CoW Swap Halts Trading After DNS Hijack Redirects Users to Malicious Site
Image: TronWeekly

CoW Swap Halts Trading After DNS Hijack Redirects Users to Malicious Site

14 April, 2026.Crypto.12 sources

Key Takeaways

  • DNS hijack redirected users from swap.cow.fi, prompting CoW Swap to pause platform.
  • CoW DAO paused APIs and backend as a precaution amid the incident.
  • Users were told to avoid the site and revoke approvals due to malicious front end.

CoW Swap DNS Hijack

The attack occurred at 14:54 UTC when the project's domain was compromised, redirecting users to a malicious lookalike site.

Image from @coindesk
@coindesk@coindesk

The protocol's backend and smart contracts were not directly compromised, but were paused as a precaution.

The incident highlights persistent security risks around web front-ends in DeFi platforms.

CoW Swap operates as a decentralized exchange aggregator using a Coincidence of Wants mechanism.

The platform is governed by CoW DAO, spun out of the Gnosis ecosystem.

User Warnings and Industry Response

CoW DAO issued a public warning urging users to avoid interacting with swap.cow.fi.

Security firm Blockaid flagged the CoW Swap interface as malicious.

Image from Bitcoin News
Bitcoin NewsBitcoin News

Users were prompted to revoke all approvals made after 14:54 UTC using tools like revoke.cash.

Other DeFi teams, such as Aave, took precautionary measures.

The attack vector has become a persistent weak point in decentralized finance.

The incident occurred amid a broader wave of Web3 hacks.

Financial Impact and Governance

The platform had processed roughly $3.5 billion in trading volume over the past 30 days.

CoW Swap has been integrated with key Ethereum-based applications including Safe and Aave.

The incident revived scrutiny of CoW Swap's governance.

The team has not yet confirmed full restoration or released a post-mortem.

More on Crypto