Cryptobriefing Pando Rings Exploit Wallet Executes $10M ETH Purchase Amid Market Dip
Article Content
- •A wallet linked to the 2022 Pando Rings exploit executed a $10 million ETH purchase.
- •The exploit involved an oracle manipulation attack, resulting in $20 to $22 million in losses.
- •Investors should monitor the wallet for potential sell pressure from the recently acquired ETH.
A wallet associated with the 2022 Pando Rings exploit executed a $10 million transaction, acquiring 6,243 ETH at an average price of $1,602. This transaction marks the wallet's first significant activity since the exploit, which involved an oracle manipulation attack that drained $20 to $22 million from the protocol. The Pando Rings exploit occurred on November 5, 2022, leading to the suspension of the protocol's operations. Despite some stolen assets being frozen with the help of Mixin Network, a substantial amount remains unaccounted for. The recent transaction suggests that the hacker is betting on Ethereum's price increase, raising concerns about the security of other DeFi protocols. Investors are advised to monitor this wallet closely for potential sell pressure as the 6,243 ETH could be liquidated if the hacker decides to take profits.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ethereum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…