{"investigation":{"slug":"the-dao","entity_name":"The DAO","trust_score":10,"severity_base":null,"score_modifier":0,"confidence":0.92,"status":"published","content_type":"investigation","summary":"The DAO was a decentralized autonomous organization launched on the Ethereum blockchain in April 2016 that raised approximately $150 million in Ether — the largest crowdfunding to date at the time — before being drained of 3.6 million ETH (roughly $50–60 million) on June 17, 2016, via a reentrancy vulnerability in its smart contract code. The hack triggered an acrimonious debate over blockchain immutability and led to a contentious hard fork of the Ethereum network on July 20, 2016, splitting it into Ethereum (ETH) and Ethereum Classic (ETC). In 2017 the U.S. SEC concluded that DAO tokens constituted unregistered securities, marking a landmark regulatory precedent for the entire crypto industry.","sections":[{"content":"The DAO (Decentralized Autonomous Organization) was an investor-directed venture capital fund implemented entirely as a set of Ethereum smart contracts. It was conceived and primarily coded by Christoph Jentzsch, Chief Technology Officer of Slock.it, a German blockchain and Internet-of-Things startup co-founded with his brother Simon Jentzsch and Stephan Tual. The project launched its token crowdsale on April 30, 2016, with the stated goal of funding Ethereum-based projects chosen by token-holders. The DAO had no conventional corporate structure, board, or management team; governance was to be executed entirely through on-chain voting by DAO token holders. At its peak, The DAO held nearly 14% of all Ether in circulation and attracted participation from tens of thousands of investors worldwide.","heading":"Overview and Background","sources":[{"url":"https://en.wikipedia.org/wiki/The_DAO","name":"en.wikipedia.org","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2016/05/12/the-dao-or-how-a-leaderless-ethereum-project-raised-50-million","name":"coindesk.com","type":"other","credibility":3},{"url":"https://bitcoinmagazine.com/business/the-dao-raises-more-than-million-in-world-s-largest-crowdfunding-to-date-1463422191","name":"bitcoinmagazine.com","type":"other","credibility":3}],"severity":"medium"},{"content":"From April 30, 2016 through May 28, 2016, The DAO sold approximately 1.15 billion DAO tokens in exchange for roughly 12 million Ether. At prevailing ETH prices, this equated to approximately $150 million USD — making it the largest crowdfunding campaign in history at the time. The fundraise grew rapidly: more than $34 million had been raised by May 10; over $50 million by May 12; and over $100 million by May 15, 2016. These figures are supported by the SEC's own investigative report, which placed the total at approximately $150 million. The scale of the raise drew widespread media attention and was cited as validation of the smart-contract model.","heading":"Crowdsale and Capital Raised","sources":[{"url":"https://bitcoinmagazine.com/business/the-dao-raises-more-than-million-in-world-s-largest-crowdfunding-to-date-1463422191","name":"bitcoinmagazine.com","type":"other","credibility":3},{"url":"https://www.sec.gov/newsroom/press-releases/2017-131","name":"sec.gov","type":"other","credibility":3},{"url":"https://en.wikipedia.org/wiki/The_DAO","name":"en.wikipedia.org","type":"other","credibility":3}],"severity":"medium"},{"content":"On June 17, 2016, an unknown attacker exploited a reentrancy vulnerability in The DAO's smart contract code and drained 3.6 million ETH — approximately one-third of the 11.5 million ETH held in the contract — valued at roughly $50–60 million at the time. The exploit worked by repeatedly calling the smart contract's withdrawal function before the contract could update its internal balance, allowing the attacker to withdraw funds in a recursive loop far exceeding their actual token holdings. The stolen funds were moved to a 'child DAO' contract that imposed a 28-day holding period, temporarily preventing the attacker from