EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Pando Rings oracle attacker appears again and transfers ETH to Tornado Cash

2026-08-18 12:49:17
Bookmark

The wallet associated with the 2022 Pando Rings oracle attack was reactivated on August 18 after two months of silence. Hackers exchanged 3 million DAIs for approximately 1570 ETH pieces through CoW Protocol, worth approximately US$3 million. About 800 ETH (worth approximately $1.52 million) are known to have flowed into Tornado Cash through eight transactions in the wallet.

Although the operation itself was relatively small, the historical background of the incident was extraordinary. After an attack nearly four years ago that used a price oracle to manipulate the theft of Pando Rings funds, the fraudster continues to move funds that can still be traced back to the original fraud.

Oracle manipulation was once a major cause of loss in the DeFi field, but due to improvements in protocol development, such incidents no longer occur frequently.

A prophet that misreads its own collateral

On November 5, 2022, Pando Rings was attacked. The hackers successfully tampered with the price of the sBTC-WBTC liquidity provider token on Pando automated market maker 4swap and used this price manipulation to attempt to extract $70 million worth of crypto assets. By the time the team took action, approximately $21.9 million worth of ETH, EOS and BTC had flowed out of two Mixin wallets controlled by the hackers.

Some assets were not lost. Pando teamed up with Mixin Network and cybersecurity company SlowMist to lock in the rest of the money. The frozen assets include 2,022,662 EOS (valued at approximately US$2.36 million) and other tokens with a total valuation of more than US$50 million.

The company suspended services such as Pando Rings, 4swap, Pando Leaf and Pando Lake until the oracle is repaired and promised to compensate all customers.

From bottom reading to currency mixer

Since then, the same address has appeared intermittently many times. According to a report released June 6, the same person conducted a deal to purchase a total of 6243 ETH units with 10 million DAIs at an average price of $1602. The report also mentioned that "even hackers are copying ETH."

This purchase and this week's redemption show a common strategy: convert stolen stablecoins to ether at the right time, and then wait for the best time to transfer them. The change on August 18 lies in the final destination.

Criminals no longer hold ether, but are starting to send it through Tornado Cash-a service used to hide the connection between deposits and withdrawals of funds. As of now, the total deposit in the currency mixer is 800 Ethereum, completed in eight transactions.

Why funds can still be traced after mixed coins

Even if someone sends funds through Tornado Cash, it doesn't mean that the clues will disappear. In June this year, TRM Labs traced an attack in which someone extracted approximately 664 ETH from Tornado Cash and used it to control a small Ethereum protocol project called TOP. This case shows that even if direct trading clues are difficult to track, currency mixer operations may still expose risks.

The legal status of Tornado Cash has changed. Although sanctioned by the U.S. Treasury Department in August 2022, the service was removed from the sanctions list on March 21, 2025 after a federal appeals court ruled that immutable smart contracts could not be classified as "property" subject to sanctions legislation. Its use as an Ethereum mixer means that large transfers made through the protocol attract attention rather than disappear quietly.

The protocol is gradually shutting down, but attackers are transferring funds.

The timing is quite subtle. Just three days before the wallet event, Pando announced on August 15 that it would stop operating the protocol and place its DeFi products in maintenance mode under Mixin supervision. Currently, Pando Rings is only used to support loan repayments and collateral withdrawals.

At the same time, incidents like Pando are no longer common. Immunefi's six-year loss analysis found that the proportion of ecosystem-based attacks such as Lightning Oracle manipulation in DeFi losses has dropped from nearly 19% in 2022 to less than 1% in 2025. As a result, the attackers of the Pando incident have become remnants of the old era of DeFi security and are still profiting from vulnerabilities that the entire industry has been circumvented through blockchain technology.

Broader security perspective

The timing of Pando's announcement on August 15 that the agreement was suspended is worth reviewing together with signs of attacker reactivation. This is not a simple re-emergence of the old 2022 attack, but a demonstration of the long-term impact of the DeFi attack: stolen assets can remain dormant for years and become active again when market conditions, liquidity or money laundering channels change.

Timeline

November 5, 2022: Pando Rings was attacked. Pando said it has suspended Pando Rings and other services and is working with SlowMist to track stolen funds.

June 2026: Associated attacker wallets reappear, exchanging 10 million DAIs for 6243 ETH.

June to August 2026: The wallet then remains relatively silent.

August 18, 2026: The wallet exchanged 3 million DAIs for approximately 1570 ETH, and then sent 800 ETH to Tornado Cash.

August 15, 2026: Pando announced the suspension of the agreement and service transition, a time point that may be related to the timing of the attacker's actions.

These transactions suggest that stolen cryptocurrencies may remain dormant for long periods of time before being converted, integrated, or transferred through privacy infrastructure. This is a path worth pursuing by defenders.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP