Pando Hack
What happened
Pando Rings was exploited through manipulation of the sBTC-WBTC liquidity-provider token price used by its oracle. Assets left the attacker's Mixin wallets before intervention. Pando and its partners froze other funds and halted affected services.
Pando Rings relied on a manipulable LP-token price in its oracle. The official notice establishes this pricing failure but does not explain the underlying contract implementation.
Case & protocol details
How it happened
- The attacker manipulated the price of the 4swap LP token used by Pando Rings.
- The distorted oracle valuation enabled extraction of assets from the lending system.
- Some assets were transferred out before intervention; other assets were frozen with help from Mixin and the community.
- Pando halted services, began repairing the oracle and engaged SlowMist to trace funds.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.