liquidating or transferring the assets. Warnings about the recursive-call vulnerability had circulated in the developer community as early as June 9, when blockchain developer Peter Vessenes published a blog post flagging the flaw. On June 12, Slock.it's Stephan Tual published a post asserting that The DAO was not at risk despite similar vulnerabilities known to exist. On June 16, researchers affiliated with the Initiative for CryptoCurrencies and Contracts (IC3) called further attention to recursive-call risks — one day before the attack commenced. Following the exploit, a message claiming to be from the attacker was posted to Pastebin arguing that the withdrawal was legitimate under the terms of The DAO's own smart contract code.","heading":"The June 2016 Reentrancy Hack","sources":[{"url":"https://blog.chain.link/reentrancy-attacks-and-the-dao-hack/","name":"blog.chain.link","type":"other","credibility":3},{"url":"https://www.gemini.com/cryptopedia/the-dao-hack-makerdao","name":"gemini.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/consensus-magazine/2023/05/09/coindesk-turns-10-how-the-dao-hack-changed-ethereum-and-crypto","name":"coindesk.com","type":"other","credibility":3},{"url":"https://beincrypto.com/learn/dao-hack-explained/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://labs.withsecure.com/publications/the-hack-that-changed-the-blockchain-perspective","name":"labs.withsecure.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The hack triggered an intense community debate over whether to intervene and reverse the theft via a protocol-level change to the Ethereum blockchain — a proposal that directly challenged the 'code is law' and immutability principles that many considered foundational to decentralized networks. Ethereum co-founder Vitalik Buterin initially proposed a soft fork to blacklist the attacker's addresses; when technical concerns about that approach emerged, the community pivoted to a hard fork. On July 16, 2016, a community vote was held: of the 82 million ETH then in existence, only roughly 4.54 million ETH (5.5% of supply) participated. Of those votes, approximately 87% supported the fork, though critics noted that a quarter of supporting votes came from a single address. On July 20, 2016, the Ethereum network executed the hard fork, moving the drained funds to a recovery contract from which original DAO token holders could reclaim their Ether. A minority of participants refused to adopt the new chain, continuing on the unmodified blockchain under the name Ethereum Classic (ETC). The stolen ETH remained in attacker-controlled addresses on the ETC chain, worth approximately $8.5 million in ETC in the months following the attack. The fork remains one of the most debated governance events in blockchain history, raising unresolved questions about decentralization, network neutrality, and the limits of community intervention.","heading":"Ethereum Hard Fork Controversy","sources":[{"url":"https://www.coindesk.com/tech/2016/07/20/ethereum-executes-blockchain-hard-fork-to-return-dao-funds","name":"coindesk.com","type":"other","credibility":3},{"url":"https://en.wikipedia.org/wiki/Ethereum_Classic","name":"en.wikipedia.org","type":"other","credibility":3},{"url":"https://www.gemini.com/cryptopedia/the-dao-hack-makerdao","name":"gemini.com","type":"other","credibility":3},{"url":"https://beincrypto.com/learn/dao-hack-explained/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://medium.com/bankless-dao/not-forking-around-the-dao-hack-7a3e974ff110","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The identity of the attacker has never been officially confirmed or resulted in criminal charges. In 2022, Forbes journalist Laura Shin, reporting for her book 'The Cryptopians,' alleged that former TenX CEO Toby Hoenisch was responsible for the hack, citing on-chain analysis conducted by blockchain analytics firm Chainalysis. Shin's evidence included: the stolen funds were converted to the privacy coin Grin and routed to a Grin node named 