{
 "failure_mode": "smart-contract-bug-and-exploit",
 "specific_names": [
  "DAO code exploit",
  "DAO code flaw exploit",
  "blind approval",
  "bugs-in-simple-contracts",
  "dao-code-exploit",
  "dao-code-vulnerability",
  "smart contract exploit",
  "technology-risk-exposure",
  "unauthorized-veto-provision-unenforceable",
  "unmitigated-contract-risk",
  "unquantifiable technology risk",
  "unverifiable-code-behavior"
 ],
 "count": 14,
 "claims": [
  {
   "id": "kaal:claim:2998033-007",
   "url": "https://wulfkaal.github.io/claims/2998033-007",
   "claim": "The DAO failed because of fundamental flaws in its own code, which allowed hackers to move one third of its funds to a subsidiary account, showing that governance built entirely on smart contracts inherits the defects of its code.",
   "specific_name": "dao-code-exploit",
   "conditions": [
    "applies to organizations whose governance and asset control rest entirely on open source smart contract code"
   ],
   "source": "Blockchain Innovation for Private Investment Funds",
   "year": "2017",
   "quote": "Alas, things went terribly wrong with the DAO. Fundamental flaws in the DAO code enabled hackers to transfer one third of the total funds to a subsidiary account.",
   "citation": "Wulf A. Kaal, Blockchain Innovation for Private Investment Funds (2017). SSRN: https://ssrn.com/abstract=2998033"
  },
  {
   "id": "kaal:claim:3002908-031",
   "url": "https://wulfkaal.github.io/claims/3002908-031",
   "claim": "Because American funds lean on smart contracting, they have a better opportunity to launch disruptive blockchain implementations, but they may also experience a higher rate of failure from greater exposure to technological risk.",
   "specific_name": "technology-risk-exposure",
   "conditions": [
    "conditional on American funds continuing to emphasize smart contracting over conservative crypto asset strategies"
   ],
   "source": "Blockchain Innovation in Private Investment Funds - A Comparative Analysis of the United States and",
   "year": "2017",
   "quote": "This may imply that American private investment funds will have a better opportunity to launch future disruptive implementations of blockchain technology, while at the same time they may experience a higher rate of failure, due to a greater exposure to technological risks.",
   "citation": "Wulf A. Kaal, Marco Dell'Erba, Blockchain Innovation in Private Investment Funds - A Comparative Analysis of the United States and (2017). SSRN: https://ssrn.com/abstract=3002908"
  },
  {
   "id": "kaal:claim:3071378-012",
   "url": "https://wulfkaal.github.io/claims/3071378-012",
   "claim": "The DAO failed because its code had not yet been perfected: hackers took a third of the DAO tokens and transferred them to another account, and that hack together with other technological limitations led to the demise of the DAO.",
   "specific_name": "dao-code-vulnerability",
   "conditions": [
    "The DAO, launched May 2016 on Ethereum"
   ],
   "source": "Blockchain Technology and Race in Corporate America",
   "year": "2017",
   "quote": "Unfortunately, the code had not yet been perfected and hackers were able to take a third of the DAO tokens and transfer them into another account. This hack and other technological limitations, led to the demise of the DAO.58",
   "citation": "Wulf A. Kaal, Blockchain Technology and Race in Corporate America (2017). SSRN: https://ssrn.com/abstract=3071378"
  },
  {
   "id": "kaal:claim:2939127-030",
   "url": "https://wulfkaal.github.io/claims/2939127-030",
   "claim": "Fundamental flaws in the DAO's code let hackers move one third of its total funds to a subsidiary account, and that hack together with further technological limitations destroyed the DAO initiative.",
   "specific_name": "dao-code-exploit",
   "conditions": [
    "the DAO as launched in May 2016 on Ethereum"
   ],
   "source": "Legal Education in the Blockchain Revolution",
   "year": "2017",
   "quote": "Alas, things went terribly wrong with the DAO. Fundamental flaws in the DAO code enabled hackers to transfer one-third of the total funds to a subsidiary account.92 This hack in combination with additional technological limitations brought down the DAO initiative.",
   "citation": "Mark Fenwick, Wulf A. Kaal, Erik P. M. Vermeulen, Legal Education in the Blockchain Revolution (2017). SSRN: https://ssrn.com/abstract=2939127"
  },
  {
   "id": "kaal:claim:3017612-034",
   "url": "https://wulfkaal.github.io/claims/3017612-034",
