Particle.news

Blockaid Flags CoW Swap Website as Malicious in DNS Hijack

The case highlights the user risk from hacked DeFi websites that replace transaction prompts to steal funds.

Overview

  • Blockaid said Tuesday it detected a front‑end attack on CoW Swap and marked the cow.fi site as malicious.
  • CoW Swap confirmed a DNS hijack of its website and told users not to use the app while the team investigates.
  • The project said its smart contracts and APIs were not breached and paused backend services as a safety step.
  • Users who connected wallets are urged to revoke any new token approvals using tools like revoke.cash to block future unauthorized transfers.
  • A DNS hijack can redirect a real domain to a fake interface, a tactic seen recently at OpenEden, Curvance, and Maple Finance.