Attacker Resumes Activity After Two-Month Hiatus

According to monitoring data from Onchain Lens, the wallet address associated with the Pando Rings attack became active again on August 18, following a two-month period of inactivity. This movement has drawn significant attention from the blockchain security community.

Large-Scale Asset Swap

The attacker initiated the activity by using CoW Protocol to swap 3 million DAI stablecoins for approximately 1,570 ETH. At prevailing market rates, this transaction was valued at around $3 million.

This swap did not occur in isolation. On-chain records indicate that shortly after acquiring the ETH, the attacker proceeded with further transactions.

Subsequent Fund Movement

After obtaining the ETH, the attacker divided and transferred 800 ETH (worth roughly $1.52 million) across 8 separate transactions to a well-known privacy-enhancing protocol. This batch processing method is commonly used in attempts to obfuscate the trail of funds.

Background: The $20 Million Exploit

The address in question is linked to a major oracle manipulation attack on Pando Rings in November 2022. The exploiter took advantage of a vulnerability in the protocol's price oracle, making off with an estimated $20 million in assets.

The attacker's decision to move the funds after such a long interval suggests they may believe scrutiny has diminished or could be part of a final cash-out strategy. Security analysts note that fund movements from major historical exploits often warrant continued observation.