CoWSwap's cow.fi domain hijacked via fraudulent SSL certificate for phishing; users who connected wallets between 13:00โ20:00 UTC on April 14 should revoke approvals immediately.
Security & Exploits ยท
CoWSwap's team regained control of the cow.fi domain after an attacker used fraudulent documents to obtain a new SSL certificate and host a phishing site mimicking the DEX interface. The protocol had been operating normally at cow.finance during the incident and is now transitioning back to its original domain.
Users who connected their wallets to cow.fi between approximately 13:00 and 20:00 UTC on April 14 should assume their wallets are compromised and immediately revoke all approvals using revoke.cash. The attack exploited domain control rather than a vulnerability in the protocol itself, but exposed users who interacted with the fraudulent interface to potential token loss through existing permissions.
The full scope of affected users and any funds lost through the phishing attack remain unclear. CoWSwap has not disclosed whether the attacker accessed any other infrastructure or whether the SSL issuance process involved a specific Certificate Authority failure.