'grin.toby.ai'; that IP address also hosted Bitcoin Lightning nodes labeled 'ln.toby.ai' and 'lnd.ln.toby.ai'; and a node at the same IP address was named 'TenX'. Shin further alleged that Hoenisch had prior knowledge of vulnerabilities in The DAO's code through communications with Slock.it. Hoenisch denied the accusations, telling Forbes the conclusions were 'factually inaccurate.' No law enforcement authority has filed charges against any individual in connection with the 2016 hack, and the alleged attacker identification should be treated as unverified.","heading":"Alleged Attacker Identity","sources":[{"url":"https://www.theblock.co/post/135017/new-research-claims-to-identify-the-man-who-hacked-the-dao","name":"theblock.co","type":"other","credibility":3},{"url":"https://decrypt.co/93547/crypto-ceo-denies-11-billion-ethereum-dao-hack","name":"decrypt.co","type":"other","credibility":3},{"url":"https://gizmodo.com/hacker-behind-11-billion-crypto-theft-believed-identif-1848577454","name":"gizmodo.com","type":"other","credibility":3},{"url":"https://crypto-economy.com/chainalysis-investigation-ties-ex-tenx-ceo-toby-hoenisch-to-2016-the-dao-hack/","name":"crypto-economy.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On July 25, 2017, the U.S. Securities and Exchange Commission issued an investigative report under Section 21(a) of the Securities Exchange Act of 1934 concluding that DAO tokens were securities under federal law. The SEC applied the Howey test — derived from the 1946 Supreme Court case SEC v. W.J. Howey Co. — finding that DAO tokens constituted investment contracts: investors committed capital (Ether) to a common enterprise (The DAO) with an expectation of profit derived from the managerial efforts of others (Slock.it and The DAO's curators). The Commission determined that The DAO's token offering should have been registered with the SEC or qualified under a valid exemption, and that the platforms on which DAO tokens were traded functioned as unregistered exchanges. Notably, the SEC declined to bring charges or make formal findings of violations in this instance, treating the report as a cautionary guidance document for the broader industry. The ruling is considered a landmark precedent: it was the first time the SEC formally classified a digital token as a security, establishing a regulatory framework that has been cited in subsequent enforcement actions across the crypto sector.","heading":"SEC Regulatory Action","sources":[{"url":"https://www.sec.gov/newsroom/press-releases/2017-131","name":"sec.gov","type":"other","credibility":3},{"url":"https://www.sec.gov/files/litigation/investreport/34-81207.pdf","name":"sec.gov","type":"other","credibility":3},{"url":"https://corpgov.law.harvard.edu/2017/08/10/sec-confirms-that-some-initial-coin-offerings-are-illegal-unregistered-securities-offerings/","name":"corpgov.law.harvard.edu","type":"other","credibility":3},{"url":"https://corpgov.law.harvard.edu/2017/08/09/blockchain-and-initial-coin-offerings-sec-provides-first-u-s-securities-law-guidance/","name":"corpgov.law.harvard.edu","type":"other","credibility":3}],"severity":"medium"},{"content":"The DAO effectively ceased operations in the aftermath of the hack. By September 2016, DAO tokens had been delisted from major exchanges including Poloniex and Kraken, and the organization was considered defunct. The hack and subsequent hard fork had lasting consequences for the Ethereum ecosystem and the broader crypto industry: it demonstrated that even audited, high-profile smart contracts could carry critical vulnerabilities; it established reentrancy as a canonical smart-contract attack vector, prompting the development of new coding standards and security tooling; it created Ethereum Classic as a separate, principles-based blockchain that survives to the present day; and it produced the first major SEC digital-asset securities determination. The event is widely cited in blockchain security literature and regulatory discourse as a formative moment in the