Cow Swap, the decentralized exchange aggregator built on Cow Protocol, temporarily halted protocol operations after attackers hijacked the DNS records for its main frontend, swap.cow.fi. According to the project’s public updates, the issue was detected at around 14:54 UTC on April 14, 2026, prompting an urgent warning for users to stop interacting with the website while the team investigated the scope of the incident.
Incident Timeline and Immediate Response
Cow DAO first warned the public at roughly 15:41 UTC, advising users not to connect wallets, sign transactions, or otherwise interact with the affected frontend. In a follow-up message at approximately 16:24 UTC, the team confirmed that the problem was a DNS hijacking incident. Although Cow Protocol’s backend systems and APIs were not initially confirmed to be compromised, the project still chose to pause them as a precautionary measure.
That decision reflected a familiar security playbook in decentralized finance. When the entry point used by retail users becomes suspect, teams often shut down adjacent services even if core infrastructure appears intact. The idea is simple: limit further exposure, preserve evidence, and reduce the risk that users continue interacting with a malicious interface while investigations are ongoing.
How DNS Hijacking Threatens DeFi Users
DNS hijacking is a known attack vector in DeFi and broader crypto infrastructure. Rather than exploiting a flaw in smart contract logic, attackers target domain-level controls and redirect legitimate traffic to a fraudulent or manipulated website. Once users arrive on the spoofed frontend, they may be prompted to connect their wallets, approve token spending, or sign malicious transactions that can lead to wallet drains.
These attacks are particularly dangerous because the user experience may appear almost identical to the legitimate product. In many cases, victims believe they are using the real interface, especially when the attack affects a trusted domain name rather than an obscure phishing link. That makes registrar security, DNS management, and access controls around web infrastructure just as important as smart contract audits.
What Was and Was Not Affected
Cow Protocol stated that smart contracts and onchain infrastructure were not touched in this incident. Because Cow Swap operates as a non-custodial platform, the protocol itself does not directly hold user funds in the same way a centralized exchange would. As a result, the primary risk did not stem from a protocol-wide compromise of treasury or custody systems.
Instead, the danger was concentrated among users who visited swap.cow.fi after 14:54 UTC and then signed approvals or transactions through the compromised frontend. In other words, the threat was tied to frontend interaction during the attack window, not to a breach of core contract architecture.
User Guidance: Revoke Approvals Immediately
In another update posted around 16:33 UTC, Cow DAO urged potentially affected users to review and revoke token approvals granted after the incident began. The team specifically pointed users to revoke.cash, a widely used tool for canceling token allowances and reducing the risk of unauthorized fund movement.
This guidance is standard but critical. In many frontend attacks, the most immediate damage comes not from a single transaction but from token approvals that grant broad access to an attacker-controlled address or malicious smart contract. Revoking those approvals as quickly as possible can help contain losses, especially if the compromise involved wallet drainer behavior rather than an instantly executed asset theft.
The team also asked users with suspicious activity to submit their transaction hashes for review, signaling that the investigation included case-by-case analysis of potentially affected wallet interactions.
No Confirmed Large-Scale Losses, but Monitoring Continued
As of the latest information available in the source material, Cow DAO had not confirmed any large-scale losses. Community members reportedly flagged isolated suspicious transactions, but there was no evidence of a broad systemic drain affecting the protocol as a whole. That distinction matters: isolated user-level impact through a malicious frontend is serious, but it is different from a compromise of smart contracts or protocol reserves.
Security platform Blockaid flagged swap.cow.fi and related domains, including cow.fi, during the incident window. Monitoring reportedly continued through around 18:15 UTC, while the team worked to assess exposure and determine when services could be safely restored.
Protocol Status and Pending Post-Mortem
At the time of the latest update, the protocol remained paused, and Cow DAO had not yet confirmed a full restoration of service. It also had not released a formal post-mortem. A more detailed incident report is expected once the DNS issue is fully resolved and the frontend is confirmed safe to use again.
For users and observers, that post-mortem will likely be important for understanding the exact chain of events: how the DNS records were altered, what protections were in place, how quickly the compromise was detected, and what new safeguards may follow. In incidents like this, remediation is not only technical but procedural, often involving registrar controls, internal access policies, and stronger verification around domain changes.
A Broader Warning for DeFi Infrastructure
The Cow Swap incident highlights a recurring weakness in DeFi: even when smart contracts remain secure, frontend and domain infrastructure can still become a point of failure. Recent attacks across the sector have shown that adversaries do not always need to break audited code. In many cases, compromising the user-facing layer is enough to inflict damage.
These incidents often involve weaknesses at the registrar or account-management level, such as social engineering against support staff, compromised credentials, or failures in two-factor authentication. The result is the same: users are routed to a trusted-looking destination that no longer serves the protocol safely.
Cow Protocol, part of the Gnosis ecosystem, is known for using batch auctions and Coincidence of Wants matching to provide MEV-protected trading. The protocol has processed billions of dollars in volume since launch, making any disruption to its interface notable for the broader market. While no contract-level exploit has been confirmed here, the episode serves as another reminder that DeFi security extends far beyond the blockchain itself.
Until the team confirms that the frontend is fully restored, the clearest takeaway for users is caution: avoid interacting with the affected domain, verify official communications carefully, and revoke any approvals granted during the risk window.

