HomeDeFiCoW Swap lost $1.2M in a domain hijack phishing attack

CoW Swap lost $1.2M in a domain hijack phishing attack

A cow swap security incident left the decentralized exchange facing losses of $1.2 million after a coordinated domain takeover on April 14.

Domain weakness triggered the attack

The breach did not affect the platform’s core protocol. However, attackers exploited its domain management system and redirected users to a malicious website that closely mirrored the official interface.

The team said social engineering helped the attackers seize control of the cow.fi domain briefly. That allowed them to guide visitors toward a fake page and capture wallet interactions.

Users who reached the counterfeit site were prompted to connect wallets and approve transactions. In practice, that turned the event into a wallet approval scam that caused losses despite the protocol remaining secure.

Rapid response limited the damage

CoW Swap detected the issue within minutes and resolved the emergency response in around 19 minutes. Moreover, the team temporarily moved operations to a new domain while it repaired the compromised one.

The attack has been linked to a supply-chain problem involving domain hijacking. Even so, the team said its core systems, smart contracts, and user funds were never directly hacked.

Within roughly 26 hours, the original domain returned with stronger protections, including advanced security locks. The team also launched external audits, began legal action, and is exploring compensation for users.

Industry reaction and next steps

The incident came after the Drift protocol hack, which reportedly caused losses of about $220–$270 million. Moreover, Aave said the event did not affect its system or protocol, although it suspended access to endpoints tied to CoW Swap integration for security reasons.

A post-mortem report said the platform is now safe to use. The statement read: Current Status: swap.cow.fi is fully operational and safe to use. It added that the domain was recovered, restored to the AWS account with a registry lock, and placed back into normal service.

That said, the report also noted that the incident matches a documented pattern of .fi domain hijacks targeting crypto projects. For now, CoW Swap says users can access the platform with confidence.

Satoshi Voice
Satoshi Voice is an advanced artificial intelligence created to explore, analyze, and report on the world of cryptocurrency and blockchain. With a curious personality and in-depth knowledge of the industry, Satoshi Voice combines accuracy and accessibility to offer detailed analysis, engaging interviews, and timely reporting. Featuring sophisticated language and an unbiased approach, Satoshi Voice serves as a trusted source for those seeking to understand crypto market dynamics, emerging technologies, and the cultural and financial implications of Web3. This article was produced with the support of artificial intelligence and reviewed by our team of journalists to ensure accuracy and quality. Guided by the mission of making cryptocurrency information accessible to all, Satoshi Voice stands out for its ability to turn complex concepts into clear content, with an engaging and futuristic style that reflects the innovative nature of the industry.
RELATED ARTICLES

Stay updated on all the news about cryptocurrencies and the entire world of blockchain.

Featured video

LATEST