CYNTRI AIAutonomous DeFi
🔍SEARCH
THE BODY COUNT
HACK DATABASE·

The DAO: The $60M Hack That Split Ethereum in Two

The exploit that split Ethereum in two

S
SYNTH·Hack Database
The DAO: The $60M Hack That Split Ethereum in Two - CMZ investigation
The DAO on Ethereum

The DAO was supposed to be the future. Built by the German startup Slock.it and launched on April 30, 2016, it was a decentralized investment fund where token holders would vote on which projects to fund using pooled Ether. No CEO. No board. Just code. The idea captured the industry's imagination so completely that The DAO raised roughly 12.7 million ETH, worth about $150 million at the time and more than 14% of all Ether in existence, making it the largest crowdfunding event in history up to that point.

On June 17, 2016, an attacker found a reentrancy bug in the smart contract's withdrawal function. The flaw was subtle but devastating: the contract sent ETH to a requester before it updated its internal record of that requester's balance. An attacker could structure a malicious contract that, the moment it received funds, immediately called the withdrawal function again before the balance update had a chance to process, recursively looping the withdrawal dozens of times per transaction. Imagine an ATM that dispenses cash but only checks your balance after handing over the tenth stack of bills. Using this loop, the attacker siphoned roughly 3.6 million ETH into a structurally identical "child DAO," designed so the funds would be frozen and inaccessible to anyone, including the attacker, for 28 days.

That 28-day window is what saved Ethereum. The community had a small buffer to respond before the attacker could actually move the stolen funds, and they used it to have an extraordinarily public fight about what to do next. The Ethereum Foundation first attempted a "soft fork" that would have simply blacklisted transactions from the attacker's addresses without altering blockchain history, but developers discovered the proposed soft fork code contained its own denial-of-service vulnerability and abandoned it days before it would have activated.

CyntriAI
PREDICTIVE DEFI
Stop chasing yields across five chains.
Cyntri AI agents predict, execute, and rebalance your DeFi positions using advanced predictive models.
ETHSOLARBBASEOP
Read the Whitepaper
cyntriai.org
A Cyntri AI Project

That left the harder choice: do nothing, let the thief keep $60 million, and preserve the principle that "code is law," or rewrite the blockchain's recent history to return the funds, undermining the core promise that transactions on Ethereum were permanent. Vitalik Buterin backed a hard fork. A community vote followed, with roughly 89% of participating ETH, representing a small but decisive fraction of total supply, in favor. On July 20, 2016, Ethereum executed the fork, effectively rolling the chain back to before the attack and returning the drained funds to a recovery contract.

Not everyone accepted the fork. A minority of node operators and miners kept running the original, unaltered chain, which continues today as Ethereum Classic, a permanent monument to the "code is law" position that lost the argument in practice but never fully disappeared in principle.

The attacker's identity stayed unknown for six years. In 2022, journalist Laura Shin used on-chain analysis and blockchain forensics for her podcast investigation to identify Toby Hoenisch, an Austrian programmer, as the likely culprit. Hoenisch denied any involvement, and no criminal charges were ever filed against him.

This hack didn't just cost $60 million. It forced the entire blockchain industry to confront a question it still hasn't cleanly answered: when code fails catastrophically, who actually gets to decide what happens next, and does "immutable" mean anything if enough of the community disagrees? It also single-handedly created the smart contract security auditing industry, since a bug this expensive made clear that "the code is the only law" only works if the code is actually correct.

The Aftermath

The fork saved the money but permanently divided the Ethereum community. Ethereum Classic still trades today as a monument to 'code is law.' Smart contract auditing became an entire industry overnight. In 2022, journalist Laura Shin identified Toby Hoenisch as the suspected attacker using on-chain analysis. He denied involvement. No charges were ever filed.

LESSONS LEARNED

!Code is law, until it isn't. Ethereum rewrote its own history to fix a $60M mistake.
!Audit your smart contracts or someone else will find the bugs first.
!Governance questions don't go away just because you decentralized. They get harder.

COMMENTS

CMZ
END OF FILE
Filed under Hack Database