Pando Rings Exploiter Wallet Resurfaces, Buys ETH and Sends 100 ETH to Tornado Cash
Key Takeaways
- •The wallet linked to the Pando Rings exploit bought more than 6,300 ETH using roughly $10 million in DAI in early June 2026.
- •The address later transferred 100 ETH to Tornado Cash, making follow-on tracing more difficult.
- •Pando Rings suffered an oracle manipulation attack in November 2022 that targeted around $70 million in crypto assets.
- •About $21.9 million in assets left the attacker’s Mixin wallets before countermeasures took effect, and some remaining funds were frozen.
- •The protocol later restored parts of its services and changed its lending and collateral controls.

A cryptocurrency wallet tied to the 2022 Pando Rings exploit has re-emerged after years of limited activity, drawing renewed attention to the movement of funds connected to one of the protocol's largest security incidents.
On-chain monitoring identified an address associated with the exploiter as it converted roughly $10 million in DAI, a dollar-pegged stablecoin, into more than 6,300 ETH in early June 2026. The purchases took place near an average price of about $1,600 per ETH. Blockchain attribution in the case, however, rests on transaction-flow analysis rather than definitive proof of ownership.
The wallet subsequently transferred 100 ETH to Tornado Cash, a privacy-focused cryptocurrency mixer that pools deposits and issues withdrawals in a way designed to sever the on-chain link between sender and recipient. The tool has a prominent regulatory history: the U.S. Treasury's Office of Foreign Assets Control sanctioned Tornado Cash in August 2022 over its use in laundering cybercrime proceeds, then lifted those sanctions in March 2025 after a U.S. appeals court ruled that immutable smart contracts could not be sanctioned as property. The transfer has drawn increased scrutiny because the address is linked to funds from the earlier exploit.
The 2022 Pando Rings Attack
Pando Rings, a decentralized lending service built on Mixin Network, suffered an oracle manipulation attack in November 2022. Such attacks target the price data that lending protocols rely on to value collateral, allowing an attacker to inflate an asset's apparent price and borrow against it. According to Pando, the attacker manipulated the price of an LP token and attempted to extract roughly $70 million in crypto assets.
The protocol reported that about $21.9 million in assets — including ETH, EOS and BTC — left the attacker's Mixin wallets before countermeasures took effect. Pando said it also froze a substantial portion of the remaining funds with assistance from Mixin Network and its community.
Following the attack, the protocol restored parts of its services and revised its lending and collateral controls.
Renewed Activity Raises Tracking Concerns
The latest transactions show that funds linked to the exploit remain active years after the original incident. The large ETH purchase also illustrates how dormant crypto assets can re-enter markets without warning.
The transfer to Tornado Cash further complicates the tracing of subsequent movements. Investigators and blockchain analysts can still follow transactions entering and leaving public addresses, but privacy tools can make attribution more difficult.
For crypto markets, the activity underscores the continuing risks associated with compromised wallets and long-dormant exploit proceeds. Traders and compliance teams are likely to watch the associated addresses closely for further ETH movements or attempts to convert the assets into other cryptocurrencies.