   "claim": "Absent explicit statutory authorization, many courts have refused to enforce veto provisions contained in shareholder agreements, which is why such provisions should be implemented through charter or bylaw amendment.",
   "specific_name": "unauthorized-veto-provision-unenforceable",
   "conditions": [
    "states without statutes specifically authorizing shareholder control agreements",
    "veto or supermajority provisions"
   ],
   "source": "Shareholder Agreements - National Report of the United States of America",
   "year": "2017",
   "quote": "explicit statutory authorization, many courts have refused to enforce veto provisions in shareholders' agreements.",
   "citation": "Wulf A. Kaal, Shareholder Agreements - National Report of the United States of America (2017). SSRN: https://ssrn.com/abstract=3017612"
  },
  {
   "id": "kaal:claim:2922176-035",
   "url": "https://wulfkaal.github.io/claims/2922176-035",
   "claim": "Fundamental flaws in the DAO's code allowed hackers to move one third of contributed funds to a subsidiary account, ending that initiative, but the flaws were in the implementation and do not defeat the DAO vision, which developers continue to rebuild.",
   "specific_name": "DAO code flaw exploit",
   "conditions": [
    "the original DAO, launched May 2016 on Ethereum"
   ],
   "source": "The ‘Unmediated’ and ‘Tech-Driven’ Corporate Governance of Today's Winning Companies",
   "year": "2017",
   "quote": "The initial DAO did not end well, but DAO enthusiasts and coders are developing new structures to address the flaws of the existing DAO infrastructure. Fundamental flaws in the DAO code made it possible for hackers to transfer one third of the total contributed funds to a subsidiary account.",
   "citation": "Mark Fenwick, Wulf A. Kaal, Erik P. M. Vermeulen, The ‘Unmediated’ and ‘Tech-Driven’ Corporate Governance of Today's Winning Companies (2017). SSRN: https://ssrn.com/abstract=2922176"
  },
  {
   "id": "kaal:claim:3227933-035",
   "url": "https://wulfkaal.github.io/claims/3227933-035",
   "claim": "Fundamental flaws in the DAO's code allowed hackers to transfer one third of the total contributed funds to a subsidiary account, and this together with other technological limitations ended the initiative, but the authors argue it did not end the underlying vision of decentralized autonomous organization.",
   "specific_name": "DAO code exploit",
   "conditions": [
    "the DAO, 2016"
   ],
   "source": "Why 'Blockchain' Will Disrupt Corporate Organizations",
   "year": "2018",
   "quote": "To be sure, fundamental flaws in the DAO code made it possible for hackers to transfer one-third of the total contributed funds to a subsidiary account. This, and other technological limitations meant the end of the initiative",
   "citation": "Mark Fenwick, Wulf A. Kaal, Erik P.M. Vermeulen, Why 'Blockchain' Will Disrupt Corporate Organizations (2018). SSRN: https://ssrn.com/abstract=3227933"
  },
  {
   "id": "kaal:claim:3411110-020",
   "url": "https://wulfkaal.github.io/claims/3411110-020",
   "claim": "Blockchain based offerings introduce technology risks from code design and functioning and from third party intrusions that are generally absent in traditional offerings, and these risks cannot really be quantified.",
   "specific_name": "unquantifiable technology risk",
   "conditions": [
    "blockchain based offerings compared with traditional offerings"
   ],
   "source": "Blockchain-Based Securities Offerings",
   "year": "2019",
   "quote": "Technology-based risks include risks from the design and functioning of code, and from third-party intrusions. Such risks are generally not present in a traditional offering.",
   "citation": "Wulf A. Kaal, Samuel Evans, Blockchain-Based Securities Offerings (2019). SSRN: https://ssrn.com/abstract=3411110"
  },
  {
   "id": "kaal:claim:3373393-030",
   "url": "https://wulfkaal.github.io/claims/3373393-030",
   "claim": "Fundamental flaws in the DAO code enabled hackers to transfer one third of total funds to a subsidiary account, and that hack combined with additional technological limitations brought down the first DAO initiative.",
   "specific_name": "dao-code-exploit",
   "conditions": [
    "the first DAO, 2016"
   ],
   "source": "Blockchain Solutions for Agency Problems in Corporate Governance",
   "year": "2019",
   "quote": "This hack in combination with additional technological limitations brought down the first DAO initiative.",
   "citation": "Wulf A. Kaal, Blockchain Solutions for Agency Problems in Corporate Governance (2019). SSRN: https://ssrn.com/abstract=3373393"
