New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

TheDAO Security Fund - Ethereum Initiatives Funding Round | Pol, Dappnode | ETHTaipei 2026

ETHTaipeiSat, Oct 3, 2026, 12:00 AM

TheDAO Security Fund - Ethereum Initiatives Funding Round: How can you participate? | Pol, Dappnode | ETHTaipei 2026

Transcript

[music]

Hello there. How's it going? Good. Perfect. How many of you were around the ecosystem in 2016?

Not so many. So, maybe this maybe this story will be interesting to you. Maybe uh maybe you have heard about The DAO. The DAO was a project that existed in 2016 that broke Ethereum into. It split Ethereum into Ethereum and Ethereum Classic.

So, let's go back to 2016, where The DAO is this new project. There's not much to do on Ethereum in 2016. It's still fairly new. And this crazy idea of The DAO comes up. And we can pool money together, and we can all collectively decide what are we going to use this money for.

This, which sounds so natural now, with Constitution DAO, with like a bunch of like we've done it many many times now. In 2016, it was the craziest thing that you could do, and it raised a hundred and fifty million dollars in Ethereum, which was a lot back then, the highest, the largest crowdfunding ever at that point. And now, in 2016, we 99% of what was hacked was claimed, and we still have Wait a minute. 180 million are left. The The maths don't math.

What what's going on? Well, let me explain you to you what's going on. Um The DAO The The the still has The DAO raised 150 million and it still has 180 million. So, how did this happen? Well, okay.

The DAO raised 150 million at uh around 12.5 ETH per uh dollars per ETH, sorry, which was around uh 12 million ETH, which was I think around a little bit low 20% of all the Ethereum in circulation at that point. Um then, as you know, this DAO got hacked and the hacker took 50 million in US terms out of this contract. Now, that was catastrophic for Ethereum. That was basically that could have tanked the price of Ethereum and there was a huge debate.

The first instance of the debate is code law. Some people said, "Hey, this is what was written in the smart contract. The smart contract could be exploited. We should let the hacker keep the money." And these people decided to not fork Ethereum to save and recover this money.

So, these people are the ones that created Ethereum Classic because the whole Ethereum community as a whole was like, "Actually, not really. This money was hacked and nobody ever intended for this money to be hacked. So, this is code is not law and we will roll back the chain." This has never happened before in Ethereum uh and it hasn't happened since in Ethereum um to create a fork of this dimension. So, the hard fork rescued 100% of the funds because they just rolled back all of the transactions that the hacker did.

Now, there was these were these accounted for 97% of the whole uh of all of the ETH that was in the in the hack and then there were some edge cases, people that paid more uh more than one ETH per 100 DAO tokens, like a bunch of edge edge cases that uh as what was called the DAO curators put in a multi-sig and decided to manage and let people claim. And the white hat group uh rescued 70% uh of the funds in Ethereum Classic. So, the the the same hackers that that hacked or secured the 100 million that were left in Ethereum, they also went to Ethereum Classic and secured uh 70% of those funds as well. Now, out of the funds on Ethereum, 99.3 were claimed.

Out of the um edge cases, 80% are claimed. And out of the ones in Ethereum Classic, about 85% are claimed. Um by the way, a very funny story is that this is the only hack in history that I know of where literally everybody made money. The hacker made money because even if in Ethereum they rolled back and they couldn't, then in Ethereum Classic, he made money. So, uh regular DAO users in Ethereum, they didn't lose anything because the transactions got rolled back.

So, they didn't lose anything. But in Ethereum Classic, all of a sudden, they also have Ethereum Classic. So, they made money as well. The hacker made money and regular users made money as well. Wouldn't that be great in the hacks that we have nowadays?

Well, it takes uh it takes a hard fork it's to to do that and I'm I'm afraid we're we're not in the space to do it. Um okay, so, where do these 180 million come from? They come from these 3% of the whole funds that are edge cases. And these edge cases, because they're very hard to classify and we don't know exactly who had a claim to it, then um the people claiming this said in this post, "After a few months, in January 31st, all of the money that has not been claimed will be sent to Ethereum security." And then proceeded to forget about this at all.

This money was left in that contract for people to claim, and people have been claiming over these years, but it was basically forgotten money. Until last year, 9 years later, 9 years after this, there is PC. PC is sits on the board of the Ethereum Foundation, and he's probably one of the most important people in Ethereum security that exists. He was talking with Fade from Wintermute. Uh Fade was 8 years old when the DAO hack happened.

So, he was 17 or 18 when um he was talking with PC, and Fade discovered that blog post that said this money will be given to security. And Fade said to PC, "Hey, why don't Why don't you I've checked the smart contracts. This money's still there. Why don't you use this money?" So, they contacted Griff.

Uh Griff, who was the original coordinator of the DAO. And Griff tried to find the uh curators, the the multi-sig curators, the DAO curators, and it was extremely hard to find. They were impossible to find. They were He messaged them everywhere in every platform, mail, uh found them on LinkedIn. It was It was impossible.

