Cornell Professor Calls for 'DAO 2.0' Movement
Emin Gün Sirer already helped identify the bug that led to an expensive exploit of The DAO. Now he's helping ensure future DAOs are safe.

The Cornell computer scientist who helped identify vulnerabilities in The DAO revealed 10 new exploits in its code at an event in New York.
The statements from Emin Gün Sirer, a longstanding critic of the project, come amid broad concern over developments at The DAO, a smart contract-based funding vehicle built with ethereum that has effectively collapsed following an exploit of a vulnerability within its smart contract code.
Sirer warned that, while the vulnerability that led to the removal of tens of millions of dollars worth of the cryptocurrency ether is now well-understood, much remains to be fixed before another DAO (decentralized autonomous organization) can be launched.
The statements were the first to lay a clear path forward for how to build an organization run largely with code, and thus fulfill the original vision of The DAO.
Sirer, who is the co-director of the Initiative for Cryptocurrencies and Contracts (IC3), an academic research project focused on the technology, used the forum to lay out a detailed account of possible exploits for such projects that go all the way down to the Ethereum coding language itself.
Sirer went on to argue that the issues highlighted are relevant when looking at the question of creating similar projects in the future.
He told the crowd:
"The DAO 2.0 requires much, much more effort. It’s a much deeper field than people might think."
Vulnerabilities detailed
In the days leading up to the initial bug detection, Sirer and his colleagues published an overview of what they called a “recursive call” vulnerability that allowed the exploiter to move funds into a so-called “child DAO” that breaks off from the original DAO.
Addressing a crowd of about 70 bitcoin coders, ethereum developers, computer scientists and financial professionals at last night's event, Sirer went into detail about other possible threats.
For example, the “stalking” bug – which is currently being used to mount a counter-attack against a white-hat hack designed to move funds into a safe account – is an example of one of the vulnerabilities Sirer identified at last night’s event.
The 10 vulnerabilities Sirer discussed in detail include a "concurrent proposal trap" whereby an attacker makes an arbitrary proposal such as 'Do you believe in God?' designed to entice a high degree of response, and include long voting period during which the token used to vote becomes trapped. Then, a competing proposal could be made by the attacker after the funds have been locked up.
Another exploit, called a "majority takeover" attack, disguises a majority vote by a single party that might benefit from a successful proposal by splitting the voting power into smaller votes cast separately, for which he said there is no known defense.
Some of the exploits discussed last night were published in detail in the earlier paper. A full list, along with an account of how The DAO functions, can be found here.
"The whole point of smart contracts is to create exciting, weird financial instruments," Sirer told attendees, adding:
"This is not exciting, it’s just weird."
Tough love
In the hours leading up to yesterday’s event, Sirer engaged in an Twitter debate in which he argued that the Ethereum community should ostracize founding members of Slock.it, a Germany-based startup that wrote The DAO code and spearheaded its deployment.
At the event in New York, Sirer doubled-down on his call, naming founders Stephan Tual and Christoph Jentzsch, in particular.
But while Sirer had some harsh words for Slock.it, he said the problems extend to ethereum itself. He called The DAO a "ginormous $220m bug bounty", a criticism that extended not only to DAOs, but to ethereum’s smart contracts coding language Solidity, which he said is a work in progress.
Sirer told attendees:
"We should redesign Solidity, we should rethink what it means to write secure state machines, how we should specify them and how we should make sure that they do not mess up."
Image by Michael del Castillo for CoinDesk
More For You
Protocol Research: GoPlus Security

What to know:
- As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
- GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
- Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.
More For You
IREN Raises $2.3B, Repurchases Debt in Balance Sheet Overhaul

The bitcoin miner extended maturities, reduced coupon costs and strengthened its capital structure.
What to know:
- IREN completed a refinancing deal involving a $2.3 billion convertible senior notes offering and a $544.3 million repurchase of existing notes.
- The new notes include $1 billion of 0.25% notes due 2032, $1 billion of 1% notes due 2033, and a $300 million greenshoe allotment.
- The transactions provided $2.27 billion in net proceeds, reduced IREN's cash coupon burden, and extended its debt maturity profile.











