In April 2024, a single on-chain vote moved $165 million out of Uniswap's treasury and into a two-year grants program. No CEO signed off on it. No board met in a room somewhere. A scattered group of token holders, most of them anonymous, debated the idea on a public forum, voted through a smart contract, and the money moved, automatically, exactly as the code said it would. That's a DAO in action, a decentralized autonomous organization, basically an attempt to run an organization with code and token votes instead of a management hierarchy.
A normal company has officers, a board, bylaws, and a bank account someone with signing authority controls. A DAO tries to replace all of that with a smart contract holding a shared treasury, plus a token that gives its holder voting rights over what happens to that treasury. Want to propose spending money on something? Post a proposal, usually on a forum first for discussion, then a formal on-chain vote. If enough token-weighted votes say yes, the contract executes it. Nobody has to trust a treasurer not to run off with the funds, the code only does what the vote told it to do.
The very first project to actually use the name was, confusingly, called The DAO, launched on Ethereum in 2016 as a kind of crowdfunded venture fund. It raised an enormous amount of ether for the time, and then, weeks later, an attacker exploited a flaw in its smart contract code and drained roughly a third of its funds, worth tens of millions of dollars at the time. The Ethereum community faced a hard choice: leave the theft standing because "the code is the law," or intervene and reverse it. They chose to intervene, hard forking the network to return the funds, a decision controversial enough that a portion of the community rejected it and kept running the original, unforked chain, which is why Ethereum Classic exists today as a separate network. Every DAO built since has been shaped, one way or another, by that early lesson: smart contract code with real money behind it needs to be audited like it's holding a bank vault, because in a real sense, it is one.
Most DAOs today follow roughly the same cycle. Someone drafts a proposal and posts it to a discussion forum, often somewhere like Discourse or Discord, where the community argues about it for days or weeks. If it gains enough support, it moves to a formal on-chain vote, usually through a platform like Snapshot for off-chain signaling or directly through the protocol's own governance contract for binding votes. Voting power is almost always proportional to how many governance tokens someone holds, one token, one vote, rather than one person, one vote. If the proposal passes, execution can happen automatically through the smart contract, or through a multisig wallet controlled by a smaller, trusted subset of the community for proposals too complex to fully encode. For how that underlying multisig mechanism works, see what a multisig wallet actually is, and for the smart contract layer making any of this enforceable at all, see what a smart contract actually does.
MakerDAO, now rebranded Sky, governs one of DeFi's largest stablecoin systems entirely through token holder votes on collateral types and risk parameters. Uniswap DAO controls the protocol's fee switch and treasury, the same treasury behind that $165 million grants vote. Aave DAO governs one of the largest lending protocols the same way. MolochDAO, launched in 2019 with a deliberately stripped-down "minimum viable DAO" design focused narrowly on funding Ethereum ecosystem grants, inspired a whole wave of simpler forks built on the same idea: keep the governance surface small enough that it's actually hard to attack. By early 2026, DAO treasuries collectively held somewhere north of $30 billion, up from around $16 billion in 2021, spanning DeFi, gaming, media, and increasingly real-world asset management.
The private key for every Bitcoin wallet on Earth is on this website, even Satoshi's. But even if you try for a million years, you'll never find a funded one.
Try the key collider nowToken-weighted voting sounds democratic until you notice it isn't really one person one vote, it's one dollar one vote, and researchers studying DAO governance have consistently found that large token holders, whales, end up disproportionately shaping outcomes simply because they can afford to buy more voting power than anyone else. Voter apathy is a real, persistent problem too, plenty of governance votes pass or fail on a tiny fraction of eligible tokens actually participating, since most holders never bother voting at all. Governance attacks are a genuine risk category of their own: an attacker can, in theory, borrow a large amount of a governance token temporarily through a flash loan, vote through a malicious proposal, and repay the loan within the same transaction, though most major protocols have added time delays and voting-power snapshots specifically to close that hole. And legally, most DAOs still exist in a genuine gray zone, some jurisdictions, Wyoming among the first, have created specific legal structures like a DAO LLC to give these organizations liability protection and legal standing, but plenty of DAOs still operate with no formal legal wrapper at all, which creates real uncertainty about who's actually liable if something goes wrong.
It's not just theoretical risk. Beanstalk Farms, a DeFi protocol, lost around $182 million in April 2022 when an attacker used a flash loan to temporarily acquire enough governance tokens to pass a malicious proposal in a single transaction, draining the protocol's funds before anyone could react. Build Finance DAO was effectively taken over in early 2022 when an attacker simply showed up to a poorly attended vote, proposed themselves as the sole admin, and passed it because almost nobody else voted. Neither of these needed a sophisticated code exploit in the traditional sense, they exploited the governance process itself, low voter turnout in one case, a lending mechanism in the other. That's part of why most serious DAOs now build in time-locks between a vote passing and it actually executing, giving the community a window to notice something's wrong and react before funds actually move.
Not every DAO story is about an exploit. In November 2021, a group of strangers organized almost entirely over the internet, calling themselves ConstitutionDAO, and raised roughly $47 million in a matter of days from thousands of small contributors, all trying to win a Sotheby's auction for an original copy of the US Constitution. They actually lost the auction to a single wealthy bidder, and then faced a awkward problem afterward: refunding tens of thousands of contributors was expensive and slow on Ethereum given gas fees at the time, and many people ended up paying more in transaction fees to get their money back than they'd actually contributed. It wasn't a hack or a scam, just a real demonstration of how hard fast, ad hoc coordination at that scale actually is once the fun part, raising the money, is over and the boring part, winding things down cleanly, begins.
Wyoming passed the first US law specifically recognizing a DAO LLC structure back in 2021, letting a DAO register as a limited liability company with its governance rules encoded directly into the smart contract rather than a traditional operating agreement, giving members real liability protection in the process. A handful of other states and countries have since introduced similar frameworks, but adoption has been slow, and plenty of large, well-known DAOs still operate without any formal legal entity behind them at all. That matters more than it might sound like it does: without a legal wrapper, courts in some jurisdictions have started treating DAO participants as something closer to a general partnership, which can mean personal liability for members if the DAO gets sued, exactly the kind of exposure a legal structure like Wyoming's is meant to prevent. A widely discussed 2022 case in a California federal court leaned in that direction, treating an unincorporated DAO's token holders as potentially liable partners, a ruling that got a lot of attention across the industry precisely because it confirmed the risk was real rather than just theoretical.
Academic researchers who've studied real DAO governance closely tend to describe most of them as something less than fully decentralized in practice, more of a polycentric structure where a handful of large stakeholders, founding teams, venture backers, and big token holders, hold outsized influence even though the formal structure is open to everyone. That doesn't make the model worthless, a DAO's treasury and rules are actually transparent and auditable by anyone in a way a private company's books never are, and execution really does happen without a single person able to unilaterally block or reverse it. It just means "decentralized" in DAO governance is closer to a spectrum than a binary, and where any specific DAO actually sits on that spectrum is worth checking before assuming the label guarantees anything about how power actually gets distributed inside it.