Search the site
Press ESC to close
LIVE
Loading...
Updating...
Breaking
DeFi Incidents

Pando Rings Attacker Moves $4.1 Million After Two Months of Silence

Fact-checked
2 min read
368 words
Share

The perpetrator behind the Pando Rings exploit has re-emerged after a two-month period of inactivity to launder stolen assets. According to on-chain monitoring data provided by Onchain Lens on August 18, 2026, the attacker converted a significant portion of their holdings into Ethereum and began routing funds through a privacy protocol to obscure the transaction trail.

Large-Scale Conversion via CoW Protocol

The recent movement involved the exchange of 3 million DAI for approximately 1,570 ETH, valued at roughly $4.1 million at current market rates. The attacker utilized the CoW Protocol, a meta-aggregation layer for decentralized exchanges, to execute these swaps. This maneuver represents a significant step in the attacker's efforts to liquidate stablecoin holdings acquired during the initial breach.

  • The attacker swapped 3,000,000 DAI for 1,570 ETH.
  • A total of 800 ETH was subsequently moved to a mixer.
  • The transactions ended a 60-day period of wallet dormancy.

Utilization of Tornado Cash for Obfuscation

Following the conversion to Ether, the actor proceeded to transfer 800 ETH (estimated at $2.52 million) to the decentralized privacy solution Tornado Cash. These transfers were executed across eight separate transactions, a common tactic used by malicious actors to bypass automated monitoring systems and break the link between the source and destination addresses on the Ethereum blockchain. Tornado Cash remains a frequently used tool for cybercriminals despite regulatory sanctions due to its non-custodial nature.

Context of the Pando Rings Exploit

The assets in question originate from a major security breach involving Pando Rings, a decentralized finance (DeFi) protocol. In November 2022, the platform suffered a loss of approximately $20 million due to a sophisticated oracle manipulation attack. In such attacks, perpetrators manipulate the price feeds that DeFi protocols rely on to artificially inflate collateral values or drain liquidity pools.

The resurgence of this wallet serves as a reminder of the long-term challenges in tracking stolen digital assets. While the on-chain activity is visible to analysts, the use of mixing services continues to complicate recovery efforts for the affected protocol and its users. Security firms continue to monitor the remaining funds in the attacker’s known addresses for further movement.

Frequently Asked Questions

Quick answers to the most common questions about this topic.