A prominent decentralized exchange aggregator, CoW Swap, has temporarily suspended its services due to a domain name system hijacking incident that affected its website. The incident highlights the ongoing security vulnerabilities in the front-end layer of DeFi platforms.
According to a post by the team, the attack occurred at 14:54 UTC, prompting a warning to users to avoid interacting with the interface until further notice. Although the protocol's underlying infrastructure, including its backend and APIs, was not directly compromised, it has been paused as a precautionary measure while the team works to resolve the issue. DNS hijacking is a type of attack that allows hackers to redirect users from a legitimate domain to a fake site, often to steal cryptocurrency or sensitive information. This attack vector has become a significant weakness in decentralized finance, where users rely on web-based interfaces to access secure smart contracts.
CoW Swap functions as a decentralized exchange aggregator, sourcing liquidity from various venues and utilizing a 'Coincidence of Wants' mechanism to match trades directly between users or batch them for more efficient execution. The platform is designed to reduce slippage and limit exposure to maximal extractable value (MEV), a practice where bots reorder transactions to extract profits at users' expense.
CoW Swap is governed by CoW DAO, a decentralized autonomous organization that emerged from the Gnosis ecosystem. The project positions itself as a user-protective alternative in DeFi trading, emphasizing high-quality execution and fairer trading outcomes.
The team has advised users to refrain from using the swap.cow.fi website until it is confirmed to be safe.