These people were impossible to find. And then, the Balancer hack happened. This means this was the beginning of the AI hack apocalypse. The Balancer hack was a bug in Solidity, I think. Um and all of All of a sudden, we did not have much time because the AI was really pushing for contracts that were compiled with earlier versions of solidity.

There was key management risk after so many years. Do these people even have the keys to recover this money? What's going like are these these keys already compromised? Were in devices that were already compromised? So doing nothing was not an option.

How can we recover this money and make something with it? Well, we can put it into staking. Staking is a very well known mechanism in Ethereum and it's very secure and it's very well known how to secure this. And then we will use the profits of staking in order to dedicate to security. This way we can leave the claims for people who have not claimed this money yet open.

But in the meanwhile, we'll have them generating revenue for security. Okay, so this is exactly what I explained. The extra balance had 70k in Ethereum. This is still claimable. If you have funds in there, you can still claim them.

In fact, since we have announced the DAO, there have been more claims than in the past 9 years. Except the first year. And then we put this ETH to stake and we're generating projects. These are the new curators of the new DAO, the DAO security funds. And I am privileged to be among these giants.

So why security? Well, this was the original intention. This was the original intention dedicate this money to security. So that's what we that's what we're doing. And it also happens to fit really well into this ecosystem where the Ethereum Foundation is sort of stepping back a little bit and leaving space for other organizations to take over certain aspects.

ETH systems is focusing on privacy. Ethereum institutional is focusing on well, institutions. ETH labs on more research and the DAO security funds, well, we're focusing on security. Uh what is Ethereum security? This is we didn't have to make this up.

The Ethereum Foundation has the trillion-dollar security trillion-dollar security.org. You can check this out. Um But what have we we've done so far? So far we've put 1.

9 million USD into Ethereum security on 135 projects and 615,000 came from other co-sponsors, co-founders, and donors. Wintermute, Quantstamp, Sigma Prime, Certora, uh Chain Security, and OtterSec. Thank you. If any representatives of these companies are here, thank you again for your contribution to Ethereum security. Um But 1.

9 million is not enough. Numbers are not enough. We want to see impact. Um so we created this group, the Ethereum uh ba- Ethereum security badge holders, 200 securities uh experts across the whole ecosystem, and we're going to see why we are going to use them. Now, this is what matters to you.

Round two. We are going to distribute more for Ethereum projects. This time we're focusing on impacts, and it has four stages. We're mapping the needs the security needs across Ethereum. Then we want to see that there is demand for this.

We want to create RFPs and make a transparent process for people to fulfill the security processes, and finally we want to check that the delivery uh is accountable the teams are accountable for the delivery, and there is adoption for it. Phase one. Two tracks. We are engaging with the main players in the Ethereum ecosystem. That is you.

You are a main player in the Ethereum ecosystem, and we are asking what are your security problems? And then we're also having public submissions. Go to initiatives.thedao.fund.

I'll give you the password. This will be launched the 15th the 15th there will not be password but I'll give you the password at the end of this presentation. And we're generating this RFP list. Now, phase two. We will come up with this RFP list and people will have to pledge money companies.

Will your RFP have any users? If you build a solution for this if a solution is built for this will people use it? How do we know that beforehand? Because companies need to pledge Uniswap needs to pledge money saying hey this tool I will use in all of my smart contracts on all of my wallets on all of everything. So they need to pledge wallet money for it.

We want co-funding. If a minimum threshold if co-funding is needed then we'll put to vote with the badge holders and the badge holders these 200 security experts that we have carefully curated across the ecosystem they will vote which of the projects that have passed this threshold will get the voting. Um then phase three. This is a normal RFP phase. I'm not going to spend too much time in here.

We'll open for teams like you if you work in a security company to submit a proposal on how to solve the problem that's on the RFP. If you think you can solve the problem you should submit a solution. And phase four if you get selected you will be selected to uh publish this and to to actually do the work. Very important. 33 to 50% will be based on adoption.

If you have no adoption on the project you will not receive 33 to 50% of the money. We are focusing on impact. We want to see projects that really impact the security of Ethereum. So now for you again if you have a security needs, tell me. Find me here.

Or go to initiatives.thedao.fund and submit an RFP yourself. You don't even need me. Um if you have funds and you have a security need and you have funds to fund it, talk to me.

Or go to initiatives.thedao.fund and see which of these RFPs are useful to you and pledge money for it. And finally, if you're a security expert, then you have you either can help us shape an RFP, can help us shape an RFP that already that that somebody is is submitting in order to make it more general, more actionable. You can either judge judge if you're a batch holder.

Maybe you have some batch holders here. Or you can apply to submit the project for the RFP. All right. So, that's the end of my presentation, lightning talk. Find me if you think you know what is good for Ethereum security.

Let's talk. Submit an RFP, pledge funds, or submit a proposal when the RFP is funded. Thank you, guys.

[applause]

Thank you, Paul, for that fascinating story.

Automatic transcript — names and jargon may be misspelled.