Blockaid Identifies CoW Swap Frontend as Malicious Following DNS Hijacking Incident

Here's what it means for you.
If you engage with decentralized finance (DeFi) platforms, understanding security vulnerabilities is crucial to protecting your assets.
Why it matters
This incident underscores the ongoing risks associated with decentralized finance, particularly regarding the security of domain registrars and DNS infrastructure.
What happened (in 30 seconds)
- On April 14, 2026, Blockaid flagged the CoW Swap frontend at cow.fi as malicious due to a DNS hijacking attack.
- Attackers used social engineering to gain control of the domain, redirecting users to a phishing site designed to steal wallet information.
- CoW DAO paused operations and regained control of the domain by April 15, advising users to revoke token approvals.
The context you actually need
- Frontend attacks on DeFi platforms have become more common, exploiting vulnerabilities in centralized domain registrars.
- Social engineering tactics allow attackers to impersonate domain owners, altering DNS records to redirect traffic to malicious sites.
- Previous incidents involving protocols like OpenEden and Maple Finance highlight the persistent risks in the DeFi space, despite secure smart contracts.
What's really happening
On April 14, 2026, at approximately 13:00 UTC, a coordinated attack targeted the CoW Swap decentralized exchange, a platform built on Ethereum. The attackers employed social engineering tactics to manipulate the DNS registrar, using forged documents to gain control of the domain cow.fi. This manipulation allowed them to issue a new SSL certificate and deploy a phishing frontend that closely mimicked the legitimate CoW Swap interface.
By 14:54 UTC, users attempting to access swap.cow.fi were redirected to the malicious site, which was designed to harvest sensitive information such as wallet seed phrases and private keys. Blockaid, a blockchain security firm, issued an alert at 16:18 UTC, warning users of the compromised frontend. CoW DAO, the governing body of the CoW Swap protocol, responded by posting initial warnings at 15:41 UTC and confirmed the hijacking at 16:24 UTC. They paused backend operations to prevent further exploitation.
The following day, on April 15, CoW DAO announced that they had regained full control of the domain and detailed the two-phase phishing attack: first, a wallet drainer to siphon funds, followed by a seed phrase harvester to capture users' private information. A post-mortem was published on April 16, outlining the attack vector and recommending that users check their wallets for unauthorized approvals via revoke.cash.
Despite the severity of the attack, CoW DAO reported no confirmed losses from their protocol treasury or smart contracts, indicating that the security of the underlying smart contracts remained intact. However, the incident caused a temporary dip of over 3% in the price of the COW token, reflecting market sensitivity to security breaches. The platform resumed operations through a temporary domain, cow.finance, while transitioning back to cow.fi.
This incident highlights a critical vulnerability in the DeFi ecosystem: while smart contracts can be secure, the infrastructure supporting them, such as DNS and domain registrars, can be exploited. The reliance on centralized services for domain management poses a significant risk, as attackers can bypass the security of decentralized protocols by targeting these centralized points of failure.
Who feels it first (and how)
- DeFi users: Individuals engaging with CoW Swap and similar platforms are at risk of losing funds if they interact with compromised sites.
- Investors in COW token: Price fluctuations following security incidents can impact their investments.
- Developers and protocol teams: Increased scrutiny on security practices may lead to heightened operational costs and the need for improved security measures.
What to watch next
- Increased security measures: Watch for DeFi platforms enhancing their security protocols and user education to prevent similar attacks.
- Market reactions: Monitor how the COW token and similar assets respond to security incidents, as investor confidence can shift rapidly.
- Regulatory developments: Keep an eye on potential regulatory responses aimed at improving security standards for domain registrars and DNS services in the DeFi space.
The CoW Swap frontend was compromised due to a DNS hijacking attack.
Other DeFi platforms may face similar attacks if they do not enhance their security measures.
The long-term impact on user trust in DeFi platforms following this incident remains uncertain.
Frequently Asked Questions
- Why it matters?
- This incident underscores the ongoing risks associated with decentralized finance, particularly regarding the security of domain registrars and DNS infrastructure.
- What happened (in 30 seconds)?
- On April 14, 2026, Blockaid flagged the CoW Swap frontend at cow.fi as malicious due to a DNS hijacking attack. Attackers used social engineering to gain control of the domain, redirecting users to a phishing site designed to steal wallet information. CoW DAO paused operations and regained control of the domain by April 15, advising users to revoke token approvals.
- What's really happening?
- On April 14, 2026, at approximately 13:00 UTC, a coordinated attack targeted the CoW Swap decentralized exchange, a platform built on Ethereum. The attackers employed social engineering tactics to manipulate the DNS registrar, using forged documents to gain control of the domain cow.fi. This manipulation allowed them to issue a new SSL certificate and deploy a phishing frontend that closely mimicked the legitimate CoW Swap interface. By 14:54 UTC, users attempting to access swap.cow.fi were red
- Who feels it first (and how)?
- DeFi users: Individuals engaging with CoW Swap and similar platforms are at risk of losing funds if they interact with compromised sites. Investors in COW token: Price fluctuations following security incidents can impact their investments. Developers and protocol teams: Increased scrutiny on security practices may lead to heightened operational costs and the need for improved security measures.
- What to watch next?
- Increased security measures: Watch for DeFi platforms enhancing their security protocols and user education to prevent similar attacks. Market reactions: Monitor how the COW token and similar assets respond to security incidents, as investor confidence can shift rapidly. Regulatory developments: Keep an eye on potential regulatory responses aimed at improving security standards for domain registrars and DNS services in the DeFi space.
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"Cointelegraph is a leading crypto-focused media outlet known for timely news, analysis, and educational content related to blockchain and digital assets."
— A47 Editor
DAO behind CoW Swap urges users to stay off platform after ‘hijacking‘
The decentralized exchange aggregator CoW Swap has issued a warning to its users to avoid its platform following a frontend exploit that has raised security concerns. The incident has prompted the DAO behind CoW Swap to advise users to refrain from v...
Covers Bitcoin plus altcoin news, market updates, and educational resources.
"Bitcoin.com provides news, market data, and guides focused on Bitcoin and the wider crypto industry."
— A47 Editor
Cow Protocol Halts Trading After Frontend Domain Hijack
Cow Protocol has halted trading following a hijack of its frontend domain, raising concerns about the security of its platform. This incident has led to a temporary suspension of services, affecting users and traders relying on Cow Swap and Cow DAO f...
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"CoinDesk is a well-established cryptocurrency and blockchain news provider, offering comprehensive insights, market data, and industry research."
— A47 Editor
Popular DeFi platform warns users to stay away from its site after security breach
CoW Swap, a popular decentralized finance (DeFi) platform, has issued a warning to its users to avoid its site following a security breach that has raised concerns about potential vulnerabilities. The platform's team is actively working to resolve th...
Real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors.
"Crypto News delivers real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors."
— A47 Editor
CoW Swap users warned after Blockaid flags COW.FI frontend attack
Blockchain security firm Blockaid has flagged CoW Swap's primary website, COW.FI, as malicious due to a frontend attack, urging users to revoke token approvals and avoid the decentralized application. This warning comes amid a broader wave of attacks...
Research, news, and analysis on blockchain startups, DeFi, and regulations.
"Crypto Briefing provides research, news, and analysis on blockchain startups, DeFi, and crypto regulations with investor-focused coverage."
— A47 Editor
Blockaid flags CoW Swap site as malicious amid front end attack
Blockaid has flagged the CoW Swap site as malicious following a front end attack, advising users to avoid cow.fi and revoke any approvals while the decentralized exchange investigates the situation. This warning highlights potential security vulnerab...