DeFi users, beware. Web3 security firm Blockaid posted a red alert on X, stating that the front-end website of decentralized exchange aggregator CoW Swap, cow.fi, has been hacked and flagged as a high-risk malicious site.
Blockaid: cow.fi Now a Malicious Site
According to Blockaid's community alert, its system detected a front-end attack on CoW Swap. This type of attack typically involves hackers hijacking the DNS or altering the webpage UI to replace legitimate smart contract addresses with phishing wallets or malicious contracts. If a user signs a transaction on such a site, their crypto assets can be drained instantly.
Blockaid explicitly states that cow.fi is now classified as malicious, and any interaction with it carries extreme risk.
Urgent Call: Disconnect and Revoke Approvals Immediately
In response to the security incident, Blockaid issued a strong warning to the crypto community with three steps:
- Stop interacting: Do not click any buttons on cow.fi or perform any signatures or transactions with the dApp.
- Revoke approvals: If your wallet is connected to the site or you have previously granted approvals, use a secure third-party tool like Revoke.cash to revoke all token approvals.
- Disconnect: Terminate the connection to cow.fi in your wallet settings.
As of now, the CoW Swap team has not announced any fix. Users should avoid accessing the site until the alert is lifted and the domain is confirmed safe.

