Security incident · 2016-06-17
The DAO
According to the public DefiLlama incident dataset, The DAO (Ethereum) suffered a security incident on 2016-06-17, with about $60.0M reported lost.
| Date | 2016-06-17 |
|---|---|
| Reported loss | $60.0M |
| Chain | Ethereum |
| Target type | DeFi Protocol |
| Technique class | Reentrancy |
| Technique | Reentrancy |
| Bridge incident | No |
| Within 2016 | #2 by loss that year, 44.2% of all reported losses that year |
How this kind of attack works
The contract sent funds before updating balances, and the attacker re-entered during the transfer to withdraw repeatedly.
Would a pre-payment check have helped
Reentrancy is a classic contract bug, unrelated to the counterparty; code audits address it.
Other incidents with the same technique
- Rari Capital2022-05-01 · $80.0M
- Curve DEX2023-07-30 · $61.7M
- GMX V1 Perps2025-07-09 · $42.0M
- Grim Finance2021-12-18 · $30.0M
- Penpie2024-09-03 · $27.0M
- dForce Lending2020-04-19 · $25.0M

