The code behind the DAO is available here [2].
Apparently [3], there's a bug where one can recursively call `splitDAO` multiple times to extract ether from the contract if one has a split open.
- Ether can go missing when it is sent to a public address which has no known corresponding private key. It's a "we can't inverse a hash" type of problem.
- People lose if they're holding a long position on ETH, or have DAO which they can now no longer recoup to ETH. People gain if they're shorting ETH, or are the attacker themselves (it looks like the ETH from the dao is going to this address [4])
- Looks to be an existential threat to the DAO from where we're standing right now. I can't see any mitigations but an entire Ethereum blockchain split.
[1] https://blog.slock.it/no-dao-funds-at-risk-following-the-eth...
[2] https://github.com/slockit/DAO/blob/develop/DAO.sol
[3] http://pastebin.com/DykumjLs
[4] http://etherscan.io/address/0x304a554a310c7e546dfe434669c628...