CoW Swap Hit by Front-End Attack as Blockaid Flags cow.fi as Malicious
CoW Swap is a decentralized exchange aggregator operated by CoW DAO that uses batch auctions and solvers to find better prices for users. It is also used by organizations including the Ethereum Foundation. The incident underscores that hackers do not necessarily need to breach smart contracts: hijacking an official domain can be enough to trick users into signing malicious transactions that drain assets directly from their wallets.
At 14:54 UTC on April 14, 2026, attackers used social engineering to compromise domain registrar Gandi SAS and controlled cow.fi for about 4.5 hours. Blockaid flagged the site as malicious. CoW DAO suspended its back end and API, said its smart contracts were unaffected, and told users to stop visiting the site and revoke any approvals added after 14:54. The team later estimated losses at about 1.2 million USDC.
All Coverage
4 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.