CoW Swap Pauses Operations After Front-End Compromise
- CoW Swap, an Ethereum-based decentralized exchange aggregator, warned users against interacting with its protocol due to a front-end compromise.
- Cybersecurity researcher Vladimir S. estimated that approximately $500,000 in digital assets were stolen from users’ accounts.
- The attack did not impact CoW Swap’s underlying smart contracts, but the protocol was paused as a precautionary measure.
- Vitalik Buterin, co-founder of Ethereum, had used CoW Swap for transactions as recently as a week ago.
- Martin Köppelmann, CEO of Gnosis, noted that only users who approved interactions with CoW Swap recently are potentially affected.
CoW Swap’s front-end interface was compromised by attackers who redirected users to malicious websites for unauthorized fund transfers. The incident highlights vulnerabilities in decentralized finance platforms where domain security is critical.
Despite the attack affecting the front-end only and not the smart contracts, significant losses have been reported by users totaling around $500,000 so far. (Source)