  },
  {
   "id": "kaal:claim:3405401-019",
   "url": "https://wulfkaal.github.io/claims/3405401-019",
   "claim": "In more complex smart contracts the counterparties cannot fully know whether the contract will do what it was programmed to do, or whether it will contain bugs or follow a logic the parties did not anticipate.",
   "specific_name": "unverifiable-code-behavior",
   "conditions": [
    "more complex smart contracts"
   ],
   "source": "Decentralized Commerce – A Primer on Why Decentralized Reputation Verification Systems Are Needed",
   "year": "2019",
   "quote": "In other words, in more complex smart contracts, the counterparties to the contract cannot fully know if the contract will do what it was programmed to do and whether it will have bugs or otherwise follow another logic that was not anticipated by the parties to the contract.",
   "citation": "Wulf A. Kaal, Decentralized Commerce – A Primer on Why Decentralized Reputation Verification Systems Are Needed (2019). SSRN: https://ssrn.com/abstract=3405401"
  },
  {
   "id": "kaal:claim:3405401-020",
   "url": "https://wulfkaal.github.io/claims/3405401-020",
   "claim": "Even small and simple smart contracts often contain bugs that trigger unforeseeable consequences, so contract simplicity is not by itself a guarantee of correct execution.",
   "specific_name": "bugs-in-simple-contracts",
   "conditions": [],
   "source": "Decentralized Commerce – A Primer on Why Decentralized Reputation Verification Systems Are Needed",
   "year": "2019",
   "quote": "Even small and simple smart contracts often have bugs that trigger unforeseeable consequences.",
   "citation": "Wulf A. Kaal, Decentralized Commerce – A Primer on Why Decentralized Reputation Verification Systems Are Needed (2019). SSRN: https://ssrn.com/abstract=3405401"
  },
  {
   "id": "kaal:claim:3995709-007",
   "url": "https://wulfkaal.github.io/claims/3995709-007",
   "claim": "Code confusion produces blind approval, where a reviewer hopes a co-worker knows what they are doing and approves a change without understanding it, which can result in further bugs and delayed production.",
   "specific_name": "blind approval",
   "conditions": [
    "reviewers confused by unfamiliar code",
    "peer trust within a team"
   ],
   "source": "How DAOs Optimize Open-Source Code Reviews and Create Open-Source Standards",
   "year": "2021",
   "quote": "blind approval may occur when a reviewer hopes their co-worker knows what they're doing and blindly approves a change.36 Blind approval can result in further bugs and delay production.",
   "citation": "Wulf A. Kaal, How DAOs Optimize Open-Source Code Reviews and Create Open-Source Standards (2021). SSRN: https://ssrn.com/abstract=3995709"
  },
  {
   "id": "kaal:claim:5245185-016",
   "url": "https://wulfkaal.github.io/claims/5245185-016",
   "claim": "Infrastructure level permissioning neglects critical risks such as smart contract exploits, bugs, and permission conflicts, and proposes no real time enforcement across distributed nodes, which weakens its claim to bridge AI autonomy and accountability.",
   "specific_name": "unmitigated-contract-risk",
   "conditions": [
    "permissioned transaction controls embedded in smart contracts"
   ],
   "source": "How can we Best Monitor AI Agents",
   "year": "2025",
   "quote": "also neglects critical risks, such as smart contract exploits, bugs, or permission conflicts, and fails to propose real-time enforcement solutions across distributed nodes.",
   "citation": "Wulf A. Kaal, How can we Best Monitor AI Agents (2025). SSRN: https://ssrn.com/abstract=5245185"
  },
  {
   "id": "kaal:claim:5583610-036",
   "url": "https://wulfkaal.github.io/claims/5583610-036",
   "claim": "Smart contract exploits are a live failure channel for LER, capable of producing losses on the scale of DeFi incidents that have exceeded $1 billion annually and requiring insurance premiums of one to two percent of asset value.",
   "specific_name": "smart contract exploit",
   "conditions": [
    "on-chain deployment of reward contracts"
   ],
   "source": "Liquid Equity Rewards in Corporate America",
   "year": "2025",
   "quote": "Vulnerabilities such as smart contract exploits could result in losses akin to DeFi incidents, where failures have exceeded $1 billion annually, necessitating insurance premiums of 1–2% of asset value.",
   "citation": "Wulf A. Kaal, Liquid Equity Rewards in Corporate America (2025). SSRN: https://ssrn.com/abstract=5583610"
  }
 ]
}