CoWSwap suffered a DNS hijack attack resulting in ~$500K drained via approval harvesting; team regained control of original domain and deployed fallback frontend.
Security & Exploits ·
CoW Swap regained control of its cow.fi domain after a DNS hijacking attack on April 14, 2026. An attacker used social engineering against the domain registrar, submitting false documents to impersonate a team member and obtain an SSL certificate for cow.fi. The malicious site hosted two attack phases: a wallet drainer prompting signature requests, then fake modals harvesting seed phrases and passwords. Approximately $500K was drained through approval harvesting during the roughly seven-hour window when the phishing domain was active between 13:00 and 20:00 UTC.
The incident was not caused by a breach of CoW infrastructure or a private information leak, but rather targeted the registrar directly. The team deployed swap.cow.finance as a fallback frontend within hours and has since restored normal service at the original domain. Users who connected wallets to the compromised cow.fi domain during the attack window are advised to revoke all approvals immediately, consider moving funds to a new wallet, and avoid entering seed phrases anywhere.
The team committed to publishing a full post-mortem including root cause analysis, confirmed impact figures, and hardening measures within days pending the registrar's findings. Until then, the exact scope of affected users and total losses remain incompletely documented.