Incident 50: The DAO Hack

Description: On June 18, 2016, an attacker successfully exploited a vulnerability in The Decentralized Autonomous Organization (The DAO) on the Ethereum blockchain to steal 3.7M Ether valued at $70M.

Tools

New ReportNew ReportNew ResponseNew ResponseDiscoverDiscover
Alleged: The DAO developed and deployed an AI system, which harmed DAO Token Holders.

Incident Stats

Incident ID
50
Report Count
24
Incident Date
2016-06-17
Editors
Sean McGregor

CSET Taxonomy Classifications

Taxonomy Details

Full Description

In 2016 programmers created The Decentralized Autonomous Organization (The DAO) on the Ethereum blockchain to be a venture capital firm without executives or middlemen. Members invested approximately $150M worth of Ether cryptocurrency in The DAO in return for DAO tokens which could be used to vote on and fund real-world projects. On June 18, 2016, an attacker successfully siphoned off approximately a third of The DAO’s funds, which also initiated a precipitous drop in the value of Ether. Due to the nature of blockchains, the code that made up The DAO was both publicly available and immutable, which allowed the hacker to find a vulnerability while preventing The DAO’s creators from securing their system. In a controversial vote, the Ethereum community decided to ‘hard fork’ their blockchain to return the stolen funds, which some see as a violation of the freedom and autonomy at the core of cryptocurrency.

Short Description

On June 18, 2016, an attacker successfully exploited a vulnerability in The Decentralized Autonomous Organization (The DAO) on the Ethereum blockchain to steal 3.7M Ether valued at $70M.

Severity

Moderate

Harm Type

Financial harm

AI System Description

A smart contract written to create a decentralized autonomous organization on the Ethereum blockchain.

System Developer

The DAO

Sector of Deployment

Financial and insurance activities

Relevant AI functions

Cognition

AI Techniques

Unclear

AI Applications

Unclear

Location

Global

Named Entities

The Decentralized Autonomous Organization, Ethereum

Technology Purveyor

The Decentralized Autonomous Organization

Beginning Date

2016-06-18T07:00:00.000Z

Ending Date

2016-06-18T07:00:00.000Z

Near Miss

Harm caused

Intent

Deliberate or expected

Lives Lost

No

Financial Cost

3.7M Ether ($70M at the time)

Data Inputs

User votes

Variants

A "variant" is an incident that shares the same causative factors, produces similar harms, and involves the same intelligent systems as a known AI incident. Rather than index variants as entirely separate incidents, we list variations of incidents under the first similar incident submitted to the database. Unlike other submission types to the incident database, variants are not required to have reporting in evidence external to the Incident Database. Learn more from the research paper.

Similar Incidents

By textual similarity

Did our AI mess up? Flag the unrelated incidents

TayBot

· 28 reports

Hackers Break Apple Face ID

· 24 reports