CoW Swap warns users after front-end DNS hijack
CoW Swap warns users to avoid its frontend after a DNS hijack. Revoke wallet approvals and do not use swap.cow.fi until resolved. Backend and APIs are unaffected.
CoW Swap has issued urgent warnings after detecting a front-end attack targeting its cow.fi domain. Security firm Blockaid identified the incident as a DNS hijacking, labeling the site as malicious. Users are advised to immediately revoke wallet approvals and avoid interacting with the application. CoW Swap confirmed that the backend and APIs were not impacted but have been paused temporarily as a precaution. The attack appears limited to the frontend interface, with no evidence of compromise to the underlying protocol or smart contracts. Other ecosystem participants, including Aave, acknowledged the situation and confirmed their systems remain unaffected. Users should avoid swap.cow.fi until an official resolution is announced and monitor their wallets for suspicious activity. The investigation is ongoing, with updates to follow.