A prominent decentralized trading platform, CoW Swap, has announced the temporary suspension of its services following the detection of a domain name system (DNS) hijacking incident. This type of attack enables malicious actors to redirect users from a legitimate website to a fake one, often with the intention of stealing cryptocurrency or sensitive information. The incident highlights the ongoing security risks associated with the front-end layer of DeFi platforms. According to a post by the team, the attack occurred at 14:54 UTC, and users are advised to avoid interacting with the platform's interface until the issue is resolved.
Although the protocol's underlying infrastructure, including its backend and APIs, was not directly compromised, it has been paused as a precautionary measure. CoW Swap functions as a decentralized exchange aggregator, sourcing liquidity from various venues and utilizing a 'Coincidence of Wants' mechanism to facilitate direct trades between users or batch them for more efficient execution.
The platform's design aims to minimize slippage and limit exposure to maximal extractable value (MEV), a practice where bots reorder transactions to extract profits at users' expense. CoW Swap is governed by CoW DAO, a decentralized autonomous organization that emerged from the Gnosis ecosystem, and has positioned itself as a user-protective alternative in DeFi trading, emphasizing high-quality execution and fairer trading outcomes. The team has assured that they are actively working to resolve the situation and has warned users to refrain from using the swap.cow.fi website until it is confirmed safe.