Blockchain security firm Blockaid has flagged CoW Swap’s main website, COW.FI, as malicious after detecting what it described as a frontend attack targeting the protocol. In a warning posted on X, the company said wallets integrated with Blockaid now mark the domain as unsafe and advised users not to sign transactions or interact with the dApp until the issue is fixed.
After the alert, CoW Swap community channels and independent security watchers told users who had previously connected wallets to the platform to revoke any active token approvals and stop using the frontend for now. At this stage, there has been no report that the underlying smart contracts were compromised. The concern centers on the interface users interact with, not the contracts running on-chain.
Frontend hijacks keep hitting DeFi interfaces
The incident lands in the middle of a broader run of frontend attacks across DeFi. In these cases, attackers target a project’s website or DNS instead of breaking the protocol’s contracts, then replace legitimate transaction prompts with malicious ones. A routine signature can become a wallet-draining action. The contracts may still be intact. The user can still lose everything in that session.
Blockaid pointed to a similar case from February involving tokenization platform OpenEden, where users were also told to avoid signing transactions and stop interacting with the dApp until the situation was resolved. Separate incidents have also affected lending protocol Curvance and asset manager Maple Finance, showing that major DeFi interfaces are staying under pressure.
Revoking approvals limits future access, not past losses
CoW Swap’s own DeFi security guidance says these attacks often go after “people, devices, and transaction behavior” rather than code alone. That makes basic operating hygiene important: checking URLs carefully, using bookmarks for frequently visited protocols, and reviewing token approvals on a regular basis. These are simple steps, but they matter most when the interface itself cannot be trusted.
Security services such as Kerberus and revoke tools have long advised users to audit and remove token approvals after any suspicious event. That step has limits. Revocation only strips a contract of permission to move tokens in the future; it does not recover funds that have already been drained. For DeFi traders, the CoW Swap case is another reminder that an audited protocol can still expose users to severe loss if a compromised frontend tricks them into signing the wrong transaction.

