Blockaid Flags CoW Swap Frontend as Malicious, Urges Users to Avoid COW.FI

Blockaid Flags CoW Swap Frontend as Malicious, Urges Users to Avoid COW.FI

N
News Editor 01
2026-07-23 11:50:16
Blockaid warned that CoW Swap’s main site COW.FI may have been hit by a frontend attack, telling users to stop signing transactions and revoke token approvals if they had connected wallets.
CoW SwapBlockaidDeFi securityfrontend attacktoken approvals

Blockchain security firm Blockaid has flagged CoW Swap’s main website, COW.FI, as malicious after detecting what it described as a frontend attack targeting the protocol. In a warning posted on X, the company said wallets integrated with Blockaid now mark the domain as unsafe and advised users not to sign transactions or interact with the dApp until the issue is fixed.

After the alert, CoW Swap community channels and independent security watchers told users who had previously connected wallets to the platform to revoke any active token approvals and stop using the frontend for now. At this stage, there has been no report that the underlying smart contracts were compromised. The concern centers on the interface users interact with, not the contracts running on-chain.

Frontend hijacks keep hitting DeFi interfaces

The incident lands in the middle of a broader run of frontend attacks across DeFi. In these cases, attackers target a project’s website or DNS instead of breaking the protocol’s contracts, then replace legitimate transaction prompts with malicious ones. A routine signature can become a wallet-draining action. The contracts may still be intact. The user can still lose everything in that session.

Blockaid pointed to a similar case from February involving tokenization platform OpenEden, where users were also told to avoid signing transactions and stop interacting with the dApp until the situation was resolved. Separate incidents have also affected lending protocol Curvance and asset manager Maple Finance, showing that major DeFi interfaces are staying under pressure.

Revoking approvals limits future access, not past losses

CoW Swap’s own DeFi security guidance says these attacks often go after “people, devices, and transaction behavior” rather than code alone. That makes basic operating hygiene important: checking URLs carefully, using bookmarks for frequently visited protocols, and reviewing token approvals on a regular basis. These are simple steps, but they matter most when the interface itself cannot be trusted.

Security services such as Kerberus and revoke tools have long advised users to audit and remove token approvals after any suspicious event. That step has limits. Revocation only strips a contract of permission to move tokens in the future; it does not recover funds that have already been drained. For DeFi traders, the CoW Swap case is another reminder that an audited protocol can still expose users to severe loss if a compromised frontend tricks them into signing the wrong transaction.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.