The wallet associated with the 2022 Pando Rings oracle hack was reactivated on August 18 after two months of inactivity, as reported by blockchain tracker Onchain Lens, The hacker exchanged 3 million DAI for about 1,570 ETH, worth approximately three million dollars, through CoW Protocol.
Approximately 800 ETH worth around 1.52 million are known to have already reached Tornado Cash via eight transactions from this wallet.
Although the action itself may be comparatively minor, the history of the event is anything but. Nearly four years after the incident in which a price feed was manipulated to drain Pando Rings, the fraudster is continuing to move the money, which can still be traced back to the original fraud.
Once a serious cause of losses in DeFi, oracle manipulation has been effectively eliminated from occurring frequently due to improvements in protocol development.
On November 5, 2022, Pando Rings was hacked. The hacker was able to change the price of sBTC-WBTC liquidity provider token at 4swap, which is Pando’s automated market maker, and used this price manipulation in an attempt to pull out $70 million worth of crypto.
By the time the team took action, around $21.9 million worth of ETH, EOS, and BTC had already flown out of two Mixin wallets controlled by the hacker.
Some assets were not lost. Pando collaborated with Mixin Network and cybersecurity firm SlowMist to lock the rest of the funds. The frozen assets include 2,022,662 EOS coins that were worth approximately $2.36 million, as well as other tokens with a total valuation surpassing $50 million.
The company discontinued its services, namely Pando Rings, 4swap, Pando Leaf, and Pando Lake until the oracle gets fixed and they assured to reimburse all customers.
The same address has reemerged at intervals since that time. According to a Lookonchain report published on June 6, the same person conducted a transaction worth 10 million DAI to buy a total of 6,243 ETH at an average price of $1,602. It was then added that “even the hacker is buying the $ETH dip.”
The purchase that took place and this week’s swap indicates a well-known strategy: turning stolen stablecoins into Ether when the time is right, and waiting for the best moment to move on. What has changed on August 18 is the final location.
Instead of remaining in possession of the Ether token, the criminal started sending the Ether through Tornado Cash, a service that is used to conceal the connection between deposited and withdrawn funds. As of now the amount of mixer deposits stands at 800 Ether, made in eight transactions.
Even if a person sends money via Tornado Cash, that does not mean the trail will be lost. TRM Labs tracked the attack in June in which a person withdrew around 664 ETH from Tornado Cash and used it to take control of a small Ethereum protocol project known as TOP. This case reveals how mixer operations may still signal risk even if the direct transaction trail is difficult to follow.
The legal standing of Tornado Cash has altered. While being sanctioned by US Treasury in August 2022, it was taken off the sanctions list on March 21, 2025, due to the federal appeals court’s ruling that immutable smart contracts cannot be classified as “property” subject to sanctioning legislation.
Its use as an Ethereum mixer means that big transfers going through the protocol would attract some attention instead of just disappearing.
The timing is interesting. Just three days prior to the wallet’s activity, Pando announced on August 15 that it was discontinuing the protocol and putting its DeFi products into its maintenance mode under the supervision of Mixin. At this point, Pando Rings only serves to support the repayment of loans and the withdrawal of collateral.
In the meantime, incidents like that of Pando are no longer common. Immunefi’s six-year loss analysis found that ecosystem-type attacks, such as flash-loan oracle manipulation, dropped from almost 19% of DeFi loss incidents in 2022 to less than 1% in 2025.
As a result, the Pando exploiter is a remnant of an older time in DeFi security, still profiting from a weakness that the industry as a whole has been able to engineer around while using blockchains.
The timing of Pando’s Aug. 15 announcement that it was sunsetting the protocol is worth investigating alongside the exploiter’s renewed activity. This isn’t simply an old 2022 hack resurfacing. It illustrates the long tail of DeFi exploits, where stolen assets can remain dormant for years and become active again when market conditions, liquidity, or laundering routes change.
| Date | Development |
|---|---|
| Nov. 5, 2022 | Pando Rings was exploited. Pando said it halted Pando Rings and other services and worked with SlowMist to trace the stolen funds. (Pando Proto) |
| June 2026 | The linked exploiter wallet resurfaced, swapping $10M DAI for 6,243 ETH. (CryptoBriefing) |
| ~June-Aug. 2026 | Wallet subsequently remained relatively dormant. |
| Aug. 18, 2026 | Wallet swapped $3M DAI for ~1,570 ETH, then sent 800 ETH to Tornado Cash. (Blockchain News) |
| Aug. 15, 2026 | Pando announced its protocol sunset and service transition, which is potentially relevant context for the timing. |
The transactions illustrate how stolen crypto can remain dormant for extended periods before being converted, consolidated, or moved through privacy infrastructure. That’s a pathway the defenders could well follow through.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.