Oracle Hacker of Pando Rings Resurfaces and Redirects ETH to Tornado Cash

cryptonews.ruPublished on 2026-08-18Last updated on 2026-08-18

Abstract

The wallet associated with the 2022 Pando Rings oracle hack was reactivated on August 18, 2026, after two months of inactivity. The hacker exchanged 3 million DAI for approximately 1,570 ETH (worth ~$3 million) via the CoW Protocol. Subsequently, about 800 ETH (worth ~$1.52 million) was deposited into the Tornado Cash mixer through eight transactions. This event revisits the November 2022 hack, where the attacker manipulated the price of a liquidity token on Pando's 4swap AMM, initially attempting to steal around $70 million. While $21.9 million was withdrawn, Pando, with Mixin Network and SlowMist, froze remaining assets valued over $50 million. The hacker has been periodically active since, including a major purchase of 6,243 ETH for 10 million DAI in June 2026. The recent conversion of stolen stablecoins to ETH and subsequent movement to Tornado Cash follows a known strategy of timing the market and laundering funds. The reactivation coincided with Pando's announcement on August 15, 2026, to sunset its protocol and transition services to maintenance mode. The case underscores how stolen crypto assets can lie dormant for years before being moved through privacy infrastructure. While oracle manipulation attacks have significantly declined in DeFi since 2022, this incident represents a legacy exploit from an earlier security era.

A wallet linked to the 2022 Pando Rings oracle hack was reactivated on August 18 after two months of inactivity, as reported by on-chain analytics provider Onchain Lens. The hacker swapped 3 million $DAI for approximately 1,570 $ETH, worth around three million dollars, via the CoW Protocol. It is known that about 800 $ETH, roughly 1.52 million dollars, has already been deposited into Tornado Cash from this wallet in eight transactions.

While the action itself may seem relatively minor, the history of this event is anything but. Nearly four years after the hack, which involved manipulating price data to drain Pando Rings, the perpetrator is still moving funds that can be traced back to the original exploit.

You can track this hacker at: https://t.co/BzkSa9GenR

— Onchain Lens (@OnchainLens) August 18, 2026

Oracle manipulation, once a major source of losses in DeFi, has been effectively eliminated from common occurrences thanks to improvements in protocol design.

The Oracle That Misinterpreted Its Own Collateral

On November 5, 2022, Pando Rings was hacked. The hacker managed to alter the price of the sBTC-WBTC liquidity token on Pando's automated market maker, 4swap, and used this price manipulation in an attempt to withdraw $70 million worth of cryptocurrency.

By the time the team took action, approximately $21.9 million worth of $ETH, EOS, and BTC had already been withdrawn from two Mixin wallets controlled by the hacker.

Not all assets were lost. Pando, in collaboration with Mixin Network and cybersecurity firm SlowMist, froze the remaining funds. The frozen assets include 2,022,662 EOS coins, valued at approximately $2.36 million, as well as other tokens with a total value exceeding $50 million.

The company suspended its services—namely Pando Rings, 4swap, Pando Leaf, and Pando Lake—until the oracle bug was fixed and assured it would compensate all affected clients.

From Buying the Dip to Using a Mixer

The same address has periodically resurfaced since then. According to a report by Lookonchain published on June 6, the same individual spent 10 million $DAI to buy a total of 6,243 $ETH at an average price of $1,602. The report added that "even a hacker is buying the $ETH dip."

The purchase and swap made this week point to a well-known strategy: converting stolen stablecoins into Ethereum at an opportune moment and waiting for the best time for further moves. Only the final destination changed on August 18.

Instead of holding onto the Ether, the criminal began sending it through Tornado Cash—a service used to obscure the link between deposited and withdrawn funds. So far, deposits through the mixer amount to 800 ETH, made in eight transactions.

Why Mixed Funds Remain Visible

Even if someone sends money through Tornado Cash, it doesn't mean the trail is lost. TRM Labs traced an attack in June where someone withdrew about 664 $ETH from Tornado Cash and used them to seize control of a small Ethereum project known as TOP. This case shows how mixer operations can signal risk even if the direct transaction trail is difficult to follow.

The legal status of Tornado Cash has changed. While it was under U.S. Treasury sanctions in August 2022, on March 21, 2025, it was delisted from the sanctions list following a federal appeals court ruling that immutable smart contracts cannot be classified as "property" subject to sanctions law.

Using the protocol as an Ethereum mixer means that large transfers moving through it attract attention rather than simply disappearing.

Protocol Winds Down as Its Attacker Moves

The timing is notable. Just three days before the wallet's activity, on August 15, Pando announced the sunsetting of its protocol and the transition of its DeFi products to a maintenance-only mode under Mixin's management. As of now, Pando Rings only supports loan repayments and collateral withdrawals.

Meanwhile, incidents like the Pando hack are no longer common. An analysis of losses by Immunefi over six years showed that attack types like oracle manipulation lending protocol exploits decreased from nearly 19% of DeFi loss incidents in 2022 to less than 1% in 2025.

As a result, the Pando exploiter is a relic of an older era in DeFi security, still profiting from a vulnerability the industry at large has largely managed to circumvent using blockchains.

The Broader Security Perspective

The timing of Pando's August 15 announcement about ending protocol support is noteworthy, as is the resumption of the attacker's activity. This is not merely a resurfacing of an old 2022 hack. It illustrates the long-term persistence of DeFi exploiters, where stolen assets can remain dormant for years and reactivate when market conditions, liquidity, or money laundering pathways change.

Date Development
November 5, 2022 Pando Rings service was hacked. Pando announced halting Pando Rings and other services and collaborated with SlowMist to trace stolen funds. (Pando Proto)
June 2026 The identified exploiter resurfaced, swapping 10 million $DAI for 6,243 $ETH. (CryptoBriefing)
~June-August 2026 The wallet remained relatively inactive afterward.
August 18, 2026 The wallet swapped 3 million $DAI for ~1,570 $ETH and then sent 800 $ETH to Tornado Cash. (Blockchain News)
August 15, 2026 Pando announced the end of support for its protocol and migration to a new service, which could be important context for timing.


These transactions demonstrate how stolen cryptocurrency can remain dormant for extended periods before being converted, aggregated, or moved through privacy-enhancing infrastructure. This is a path that defenders are likely to follow.



end-content

Related Questions

QWhat key action did the hacker associated with the 2022 Pando Rings oracle exploit take on August 18th, 2026, according to the article?

AOn August 18th, 2026, the hacker swapped 3 million DAI for approximately 1,570 ETH via the CoW protocol and subsequently funneled about 800 ETH (worth roughly $1.52 million) into the Tornado Cash mixer through eight transactions.

QWhat was the primary method used in the initial Pando Rings hack back in November 2022?

AThe initial hack exploited an oracle vulnerability by manipulating the price of the sBTC-WBTC liquidity token on Pando's 4swap automated market maker, allowing the attacker to attempt to drain approximately $70 million in cryptocurrency.

QHow has the legal status of Tornado Cash changed between 2022 and 2025 as mentioned in the article?

ATornado Cash was under U.S. Treasury Department sanctions in August 2022. However, on March 21, 2025, it was removed from the sanctions list following a federal appeals court decision that immutable smart contracts could not be classified as 'property' subject to sanctions law.

QWhat broader trend in DeFi security does the article illustrate through the timeline of the Pando Rings exploit?

AThe article illustrates the long-term trend where stolen assets from DeFi exploits can remain dormant for years and be reactivated later when market conditions, liquidity, or money laundering pathways change, highlighting persistent risks even after initial incidents.

QWhat significant event occurred just three days before the hacker's reactivation on August 18th, 2026, regarding the Pando protocol?

AOn August 15th, 2026, Pando announced it was sunsetting its protocol and placing its DeFi products under maintenance mode managed by Mixin, with Pando Rings serving only to support loan repayments and collateral withdrawals.

Related Reads

Refuting the Theory of Ethereum "Abandoning" ETH: What Does It Really Mean to Pay Gas Without Using ETH?

The article refutes the notion that Ethereum's proposed EIP-8141 (Frame Transactions) "abandons" ETH, explaining what "paying gas without ETH" truly means. It clarifies that the proposal doesn't eliminate ETH as the base-layer gas fee; instead, it decouples transaction signing, gas payment, and execution. Users could sign a transaction (e.g., sending USDC) while a Paymaster or another account pays the ETH-denominated gas fee on their behalf, later settling with the user in a different asset like USDC. This abstracts gas complexities away from end-users, similar to using a credit card abroad without handling foreign currency. The core goal is to improve UX by removing the significant barrier where new users must first acquire ETH to perform any on-chain action. While ERC-4337 already enables similar functionality, EIP-8141 aims to integrate it more natively into Ethereum's transaction structure. The article argues this shift doesn't inherently make ETH more bullish or bearish. ETH demand doesn't disappear; it shifts from being held by millions of individual users to being managed in larger pools by Paymasters and service providers. The key determinant for ETH's value is whether the improved user experience generates substantial new on-chain activity and transaction volume, thereby increasing overall network usage and ETH burned. If it brings more users who complete more transactions, net ETH consumption could rise despite users not holding it directly.

marsbit7m ago

Refuting the Theory of Ethereum "Abandoning" ETH: What Does It Really Mean to Pay Gas Without Using ETH?

marsbit7m ago

Only 14% of Russian Universities and Research Institutions Have Approved Rules for Using AI

Only 14% of Russian universities and scientific research institutes have officially approved internal regulations governing the use of artificial intelligence (AI), according to a survey conducted in May-June 2026 by HSE's Institute for Statistical Studies and Economics of Knowledge. The study involved 424 organizations, including 250 universities and 174 research institutes. It found that 72% of these institutions have no such regulations at all, while the remaining 14% did not provide an answer. This absence of formal rules exists despite the widespread practical use of AI in education. The survey highlights a significant gap between the rapid adoption of AI technologies and the slower pace of internal policy development within academia. In contrast, Russia is actively expanding the application of AI in school education. Since September 2026, a professional development program titled "Artificial Intelligence in the Teacher's Work" has been available, aiming to train 250,000 teachers on using neural networks for preparing lessons and assignments by the end of the year. A dedicated "Artificial Intelligence" track for schoolchildren has also been introduced. Thus, two parallel processes are unfolding: the state is promoting AI training for teachers and students, while higher education and research institutions largely lack unified internal guidelines for its use. The analysis suggests this regulatory lag is typical for new technologies, akin to the early adoption of email and the internet. In practice, students and educators are already utilizing AI tools, such as chatbots for routine tasks and exam preparation, regardless of official institutional policies. The key question remains whether future standards will be set by the educational institutions themselves or by the developers of the AI tools already integrated into the learning process.

cryptonews.ru25m ago

Only 14% of Russian Universities and Research Institutions Have Approved Rules for Using AI

cryptonews.ru25m ago

Trading

Spot
活动图片