CoW Swap has published a comprehensive report on a recent domain hijacking incident. According to Foresight News, the event was characterized as a supply chain attack, where the attacker used social engineering tactics targeting the .fi domain registry Traficom and registrar Gandi SAS. This allowed the attacker to redirect the domain's DNS to a Cloudflare server under their control, leading to phishing sites being served to users for several hours.
The CoW Protocol's smart contracts, backend API, solver network, and signature infrastructure remained unaffected, as the attack was confined to the domain registration supply chain level. The team detected the issue within 19 minutes and completed the service migration to cow.finance in approximately 3.5 hours. The domain was fully restored on April 15, with RegistryLock enabled. Preliminary analysis estimates user losses at around $1.2 million.