Pando Hack

REPORTED LOSS $18.6M
High Access Control mixin

What happened

Pando Rings was exploited through manipulation of the sBTC-WBTC liquidity-provider token price used by its oracle. Assets left the attacker's Mixin wallets before intervention. Pando and its partners froze other funds and halted affected services.

Technical Root Cause

Pando Rings relied on a manipulable LP-token price in its oracle. The official notice establishes this pricing failure but does not explain the underlying contract implementation.

Case & protocol details

Classification Exchange (DEX)
Protocol Type Exploit/Access control
Official Website pando.im/
Protocol Twitter/X @pando_im

How it happened

  1. The attacker manipulated the price of the 4swap LP token used by Pando Rings.
  2. The distorted oracle valuation enabled extraction of assets from the lending system.
  3. Some assets were transferred out before intervention; other assets were frozen with help from Mixin and the community.
  4. Pando halted services, began repairing the oracle and engaged SlowMist to trace funds.

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.