Skip to content

Deep dive · Hacks & Collapses · 12 min

The DAO Hack & the Fork That Split Ethereum

A recursive reentrancy bug drained $60M and forced the most contentious decision in Ethereum’s history: undo it or not.

On this page
Why this matters

The DAO hack of June 2016 is the most philosophically significant event in Ethereum's history. A simple bug — a recursive reentrancy flaw — drained $60 million in ETH from the largest crowdfunding project to date. But the hack itself was only Act One. Act Two was the decision: do you rewrite the blockchain to undo the theft, or do you let the code's outcome stand? That decision split Ethereum in two and created — a permanent monument to the “code is law” philosophy. Every debate about immutability, governance, and what blockchains are for traces back to this fork.

What was The DAO?

was a 2016 experiment: a decentralized, code-run venture fund on Ethereum. There was no manager, no board of directors, no legal entity in the traditional sense — just a smart contract on the Ethereum blockchain. Anyone could buy DAO tokens with ETH, and token holders would vote on which proposals to fund. The smart contract would execute the winning proposals automatically. It was the first major experiment in decentralized governance at scale.

The token sale in May 2016 raised approximately 12.7 million ETH — worth about $150 million at the time, and a significant fraction of all ETH in circulation. It was the largest crowdfunding event in history. The excitement was enormous: here was a demonstration that you could run an investment fund without any human intermediary, just code on a blockchain.

The excitement blinded people to the risk. Several researchers and developers had warned about potential vulnerabilities in The DAO's code before the token sale even ended. The warnings were largely ignored. The code had been reviewed, but not thoroughly enough — and the bug that mattered was subtle.

The bug: recursive reentrancy

The vulnerability was a recursive reentrancy bug in The DAO's “split” function. The split function allowed a DAO token holder to withdraw their share of ETH by creating a “child DAO” and sending their tokens there. The critical flaw was the order of operations:

  1. The contract checked the sender's balance.
  2. The contract sent the ETH to the sender.
  3. The contract updated the sender's balance to zero.

The problem is step 2: when the contract sends ETH to a smart contract (not a regular address), it triggers the recipient's fallback function. An attacker's fallback function could call the split function again — before step 3 ever happened. The balance hadn't been zeroed yet, so the contract would check the balance again (still full), send more ETH, trigger the fallback again, and so on — draining the contract in a loop until it ran out of gas or ETH.

The pattern

Reentrancy bugs are not unique to blockchain — they are a classic concurrency bug in software engineering. The safe pattern is “checks-effects-interactions”: update state (effects) before calling external code (interactions), so that a re-entrant call sees the already-updated state. The DAO did it in the wrong order: interactions (send ETH) before effects (update balance). This bug pattern has been rediscovered many times since (e.g., in later DeFi hacks). It is the #1 thing smart-contract auditors check for.

The attack

On June 17, 2016, an attacker deployed a malicious smart contract that exploited the reentrancy bug. The attacker's contract bought DAO tokens, then called the split function, and its fallback function re-entered the split function repeatedly — draining ~3.6 million ETH (approximately $60 million) into a child DAO the attacker had created.

Crucially, the attack was “legal” in the sense that the code permitted it. The DAO's smart contract said “here is how you withdraw.” The attacker followed the code's instructions — they just did it in a way the developers hadn't anticipated. This is the crux of the “code is law” debate: if the code allows it, is it a hack, or is it just an unexpected use of the protocol?

There was one saving grace: The DAO's design included a 27-day creation period for child DAOs, during which no ETH could be withdrawn. This meant the stolen ETH was locked in the attacker's child DAO for 27 days — giving the community a window to respond.

The debate: fork or not?

The community split into two camps:

  • Pro-fork (“interventionists”): The bug was unintended, the attacker exploited a flaw the developers didn't mean to create, and $60M of community money shouldn't be lost to a coding error. A hard fork to reverse the theft is the right call — blockchains are human tools, and humans can fix their tools.
  • Anti-fork (“code-is-law purists”): The whole point of a blockchain is that the code is the final arbiter. If you rewrite the chain every time something bad happens, you have no immutability, no credibility, and no difference from a traditional system where the powerful decide outcomes. The code permitted the withdrawal. The right answer is to learn from it, not to undo it.

The debate was fierce and personal. Vitalik Buterin and the Ethereum Foundation supported the fork. A competing proposal — a “soft fork” that would blacklist the attacker's address without rewriting history — was attempted but found to have technical issues (a denial-of-service vulnerability). The hard fork became the primary option.

The timeline

Tap any event to expand its story.

The fork and the split

On July 20, 2016, at block 1,920,000, the hard fork executed. The fork moved the stolen ETH from the attacker's child DAO to a refund contract, allowing The DAO token holders to recover their funds. Approximately 85% of miners supported the fork.

But 15% didn't. The minority continued to mine the original, unforked chain — the chain where the theft had not been reversed. This chain became (ETC). It was an organic demonstration of a profound crypto principle: you cannot force a fork on a decentralized network. If enough people want to keep the original chain, it continues to exist. The fork didn't eliminate the old chain; it created two chains from one.

Ethereum (ETH) went on to become the dominant smart-contract platform, with the stolen ETH returned to DAO token holders. Ethereum Classic (ETC) survived as a smaller chain, faithful to the “code is law” principle. It later suffered multiple 51% attacks (2019–2020), a practical demonstration that smaller chains are more vulnerable to hash-power attacks.

What the DAO hack taught the industry

The DAO hack was the founding trauma of smart-contract security. It taught the industry:

  • Audit everything. The DAO's code had been informally reviewed but not professionally audited. After The DAO, smart-contract auditing became a standard requirement.
  • Checks-effects-interactions. The reentrancy pattern is now the #1 thing every Solidity developer learns.
  • Immutability is a choice, not a fact. The fork showed that “immutable” blockchains can be rewritten — but only through social consensus, which is messier than code.
  • Forks create real splits. You can't force everyone to follow a fork. The minority chain can survive.
  • Code is not law — but code-as-law is a real philosophy. The Ethereum Classic chain is the permanent expression of that philosophy, with real value and real users.

Key takeaways

  • The DAO (2016) was the first major decentralized governance experiment, raising $150M. A recursive reentrancy bug let an attacker drain ~$60M in ETH — by following the code's own logic in an unintended way.
  • The reentrancy bug is a classic software bug (do work before updating state). It is now the #1 pattern auditors check for, and the “checks-effects-interactions” rule is standard Solidity practice.
  • The community voted to hard-fork and reverse the theft. 85% of miners supported the fork; 15% continued the original chain, becoming Ethereum Classic (ETC) — a permanent expression of “code is law.”
  • The fork settled the immediate crisis but created a lasting philosophical schism: are blockchains human tools that can be overridden, or immutable ledgers where code is final? Both Ethereum and Ethereum Classic exist as answers to that question.
  • The DAO hack founded smart-contract security as a discipline. Audits, formal verification, bug bounties, and the checks-effects-interactions pattern all trace back to this event.
Educational only, not financial or legal advice.