Back to Home

()

exploit
0xbe3e6a3cb2df...2ed47f76aa82
HomesteadContract #19KExact Bytecode MatchEdit this contract

Bytecode verified via sibling

This contract shares identical runtime bytecode with DAOReentrancyExploit (0xc0ee9db1...) which has been verified through compiler archaeology.

Deployed June 20, 2016 (10 years ago)Block 1,734,590

DAO reentrancy exploit redeployed June 19, 2016, after the attack. Byte-identical to the drain contracts but never configured. Structural reconstruction.

Homestead EraVerified Source

Historical Significance

This contract is one of the byte-identical instances of the malicious contract that drained The DAO on June 17, 2016. Together the instances removed about 3.6 million ether, worth roughly 60 million US dollars at the time and close to 15 percent of all ether then in circulation, routing it into a child DAO subject to a 28 day withdrawal delay.

The theft forced the most contentious decision in Ethereum's history. On July 20, 2016 the network executed a hard fork at block 1,920,000 that moved the drained funds to a recovery contract and effectively reversed the theft. Part of the community rejected the fork on the principle of immutability and continued the original chain as Ethereum Classic (ETC), while the forked chain kept the name Ethereum (ETH).

References:

Context

The DAO was a decentralized venture fund launched in April and May 2016 by the German startup slock.it, founded by Christoph Jentzsch, Simon Jentzsch, and Stephan Tual. Its crowdsale gathered more than 12.7 million ether, over 150 million US dollars at the time, the largest crowdfunding event created up to that point. Token holders could exit through a splitDAO function whose reward path sent ether before clearing the caller's token balance, the ordering flaw that made reentrancy possible.

After the attack, the White Hat Group, including Griff Green and Lefteris Karapetsas, deployed contracts using the same exploit to move the remaining vulnerable ether beyond the attacker's reach. Following the July 20, 2016 hard fork, recovered funds were made claimable through a WithdrawDAO contract.

Token Information
Token Name

Symbol

Decimals
1
Key Facts
Deployment Block
1,734,590
Deployment Date
Jun 20, 2016, 12:31 AM
Code Size
2.1 KB
Gas at Deploy
665,050
Transactions by Year
20162

Source Verified

SolidityExact bytecode match(2,142 bytes)
Compiler: v0.3.5-

Compiles with solc 0.3.5 (2016-06-14 nightly, commit 371690f0, optimizer on) to a byte-for-byte match of the on-chain 2142-byte runtime, with the sole exception of five identifier names whose original spellings cannot be recovered from bytecode (two public getters at slots 5 and 7, the onlyOwner trigger 0x625e847d, the setter 0x7f9f519f, and the event topic 0xbab6859b). Placeholder names limit, owner2, attack, setLimit, and NewLimit are used for those five. Everything else is confirmed exact. Verified by placeholder-substitution (0 differing bytes), Panoramix decompilation, and on-chain usage of every function.

Heuristic Analysis

The following characteristics were detected through bytecode analysis and may not be accurate.

Detected Type: exploit
Has ERC-20-like patterns

Bytecode Overview

Opcodes2,142
Unique Opcodes206
Jump Instructions99
Storage Operations61

External Links

Related contracts