CoW DAO warned users on April 14, 2026 not to use CoW Swap after identifying a Domain Name System hijacking attack against `swap.cow.fi`. The compromise redirected visitors away from the legitimate decentralized-exchange interface, creating the risk that users would connect wallets or authorize transactions through a malicious site.
The DAO said the CoW Protocol backend and application programming interfaces were not compromised, but it temporarily paused them as a precaution. It also advised users to revoke approvals created through CoW Swap after 14:54 UTC on April 14. The project had not established a complete loss figure by the end of the date, so reports circulating during the incident could not yet support a definitive estimate of affected wallets or assets.
A web-layer attack on decentralized finance
The incident mattered because it separated the security of CoW Protocol’s on-chain contracts from the security of the website through which most users reached them. A decentralized settlement system can continue operating as designed while an attacker compromises the conventional internet infrastructure that directs users to its interface.
Blockaid issued a contemporaneous alert saying its monitoring system had identified a frontend attack and marked the `cow.fi` domain as malicious. That warning supported CoW DAO’s account that the danger was concentrated at the application-access layer rather than in the protocol contracts themselves.
This distinction reduced one category of uncertainty but did not eliminate user risk. A malicious interface can present deceptive wallet requests while preserving the appearance and address of a familiar service. Users therefore did not need to encounter a defect in CoW Protocol’s settlement code to face potential losses; they only needed to trust the domain and approve what the substituted interface presented.
Integrations extend the operational impact
CoW Swap also served as trading infrastructure for other decentralized-finance applications. Aave said on April 14 that the attack did not affect either the Aave Interface or Aave Protocol. It nevertheless noted that CoW Swap had disabled swap endpoints used by integrators, demonstrating how one project’s emergency response could remove functionality from otherwise unaffected applications.
That response was institutionally significant for decentralized finance. Protocols may be governed separately and deployed through distinct smart contracts, yet their user experiences often depend on shared interfaces, routing systems, cloud services and domain registrars. An incident outside the blockchain can consequently propagate as an availability problem across several applications even when their contracts and customer balances remain intact.
CoW DAO’s decision to pause services was therefore a containment measure, not evidence that its smart contracts had been exploited. By the end of April 14, the verified record supported three conclusions: the public frontend had been redirected through a DNS compromise; users were told to avoid it and revoke approvals made after the specified time; and backend services were paused despite the team’s statement that they had not been breached.
What remained unknown on April 14
The event-day record did not yet establish how the domain controls were taken, how long malicious content had been served, how many users had interacted with it or the value of any resulting losses. Those questions required registrar records, transaction analysis and victim reporting unavailable during the initial response.
Later context
In an April 16 post-mortem, CoW DAO attributed the domain takeover to social engineering involving the `.fi` registry and registrar and estimated approximately $1.2 million in user losses. Those findings clarify the incident but were not knowable on April 14 and should not be treated as part of the event-day loss assessment.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

