On this page
The DAO hack of June 2016 is the most philosophically significant event in Ethereum's history. A simple bug — a recursive reentrancy flaw — drained $60 million in ETH from the largest crowdfunding project to date. But the hack itself was only Act One. Act Two was the decision: do you rewrite the blockchain to undo the theft, or do you let the code's outcome stand? That decision split Ethereum in two and created — a permanent monument to the “code is law” philosophy. Every debate about immutability, governance, and what blockchains are for traces back to this fork.
What was The DAO?
was a 2016 experiment: a decentralized, code-run venture fund on Ethereum. There was no manager, no board of directors, no legal entity in the traditional sense — just a smart contract on the Ethereum blockchain. Anyone could buy DAO tokens with ETH, and token holders would vote on which proposals to fund. The smart contract would execute the winning proposals automatically. It was the first major experiment in decentralized governance at scale.
The token sale in May 2016 raised approximately 12.7 million ETH — worth about $150 million at the time, and a significant fraction of all ETH in circulation. It was the largest crowdfunding event in history. The excitement was enormous: here was a demonstration that you could run an investment fund without any human intermediary, just code on a blockchain.
The excitement blinded people to the risk. Several researchers and developers had warned about potential vulnerabilities in The DAO's code before the token sale even ended. The warnings were largely ignored. The code had been reviewed, but not thoroughly enough — and the bug that mattered was subtle.
The bug: recursive reentrancy
The vulnerability was a recursive reentrancy bug in The DAO's “split” function. The split function allowed a DAO token holder to withdraw their share of ETH by creating a “child DAO” and sending their tokens there. The critical flaw was the order of operations:
- The contract checked the sender's balance.
- The contract sent the ETH to the sender.
- The contract updated the sender's balance to zero.
The problem is step 2: when the contract sends ETH to a smart contract (not a regular address), it triggers the recipient's fallback function. An attacker's fallback function could call the split function again — before step 3 ever happened. The balance hadn't been zeroed yet, so the contract would check the balance again (still full), send more ETH, trigger the fallback again, and so on — draining the contract in a loop until it ran out of gas or ETH.
Reentrancy bugs are not unique to blockchain — they are a classic concurrency bug in software engineering. The safe pattern is “checks-effects-interactions”: update state (effects) before calling external code (interactions), so that a re-entrant call sees the already-updated state. The DAO did it in the wrong order: interactions (send ETH) before effects (update balance). This bug pattern has been rediscovered many times since (e.g., in later DeFi hacks). It is the #1 thing smart-contract auditors check for.
The attack
On June 17, 2016, an attacker deployed a malicious smart contract that exploited the reentrancy bug. The attacker's contract bought DAO tokens, then called the split function, and its fallback function re-entered the split function repeatedly — draining ~3.6 million ETH (approximately $60 million) into a child DAO the attacker had created.
Crucially, the attack was “legal” in the sense that the code permitted it. The DAO's smart contract said “here is how you withdraw.” The attacker followed the code's instructions — they just did it in a way the developers hadn't anticipated. This is the crux of the “code is law” debate: if the code allows it, is it a hack, or is it just an unexpected use of the protocol?
There was one saving grace: The DAO's design included a 27-day creation period for child DAOs, during which no ETH could be withdrawn. This meant the stolen ETH was locked in the attacker's child DAO for 27 days — giving the community a window to respond.
The debate: fork or not?
The community split into two camps:
- Pro-fork (“interventionists”): The bug was unintended, the attacker exploited a flaw the developers didn't mean to create, and $60M of community money shouldn't be lost to a coding error. A hard fork to reverse the theft is the right call — blockchains are human tools, and humans can fix their tools.
- Anti-fork (“code-is-law purists”): The whole point of a blockchain is that the code is the final arbiter. If you rewrite the chain every time something bad happens, you have no immutability, no credibility, and no difference from a traditional system where the powerful decide outcomes. The code permitted the withdrawal. The right answer is to learn from it, not to undo it.
The debate was fierce and personal. Vitalik Buterin and the Ethereum Foundation supported the fork. A competing proposal — a “soft fork” that would blacklist the attacker's address without rewriting history — was attempted but found to have technical issues (a denial-of-service vulnerability). The hard fork became the primary option.
The timeline
Tap any event to expand its story.
The DAO launches a token sale, raising ~12.7 million ETH (approximately $150 million at the time) — the largest crowdfunding in history at that point. The DAO is a decentralized venture fund: token holders vote on investments, and smart contracts execute the decisions. No manager, no board — just code.
