CoW Swap front end compromised, protocol paused after domain hijacking
Security & Exploits ·
Blockaid flagged the cow.fi domain as malicious, and CoW Swap told users to stop interacting with the site and revoke wallet approvals immediately.
CoW Swap's protocol was paused following the attack, which stemmed from a hijacking of the project's front-end domain, according to The Block. Blockaid's monitoring system identified the front-end attack and flagged cow.fi as malicious, warning that any wallet connected to the site was at risk. CoW Swap confirmed the compromise directly, posting an urgent notice telling users plainly not to use CoW Swap while the issue was addressed, in a statement shared on X and mirrored on Twitter.
The core advice from both Blockaid and the CoW DAO was consistent: disconnect wallets, revoke any approvals granted to the dapp, and avoid further interactions until the situation is resolved. A front-end compromise of this kind allows an attacker to alter what a dapp's interface displays or requests without needing to breach the underlying smart contracts, meaning a wallet that signs a transaction through the malicious interface could be exposing funds to the attacker even though the protocol's on-chain code remains untouched. Revoking approvals is the standard mitigation because it strips any lingering permission the compromised front end may have granted itself to move a user's tokens.
The incident was corroborated across multiple outlets, including a report from wublockchain.xyz, which also described the frontend compromise and the DAO's advisory. Separate accounts in the same cluster described the frontend as experiencing a critical issue and confirmed that the team had halted trading recommendations pending investigation, with CoW DAO issuing a security disclosure urging caution platform-wide.
What remains unresolved is the scope of user funds affected, if any, and how the domain hijacking was carried out in the first place. It is also not yet clear when the protocol will resume normal operations or what remediation steps CoW Swap will take before restoring the front end. Users who interacted with cow.fi during the window the malicious flag was active are advised to check and revoke token approvals as a precaution while the investigation continues.