What really happened with The DAO in 2016? đ
The DAO was the first-ever venture fund built on smart contracts. Users deposited ETH and received DAO tokens to vote on where the money should go. In total, it raised $150M from 11,000 people â 15% of all ETH at the time đ·
Where was the vulnerability?
There was a bug in the splitDAO function â it allowed a user to âsplit offâ and create a new sub-DAO with a portion of the funds. But it didnât include protection from a reentrancy attack â a type of exploit where a function is called repeatedly before the balance is updated đł
How the attack worked:
âą The attacker triggered splitDAO to create a sub-DAO
âą Then called it recursively â dozens of times â before the balance updated
âą The contract didnât check if funds had already been withdrawn, so they just kept coming
Basically, it was like a broken ATM giving out cash over and over until it realized it was empty đ°
How was it fixed?
The Ethereum community had two options:
A) Leave it be and let the hacker walk away with $60M đ±
B) Roll back the blockchain to before the hack đ
They chose option B. This led to a hard fork and two separate chains:
âą Ethereum (ETH) â with the rollback and refunds
âą Ethereum Classic (ETC) â the original chain, where the code stayed unchanged
What changed after this?
1ïžâŁ Reentrancy became a well-known attack vector
â Now one of the first things auditors check
2ïžâŁ Audit firms like OpenZeppelin and Trail of Bits became industry standards
â No serious project launches smart contracts without an audit
3ïžâŁ DAO frameworks like XDAO, Aragon, and DAOstack emerged
â Nobody writes DAO code from scratch anymore
4ïžâŁ UX and governance security improved
â With roles, multisig, spending limits, rage quit, and more
Why XDAO is protected from this kind of scenario
The key difference: audits â
The DAOâs biggest flaw was launching without a full audit â and thatâs exactly how the bug went unnoticed.
The XDAO framework has been audited by independent security firms like Hacken and Pessimistic. Itâs already used in 40+ blockchains and thousands of real DAOs. The smart contracts for XDAO on TON will also be audited soon đ«Ą
Closed, secure interface â
In The DAO, users could interact directly with the contract â triggering dangerous functions intentionally or by mistake. In XDAO, all actions go through a Telegram interface with only safe, pre-approved operations. You canât call low-level contract functions manuallyđ
No critical functions like splitDAO â
The DAO had a feature that let anyone split off and take a chunk of the treasury. XDAO doesnât allow that â all fund movements require voting or multisig, and DAO behavior is set clearly at creation. Sensitive parts are guarded by roles, limits, and validation rules đ„
XDAO isnât an MVP â itâs a mature product â
Itâs gone through audits, dozens of releases, adoption in 40+ chains, and stress-tested by hundreds of thousands of DAOs.
This is robust infrastructure â and exactly what weâre building on for TON â
Conclusion
The DAO was a pioneer â and a victim of its own newness.
Its failure was a turning point for the industry. Now itâs 2025. In 9 years, everything that once failed has been rebuilt from the ground up: architecture, audit practices, interfaces, legal clarity, and collective experience. Everything that was fatal in 2016 is fortified in XDAO today đ€©

81,03Â mil
0
O conteĂșdo desta pĂĄgina Ă© fornecido por terceiros. A menos que especificado de outra forma, a OKX nĂŁo Ă© a autora dos artigos mencionados e nĂŁo reivindica direitos autorais sobre os materiais apresentados. O conteĂșdo tem um propĂłsito meramente informativo e nĂŁo representa as opiniĂ”es da OKX. Ele nĂŁo deve ser interpretado como um endosso ou aconselhamento de investimento de qualquer tipo, nem como uma recomendação para compra ou venda de ativos digitais. Quando a IA generativa Ă© utilizada para criar resumos ou outras informaçÔes, o conteĂșdo gerado pode apresentar imprecisĂ”es ou incoerĂȘncias. Leia o artigo vinculado para mais detalhes e informaçÔes. A OKX nĂŁo se responsabiliza pelo conteĂșdo hospedado em sites de terceiros. Possuir ativos digitais, como stablecoins e NFTs, envolve um risco elevado e pode apresentar flutuaçÔes significativas. VocĂȘ deve ponderar com cuidado se negociar ou manter ativos digitais Ă© adequado para sua condição financeira.

