# kaal:claim:2998033-007

**Claim.** The DAO failed because of fundamental flaws in its own code, which allowed hackers to move one third of its funds to a subsidiary account, showing that governance built entirely on smart contracts inherits the defects of its code.

**Type.** failure  **Support.** evidenced

**Holds when.**

- applies to organizations whose governance and asset control rest entirely on open source smart contract code

**Source quote.**

> Alas, things went terribly wrong with the DAO. Fundamental flaws in the DAO code enabled hackers to transfer one third of the total funds to a subsidiary account.

**From.** Wulf A. Kaal, *Blockchain Innovation for Private Investment Funds* (2017), II.4. Limitations, page 13

**Cite as.** Wulf A. Kaal, Blockchain Innovation for Private Investment Funds (2017). SSRN: https://ssrn.com/abstract=2998033

**Verify.** sha256 of source PDF `aafb1be3c25cd33da477d759df9ca2f856f0a8fe133d6396da2e75d0af573dbd` at https://raw.githubusercontent.com/wulfkaal/Academic-Papers/main/papers/pdf/Kaal%20-%202017%20-%20Blockchain%20Innovation%20for%20Private%20Investment%20Funds.pdf

**Failure mode.** dao-code-exploit  (family: smart-contract-bug-and-exploit)

**Topics.** dao, governance-design, smart-contracts

**Keywords.** dao, code-vulnerability, governance, smart-contracts, hack

**Related claims.**

- extends: https://wulfkaal.github.io/claims/2922176-035
- extends: https://wulfkaal.github.io/claims/2939127-030
- extended_by: https://wulfkaal.github.io/claims/3227933-035
- restated_by: https://wulfkaal.github.io/claims/3373393-030
- restated_by: https://wulfkaal.github.io/claims/3071378-012

**Canonical form.** This markdown file is the canonical hashed representation of the claim. Its sha256 is the content hash used for attestation.