An attacker begins exploiting a recursive reentrancy bug in The DAO's split function. The exploit works like this: the contract sends ETH to the attacker before updating the attacker's balance, and the attacker's fallback function re-enters the withdrawal before the balance is updated. Each re-entry drains more ETH. Over several hours, ~3.6 million ETH (~$60M) is siphoned into a "child DAO" the attacker created.
The Ethereum community scrambles. Vitalik Buterin proposes a soft fork that would blacklist the attacker's address and prevent withdrawal of the funds. The attacker (or someone claiming to be them) posts a message threatening to split the stolen ETH into 100 sub-DAOs with 27-day delays, making recovery impossible. A tense standoff ensues.
The Ethereum community proposes a hard fork that would move the stolen ETH to a refund contract, returning it to The DAO token holders. The fork is contentious: rather than rewriting the blockchain's history, it would move the funds at a future block into a divergent state — effectively reversing a transfer the code permitted, violating the "code is law" principle that many early Ethereum adopters believed in.
At block 1,920,000, the hard fork executes. The blockchain splits into two: the forked chain (which reverses the theft) becomes "Ethereum" (ETH) and the unforked chain (which keeps the original history, theft included) becomes "Ethereum Classic" (ETC). The DAO token holders get their ETH back on the forked chain. The attacker keeps the ETH on the ETC chain — but it is worth far less.
A faction of the community that believed the fork was wrong continues to mine and support the original, unforked chain. It becomes a real chain with real value, trading under the ticker ETC. It is the canonical expression of "code is law" — the chain where the code's outcome was not overridden by human governance.
The fork settled the immediate crisis but left a permanent philosophical schism in crypto. Ethereum (ETH) thrived and became the dominant smart-contract platform. Ethereum Classic (ETC) survived as a smaller chain, later attacked by 51% attacks multiple times. The DAO hack remains the defining debate about immutability, governance, and the meaning of "code is law."
The fork and the split
On July 20, 2016, at block 1,920,000, the hard fork executed. The fork moved the stolen ETH from the attacker's child DAO to a refund contract, allowing The DAO token holders to recover their funds. Approximately 85% of miners supported the fork.
But 15% didn't. The minority continued to mine the original, unforked chain — the chain where the theft had not been reversed. This chain became (ETC). It was an organic demonstration of a profound crypto principle: you cannot force a fork on a decentralized network. If enough people want to keep the original chain, it continues to exist. The fork didn't eliminate the old chain; it created two chains from one.
Ethereum (ETH) went on to become the dominant smart-contract platform, with the stolen ETH returned to DAO token holders. Ethereum Classic (ETC) survived as a smaller chain, faithful to the “code is law” principle. It later suffered multiple 51% attacks (2019–2020), a practical demonstration that smaller chains are more vulnerable to hash-power attacks.
The DAO hack was the founding trauma of smart-contract security. It taught the industry:
- Audit everything. The DAO's code had been informally reviewed but not professionally audited. After The DAO, smart-contract auditing became a standard requirement.
- Checks-effects-interactions. The reentrancy pattern is now the #1 thing every Solidity developer learns.
- Immutability is a choice, not a fact. The fork showed that “immutable” blockchains can be rewritten — but only through social consensus, which is messier than code.
- Forks create real splits. You can't force everyone to follow a fork. The minority chain can survive.
- Code is not law — but code-as-law is a real philosophy. The Ethereum Classic chain is the permanent expression of that philosophy, with real value and real users.
Key takeaways
- The DAO (2016) was the first major decentralized governance experiment, raising $150M. A recursive reentrancy bug let an attacker drain ~$60M in ETH — by following the code's own logic in an unintended way.
- The reentrancy bug is a classic software bug (do work before updating state). It is now the #1 pattern auditors check for, and the “checks-effects-interactions” rule is standard Solidity practice.
- The community voted to hard-fork and reverse the theft. 85% of miners supported the fork; 15% continued the original chain, becoming Ethereum Classic (ETC) — a permanent expression of “code is law.”
- The fork settled the immediate crisis but created a lasting philosophical schism: are blockchains human tools that can be overridden, or immutable ledgers where code is final? Both Ethereum and Ethereum Classic exist as answers to that question.
- The DAO hack founded smart-contract security as a discipline. Audits, formal verification, bug bounties, and the checks-effects-interactions pattern all trace back to this event.