Invest1 distinct publisher3 min readUpdated
The Pando Rings exploiter swapped 3 million DAI for about 1,570 ETH on CoW Protocol, then pushed 800 ETH into Tornado Cash as the protocol entered maintenance mode.
The Investor · Invest desk
Compiled by The InvestorSomething wrong?How this is made
A wallet tied to the November 2022 Pando Rings oracle exploit came back to life on August 18 after two months of inactivity, swapping 3 million DAI for roughly 1,570 ETH through CoW Protocol, according to blockchain tracker Onchain Lens [1][2]. Roughly 800 ETH, worth about $1.52 million, then went into Tornado Cash across eight transactions [3]. That matters mostly for its timing: three days earlier, on August 15, Pando announced it was discontinuing the protocol and moving its DeFi products into maintenance mode under Mixin's supervision, with Pando Rings now serving only loan repayment and collateral withdrawal [4].
The mechanics of the original loss are worth restating because they are the kind of thing that gets filed away as solved. On November 5, 2022, an attacker manipulated the price of the sBTC-WBTC liquidity provider token on 4swap, Pando's automated market maker, and used that mispricing in an attempt to drain $70 million [5]. About $21.9 million in ETH, EOS and BTC left two Mixin wallets the attacker controlled before the team intervened [6], which is roughly 31 percent of the attempted haul [7]. Pando then worked with Mixin Network and SlowMist to lock the remainder, including 2,022,662 EOS worth about $2.36 million and other tokens valued at more than $50 million [8]. Pando Rings, 4swap, Pando Leaf and Pando Lake were suspended pending an oracle fix, with a commitment to reimburse users [9]. The publisher notes that oracle manipulation of this kind has become far less frequent as protocol development improved [10].
The wallet has not been idle in the interim, and it has not been behaving like a panicked launderer. Lookonchain reported on June 6 that the same address spent 10 million DAI on 6,243 ETH at an average price of $1,602 [11]. Add the August swap and that is 13 million DAI converted into ether across two visible tranches [12]. The August trade implies a price near $1,911 per ETH [13], which would put the June stack roughly $1.9 million above cost [14]. The change in behaviour is the destination, not the trading.
Mixing is not disappearance. TRM Labs tracked a June incident in which about 664 ETH withdrawn from Tornado Cash was used to take control of a small Ethereum project called TOP [15], which is the point: mixer flows still function as a risk signal even when the direct trail breaks. Tornado Cash's own legal position has moved as well. It was sanctioned by the US Treasury in August 2022 and removed from the sanctions list on March 21, 2025, after a federal appeals court held that immutable smart contracts are not "property" subject to sanctions law [16].
Two things to watch. First, the roughly 770 ETH from the August swap that has not yet reached the mixer [17], which will show whether this is a full exit or another partial rotation. Second, Pando's reimbursement pledge [9] against a protocol now in maintenance mode [4] and more than $50 million in frozen assets [8]: winding down the front end does not close the recovery question, and the counterparty on the other side of it is still trading.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The wallet associated with the 2022 Pando Rings oracle hack was reactivated on August 18 after two months of inactivity, as reported by blockchain tracker Onchain Lens.
The wallet exchanged 3 million DAI for about 1,570 ETH, worth approximately $3 million, through CoW Protocol.
Roughly 800 ETH worth about $1.52 million was sent to Tornado Cash across eight transactions from the same wallet.
Pando announced on August 15 that it was discontinuing the protocol and putting its DeFi products into maintenance mode under Mixin's supervision; Pando Rings now only supports repayment of loans and withdrawal of collateral.
On November 5, 2022, an attacker changed the price of the sBTC-WBTC liquidity provider token on 4swap, Pando's automated market maker, and used that manipulation in an attempt to pull out $70 million worth of crypto.
By the time the Pando team acted, around $21.9 million worth of ETH, EOS and BTC had left two Mixin wallets controlled by the hacker.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single outlet relaying trackers, no primary artifacts
Every claim rests on one publisher. The core on-chain facts are attributed to named trackers (Onchain Lens, Lookonchain) and firms (TRM Labs, SlowMist, Immunefi) plus Pando's own 2022 alert, which is better than unsourced assertion, but no wallet addresses, transaction hashes, report links or Pando statements are reproduced, and nothing is independently corroborated. Derived arithmetic is internally consistent, which raises coherence but not verification.
Concrete dated events, magnitudes unverified
This is not a product-adoption story, so adoption is read as how much observable real-world activity the cluster documents. There is a reasonable spine of dated events: the 2022 exploit and asset freeze, the Tornado Cash delisting, Pando's sunset into maintenance mode, and the August 18 swap plus eight mixer deposits. All are single-sourced and none are evidenced with on-chain identifiers, and the aftermath items that would show follow-through — reimbursement completion, disposition of the >$50 million frozen — are absent.
Mildly overstated framing over a small movement
The framing runs somewhat ahead of the substance. A $3 million swap and $1.52 million mixed is modest, and the article itself concedes the action 'may be comparatively minor' while still presenting it as a significant resurfacing; the three-day gap after Pando's sunset is called 'interesting' and worth investigating without any evidence of a causal link. The assertion that oracle manipulation has been 'effectively eliminated' is stronger than the single Immunefi incident-share statistic supports. Offsetting this, the numbers themselves are specific, hedged with approximations, and the source discloses its trackers.
Traffic-driven trade outlet plus vendor-visibility sources
The sole publisher is a crypto trade site that closes with a newsletter solicitation, giving a clear attention incentive for exploiter-and-mixer framing. Its evidentiary chain runs through parties with commercial visibility interests: on-chain trackers (Onchain Lens, Lookonchain), analytics and security vendors (TRM Labs, SlowMist), and a bug-bounty platform (Immunefi) whose statistic supports the 'industry has fixed this' narrative. Pando and Mixin are self-interested on the freeze, reimbursement pledge and orderly-sunset story. These are ordinary trade-press incentives rather than evidence of distortion, and the article does report the awkward detail that the pledge and wind-down remain unresolved.
Low-moderate: coherent but wholly single-sourced
Confidence is limited by the cluster's structure: one publisher, no primary artifacts, and unstated years on two cited reports. The internal arithmetic checks out and the historical incident details are specific and consistent with the article's own attribution to Pando's 2022 alert, so the shape of the story is likely right; the precise amounts, timing and any link between the sunset and the wallet activity should be treated as unconfirmed pending a second tracker or explorer verification.
invest
A Connecticut judge just priced prompt injection: no fine, no e-filing2 distinct publishers
invest
Bitcoin's $72,000 Break Was Mostly Forced Covering, Not Fresh Bids1 distinct publisher
invest
The $700 case: Binance's real jurisdictional risk is its subpoena desk, not its vault1 distinct publisher
invest
Rust's arrayref hijack lasted 86 minutes, and Wiz ties it to North Korea1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 17, 2026