CoW Swap temporarily suspended its protocol on April 14, 2026 after attackers compromised the DNS settings for swap.cow.fi, redirecting visitors to a malicious phishing site. The hijacking began at approximately 14:54 UTC, with on-chain security firm Blockaid issuing the first public warning, flagging cow.fi as malicious and urging users who had connected a wallet to revoke approvals and avoid any interactions with the dApp immediately.
CoW DAO confirmed the attack in a follow-up post at roughly 16:24 UTC, identifying the incident as a DNS hijacking. The team said the underlying CoW Protocol smart contracts were unaffected, but paused the backend and APIs as a precaution while working to resolve the domain. Users who interacted with the frontend after 14:54 UTC were advised to revoke any token approvals using revoke.cash.
This story is an excerpt from the Unchained Daily newsletter.
Subscribe here to get these updates in your email for free
Aave acknowledged the situation and confirmed it had temporarily disabled CoW Swap endpoints for its integrators as a precaution. The incident is part of a broader pattern of frontend and DNS attacks targeting DeFi protocols. In recent months, Blockaid has flagged similar attacks on tokenization platform OpenEden, lending protocol Curvance, and asset manager Maple Finance.
DNS hijacking typically exploits registrar-level weaknesses, such as compromised credentials or social engineering, rather than any flaw in smart contract code. As of publication, CoW DAO had not confirmed full restoration or released a post-mortem. No confirmed user fund losses had been publicly reported.
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to
Disclaimer.
Related Articles
Claude Desktop Installation Reportedly Writes Backdoor File to Chromium-Based Browsers
The Claude Desktop application by Anthropic installs a backdoor file in Chromium-based browsers without user consent, posing serious security and privacy risks by potentially allowing attackers to control users' browsers.
GateNews58m ago
Chinese National Arrested at Buenos Aires Airport for $49.4M Crypto Fraud Scheme
A Chinese national was arrested in Argentina for carrying a forged Paraguayan passport. He is wanted for orchestrating a $49.4 million cryptocurrency fraud in Nigeria, and extradition proceedings are being initiated.
GateNews1h ago
Lido EarnETH Vault Exposed to $21.6M rsETH Following Kelp Bridge Exploit, DAO Sets $3M Loss Protection
On April 18, a Kelp cross-chain bridge exploit led to the theft of $292 million in rsETH. Lido reported $21.6 million in exposure via its EarnETH vault, prompting Aave to freeze relevant markets. EarnETH has paused transactions and is deleveraging, while Lido's DAO treasury implemented a $3 million protection mechanism to cover potential losses. The core staking protocol remains unaffected.
GateNews1h ago
Seven Israeli Officers Charged in Multimillion-Dollar Crypto Theft Ring
Israeli Security Forces Charged in Crypto Theft Case
Israeli authorities have charged seven military and police officers with running a multimillion-dollar theft and bribery ring involving cryptocurrency, marking the second crypto-related criminal case to hit the country's defence establishment in
CryptoFrontier5h ago
Ice Open Network Suffers Data Breach; User Emails and 2FA Phone Numbers Exposed
Ice Open Network reported a security breach on April 15, revealing unauthorized access to user data, including email addresses and 2FA phone numbers, but no financial data was compromised. The incident, linked to former partners of a service provider, is under legal review, and users are advised to update security settings. The breach highlights escalating security issues in the crypto sector, with significant losses reported in recent months.
GateNews8h ago