SoK: Attacks on DAOs

Authors Rainer Feichtinger , Robin Fritsch , Lioba Heimbach , Yann Vonlanthen , Roger Wattenhofer

Document Identifiers

Author Details

Rainer Feichtinger
  • ETH Zürich, Switzerland
Robin Fritsch
  • ETH Zürich, Switzerland
Lioba Heimbach
  • ETH Zürich, Switzerland
Yann Vonlanthen
  • ETH Zürich, Switzerland
Roger Wattenhofer
  • ETH Zürich, Switzerland


We thank Hubert Ritzdorf from ChainSecurity for his precious feedback.

Cite As Get BibTex

Rainer Feichtinger, Robin Fritsch, Lioba Heimbach, Yann Vonlanthen, and Roger Wattenhofer. SoK: Attacks on DAOs. In 6th Conference on Advances in Financial Technologies (AFT 2024). Leibniz International Proceedings in Informatics (LIPIcs), Volume 316, pp. 28:1-28:27, Schloss Dagstuhl – Leibniz-Zentrum für Informatik (2024)


Decentralized Autonomous Organizations (DAOs) are blockchain-based organizations that facilitate decentralized governance. Today, DAOs not only hold billions of dollars in their treasury but also govern many of the most popular Decentralized Finance (DeFi) protocols. This paper systematically analyses security threats to DAOs, focusing on the types of attacks they face. We study attacks on DAOs that took place in the past, attacks that have been theorized to be possible, and potential attacks that were uncovered and prevented in audits. For each of these (potential) attacks, we describe and categorize the attack vectors utilized into four categories. This reveals that while many attacks on DAOs take advantage of the less tangible and more complex human nature involved in governance, audits tend to focus on code and protocol vulnerabilities. Thus, additionally, the paper examines empirical data on DAO vulnerabilities, outlines risk factors contributing to these attacks, and suggests mitigation strategies to safeguard against such vulnerabilities.

Subject Classification

ACM Subject Classification
  • Security and privacy → Economics of security and privacy
  • Human-centered computing → Collaborative and social computing
  • blockchain
  • DAO
  • governance
  • security
  • measurements
  • voting systems


