Key facts
- A reentrancy exploit on The DAO ten years ago drained 3.6 million ETH.
- The exploit led to a hard fork that split the blockchain into Ethereum and Ethereum Classic.
- A new security fund, seeded with unclaimed ETH from the hack, has been launched to support Ethereum security research.
- The DAO Fund is overseen by seven curators, including Ethereum co-founder Vitalik Buterin.
Ten years ago, The DAO, a pioneering decentralized autonomous organization, was subjected to a massive exploit that drained approximately 3.6 million ETH, then valued at around $50 million. This event, which occurred on June 17, 2016, was a watershed moment for the nascent cryptocurrency space, forcing the Ethereum community to make a difficult decision: whether to adhere strictly to the principle of 'code is law' or to intervene and reverse the malicious transactions.
The attack exploited a reentrancy vulnerability in The DAO's smart contract, allowing the attacker to repeatedly withdraw funds before the contract could update its internal balances. The stolen ETH was moved into a separate 'child DAO' with a 28-day withdrawal lock, providing a critical window for the community to respond.
A group of developers, known as the White Hat Group, including The DAO's community manager Griff Green, worked to drain the remaining vulnerable funds into secure contracts they controlled, a move that itself sparked debate about intervention.
Ultimately, the Ethereum community opted for intervention. On July 20, 2016, a hard fork was executed at block 1,920,000, rolling back the blockchain's state to before the hack. This decision led to the permanent split of the network, creating Ethereum (ETH) and Ethereum Classic (ETC). Holders of the original DAO tokens were able to claim their ETH, while the attacker retained the stolen ETC on the original chain.
The aftermath of The DAO hack had profound implications. It is widely credited with catalyzing the growth of the smart-contract security industry, making code auditing and formal verification standard practices. Furthermore, the U.S. Securities and Exchange Commission (SEC) issued a report in 2017 concluding that DAO tokens qualified as securities, a precedent that has significantly shaped crypto enforcement actions.
A decade later, the legacy of The DAO continues. A new entity, The DAO Fund, has been established, utilizing over 75,000 ETH from unclaimed assets recovered after the hack. This fund operates as a long-term endowment, with its yield dedicated to supporting Ethereum security research, tooling, and incident response. Seven curators, including Ethereum co-founder Vitalik Buterin and former MetaMask security lead Taylor Monahan, oversee the fund. The fund recently completed its first allocation round, distributing over $1 million in ETH to 134 security projects.
However, the relaunch has also reignited debates. Some, like Ido Ben-Natan, CEO of Blockaid, suggest that while the fund is a positive step, it shifts trust from the code to the curators. Marcin Kazmierczak, co-founder of RedStone, notes that while funding security through a permanent endowment is progress, it doesn't eliminate trust but relocates it. Concerns have also been raised about the fund's focus, with some arguing that while contract bugs like the original DAO exploit are now better managed, current crypto losses are increasingly driven by operational security failures such as stolen keys and social engineering, rather than smart contract flaws.