development of decentralized finance.","heading":"Dissolution and Historical Significance","sources":[{"url":"https://en.wikipedia.org/wiki/The_DAO","name":"en.wikipedia.org","type":"other","credibility":3},{"url":"https://www.coindesk.com/consensus-magazine/2023/05/09/coindesk-turns-10-how-the-dao-hack-changed-ethereum-and-crypto","name":"coindesk.com","type":"other","credibility":3},{"url":"https://blog.chain.link/reentrancy-attacks-and-the-dao-hack/","name":"blog.chain.link","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2016-04-30","event":"The DAO token crowdsale launches on the Ethereum blockchain, created by Slock.it developers led by Christoph Jentzsch.","source":""},{"date":"2016-05-12","event":"The DAO crowdsale surpasses $50 million raised — the largest crowdfunding in history at the time.","source":""},{"date":"2016-05-15","event":"Crowdsale exceeds $100 million in Ether raised.","source":""},{"date":"2016-05-28","event":"Crowdsale closes with approximately 12 million ETH (~$150 million) raised from the sale of 1.15 billion DAO tokens.","source":""},{"date":"2016-06-09","event":"Developer Peter Vessenes publishes a blog post warning of recursive-call vulnerabilities in Ethereum smart contracts.","source":""},{"date":"2016-06-12","event":"Slock.it's Stephan Tual publishes a post claiming The DAO is not at risk from the known recursive-call vulnerability.","source":""},{"date":"2016-06-16","event":"IC3 researchers publish further warnings about recursive-call vulnerabilities in Ethereum contracts.","source":""},{"date":"2016-06-17","event":"Attacker exploits reentrancy vulnerability in The DAO, draining 3.6 million ETH (~$50–60 million) into a child DAO contract subject to a 28-day holding period.","source":""},{"date":"2016-06-17","event":"Vitalik Buterin proposes a soft fork to blacklist attacker addresses; ETH price drops sharply from ~$20 to ~$13.","source":""},{"date":"2016-07-16","event":"Community vote on the hard fork: approximately 87% of participating ETH supports the fork, representing only 5.5% of total supply.","source":""},{"date":"2016-07-20","event":"Ethereum hard fork executed, moving drained funds to a recovery contract. Ethereum Classic (ETC) emerges as the continuation of the original unforked chain.","source":""},{"date":"2016-09","event":"DAO tokens delisted from major exchanges including Poloniex and Kraken; The DAO considered defunct.","source":"","date_original":"2016-09-01"},{"date":"2017-07-25","event":"U.S. SEC issues investigative report concluding DAO tokens were unregistered securities; no charges filed but landmark precedent established.","source":""},{"date":"2022-02-22","event":"Forbes journalist Laura Shin alleges former TenX CEO Toby Hoenisch carried out the 2016 hack, based on Chainalysis blockchain analysis. Hoenisch denies the claim.","source":""}],"sources_used":[{"url":"https://en.wikipedia.org/wiki/The_DAO","name":"en.wikipedia.org","type":"other","archive_url":"http://web.archive.org/web/20260817224032/https://en.wikipedia.org/wiki/The_DAO","credibility":3,"archive_timestamp":"2026-08-17T22:40:32+00:00"},{"url":"https://www.coindesk.com/markets/2016/05/12/the-dao-or-how-a-leaderless-ethereum-project-raised-50-million","name":"coindesk.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://bitcoinmagazine.com/business/the-dao-raises-more-than-million-in-world-s-largest-crowdfunding-to-date-1463422191","name":"bitcoinmagazine.com","type":"other","archive_url":"http://web.archive.org/web/20260218180511/https://bitcoinmagazine.com/business/the-dao-raises-more-than-million-in-world-s-largest-crowdfunding-to-date-1463422191","credibility":3,"archive_timestamp":"2026-02-18T18:05:11+00:00"},{"url":"https://www.sec.gov/newsroom/press-releases/2017-131","name":"sec.gov","type":"other","archive_url":"http://web.archive.org/web/20260823163718/https://www.sec.gov/newsroom/press-releases/2017-131","credibility":3,"archive_timestamp":"2026-08-23T16:37:18+00:00"},{"url":"https://blog.chain.link/reentrancy-attacks-and-the-dao-hack/","name":"blog.chain.link","type":"other","archive_url":"http://web.archive.org/web/20260607192702/https://blog.chain.link/reentrancy-attacks-and-the-dao-hack/","credibility":3,"archive_timestamp":"2026-06-07T19:27:02+00:00"},{"url":"https://www.gemini.com/cryptopedia/the-dao-hack-makerdao","name":"gemini.com","type":"other","archive_url":"http://web.archive.org/web/20260825055041/https://www.gemini.com/cryptopedia/the-dao-hack-makerdao","credibility":3,"archive_timestamp":"2026-08-25T05:50:41+00:00"},{"url":"https://www.coindesk.com/consensus-magazine/2023/05/09/coindesk-turns-10-how-the-dao-hack-changed-ethereum-and-crypto","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260623234115/https://www.coindesk.com/consensus-magazine/2023/05/09/coindesk-turns-10-how-the-dao-hack-changed-ethereum-and-crypto","credibility":3,"archive_timestamp":"2026-06-23T23:41:15+00:00"},{"url":"https://beincrypto.com/learn/dao-hack-explained/","name":"beincrypto.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://labs.withsecure.com/publications/the-hack-that-changed-the-blockchain-perspective","name":"labs.withsecure.com","type":"other","archive_url":"https://web.archive.org/web/20260829193735/https://www.withsecure.com/en/resources-hub/w-labs/","credibility":3,"archive_timestamp":"2026-08-29T19:37:35+00:00"},{"url":"https://www.coindesk.com/tech/2016/07/20/ethereum-executes-blockchain-hard-fork-to-return-dao-funds","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260807173724/https://www.coindesk.com/tech/2016/07/20/ethereum-executes-blockchain-hard-fork-to-return-dao-funds","credibility":3,"archive_timestamp":"2026-08-07T17:37:24+00:00"},{"url":"https://en.wikipedia.org/wiki/Ethereum_Classic","name":"en.wikipedia.org","type":"other","archive_url":"http://web.archive.org/web/20260821015352/https://en.wikipedia.org/wiki/Ethereum_Classic","credibility":3,"archive_timestamp":"2026-08-21T01:53:52+00:00"},{"url":"https://medium.com/bankless-dao/not-forking-around-the-dao-hack-7a3e974ff110","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.theblock.co/post/135017/new-research-claims-to-identify-the-man-who-hacked-the-dao","name":"theblock.co","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://decrypt.co/93547/crypto-ceo-denies-11-billion-ethereum-dao-hack","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260606194938/https://decrypt.co/93547/crypto-ceo-denies-11-billion-ethereum-dao-hack","credibility":3,"archive_timestamp":"2026-06-06T19:49:38+00:00"},{"url":"https://gizmodo.com/hacker-behind-11-billion-crypto-theft-believed-identif-1848577454","name":"gizmodo.com","type":"other","archive_url":"http://web.archive.org/web/20260726091527/https://gizmodo.com/hacker-behind-11-billion-crypto-theft-believed-identif-1848577454","credibility":3,"archive_timestamp":"2026-07-26T09:15:27+00:00"},{"url":"https://crypto-economy.com/chainalysis-investigation-ties-ex-tenx-ceo-toby-hoenisch-to-2016-the-dao-hack/","name":"crypto-economy.com","type":"other","archive_url":"http://web.archive.org/web/20251009152148/https://crypto-economy.com/chainalysis-investigation-ties-ex-tenx-ceo-toby-hoenisch-to-2016-the-dao-hack/","credibility":3,"archive_timestamp":"2025-10-09T15:21:48+00:00"},{"url":"https://www.sec.gov/files/litigation/investreport/34-81207.pdf","name":"sec.gov","type":"other","archive_url":"http://web.archive.org/web/20260816150045/https://www.sec.gov/files/litigation/investreport/34-81207.pdf","credibility":3,"archive_timestamp":"2026-08-16T15:00:45+00:00"},{"url":"https://corpgov.law.harvard.edu/2017/08/10/sec-confirms-that-some-initial-coin-offerings-are-illegal-unregistered-securities-offerings/","name":"corpgov.law.harvard.edu","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://corpgov.law.harvard.edu/2017/08/09/blockchain-and-initial-coin-offerings-sec-provides-first-u-s-securities-law-guidance/","name":"corpgov.law.harvard.edu","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:55:01.819388+00:00","updated_at":"2026-08-29T20:45:07.396134+00:00"}}