DAI to buy a total of 6,243 $ETH at an average price of $1,602. The report added that "even a hacker is buying the $ETH dip."

The purchase and swap made this week point to a well-known strategy: converting stolen stablecoins into Ethereum at an opportune moment and waiting for the best time for further moves. Only the final destination changed on August 18.

Instead of holding onto the Ether, the criminal began sending it through Tornado Cash—a service used to obscure the link between deposited and withdrawn funds. So far, deposits through the mixer amount to 800 ETH, made in eight transactions.

Why Mixed Funds Remain Visible

Even if someone sends money through Tornado Cash, it doesn't mean the trail is lost. TRM Labs traced an attack in June where someone withdrew about 664 $ETH from Tornado Cash and used them to seize control of a small Ethereum project known as TOP. This case shows how mixer operations can signal risk even if the direct transaction trail is difficult to follow.

The legal status of Tornado Cash has changed. While it was under U.S. Treasury sanctions in August 2022, on March 21, 2025, it was delisted from the sanctions list following a federal appeals court ruling that immutable smart contracts cannot be classified as "property" subject to sanctions law.

Using the protocol as an Ethereum mixer means that large transfers moving through it attract attention rather than simply disappearing.

Protocol Winds Down as Its Attacker Moves

The timing is notable. Just three days before the wallet's activity, on August 15, Pando announced the sunsetting of its protocol and the transition of its DeFi products to a maintenance-only mode under Mixin's management. As of now, Pando Rings only supports loan repayments and collateral withdrawals.

Meanwhile, incidents like the Pando hack are no longer common. An analysis of losses by Immunefi over six years showed that attack types like oracle manipulation lending protocol exploits decreased from nearly 19% of DeFi loss incidents in 2022 to less than 1% in 2025.

As a result, the Pando exploiter is a relic of an older era in DeFi security, still profiting from a vulnerability the industry at large has largely managed to circumvent using blockchains.

The Broader Security Perspective

The timing of Pando's August 15 announcement about ending protocol support is noteworthy, as is the resumption of the attacker's activity. This is not merely a resurfacing of an old 2022 hack. It illustrates the long-term persistence of DeFi exploiters, where stolen assets can remain dormant for years and reactivate when market conditions, liquidity, or money laundering pathways change.

Date Development
November 5, 2022 Pando Rings service was hacked. Pando announced halting Pando Rings and other services and collaborated with SlowMist to trace stolen funds. (Pando Proto)
June 2026 The identified exploiter resurfaced, swapping 10 million $DAI for 6,243 $ETH. (CryptoBriefing)
~June-August 2026 The wallet remained relatively inactive afterward.
August 18, 2026 The wallet swapped 3 million $DAI for ~1,570 $ETH and then sent 800 $ETH to Tornado Cash. (Blockchain News)
August 15, 2026 Pando announced the end of support for its protocol and migration to a new service, which could be important context for timing.


These transactions demonstrate how stolen cryptocurrency can remain dormant for extended periods before being converted, aggregated, or moved through privacy-enhancing infrastructure. This is a path that defenders are likely to follow.



end-content

Preguntas relacionadas

QWhat key action did the hacker associated with the 2022 Pando Rings oracle exploit take on August 18th, 2026, according to the article?

AOn August 18th, 2026, the hacker swapped 3 million DAI for approximately 1,570 ETH via the CoW protocol and subsequently funneled about 800 ETH (worth roughly $1.52 million) into the Tornado Cash mixer through eight transactions.

QWhat was the primary method used in the initial Pando Rings hack back in November 2022?

AThe initial hack exploited an oracle vulnerability by manipulating the price of the sBTC-WBTC liquidity token on Pando's 4swap automated market maker, allowing the attacker to attempt to drain approximately $70 million in cryptocurrency.

QHow has the legal status of Tornado Cash changed between 2022 and 2025 as mentioned in the article?

ATornado Cash was under U.S. Treasury Department sanctions in August 2022. However, on March 21, 2025, it was removed from the sanctions list following a federal appeals court decision that immutable smart contracts could not be classified as 'property' subject to sanctions law.

QWhat broader trend in DeFi security does the article illustrate through the timeline of the Pando Rings exploit?

AThe article illustrates the long-term trend where stolen assets from DeFi exploits can remain dormant for years and be reactivated later when market conditions, liquidity, or money laundering pathways change, highlighting persistent risks even after initial incidents.

QWhat significant event occurred just three days before the hacker's reactivation on August 18th, 2026, regarding the Pando protocol?

AOn August 15th, 2026, Pando announced it was sunsetting its protocol and placing its DeFi products under maintenance mode managed by Mixin, with Pando Rings serving only to support loan repayments and collateral withdrawals.

Lecturas Relacionadas

Uniswap Founder: Why AMM Could Become the Core Engine of Financial Markets

In this article, Uniswap founder Hayden Adams argues that Automated Market Makers (AMMs) have the potential to become the core engine of future financial markets, drawing parallels to the disruptive rise of index funds 50 years ago. He posits that asset tokenization is more than just an infrastructure upgrade; it enables programmable markets and changes who can provide liquidity. AMMs like Uniswap have already found product-market fit in long-tail crypto assets and stablecoin pairs, where passive strategies can outcompete traditional market makers due to lower capital costs. The traditional market-making model is vertically integrated, creating high barriers to entry. Blockchain technology dismantles this by decoupling execution, custody, and settlement into competitive, open layers. In this new landscape, capital is the scarcest resource, and advantage goes to those with the lowest cost of holding assets—such as asset issuers or long-term holders who naturally have exposure. A key emerging pattern is "correlated pairs" (e.g., an asset trading against a related index like SPY instead of USD). When two assets are correlated, passive AMM strategies perform much closer to active ones, and liquidity providers bear less risk. This structure naturally organizes markets for efficiency, with passive AMMs dominating correlated pairs and active players competing on the fewer, high-volatility "bridging pairs" (like SPY/USD). Early examples already exist, such as tokenized stocks trading directly against SPY on Uniswap. Adams concludes that, much like passive index funds eventually outperformed most active managers, passive liquidity provision via AMMs is on a path to win by dramatically lowering the cost and complexity of creating and accessing markets.

marsbitHace 12 min(s)

Uniswap Founder: Why AMM Could Become the Core Engine of Financial Markets

marsbitHace 12 min(s)

Trading

Spot
活动图片