CoW DAO proposes compensation for victims of the cow.fi domain hijacking, with up to 100% reimbursement of losses

COW-1,71%
USDC0,01%

CoW DAO賠付損失

CoW DAO on April 23 published a compensation proposal (CIP) on the governance forum, suggesting the establishment of a discretionary compensation program to provide up to 100% loss reimbursement to victims of the April 14 cow.fi domain hijacking incident. The incident is estimated to have caused user losses of about US$1.2 million in USDC. CoW DAO emphasized that the compensation is of a discretionary, voluntarily disbursed nature and does not indicate any admission of legal liability.

Event Recap: How a 4.5-hour domain hijacking led to a $1.2 million loss

CoW DAO補償方案

(Source: CoW DAO)

On April 14, 2026, the domain registrar Gandi SAS used by CoW Swap’s DNS servers (AWS Route 53) was subjected to a social engineering attack. The hackers used this vulnerability to control the cow.fi domain for about 4.5 hours, setting up a phishing website to trick visitors into signing malicious transactions and stealing wallet tokens. CoW DAO emphasized that the CoW Swap protocol itself was not attacked by the hackers; the vulnerability existed at the domain registrar layer rather than in the protocol code.

Compensation Eligibility Criteria and Application Process

There are three core eligibility conditions:

Used CoW Swap: The wallet must have conducted at least one transaction on CoW Swap before the incident

Signed a specific malicious transaction: The wallet owner must be someone who signed malicious messages or transactions related to the phishing website’s specific drain contract (Note: users who entered a mnemonic phrase are not included here)

Completed KYC verification: Must pass the identity verification process (KYC information will be destroyed within 30 days after compensation is paid)

Victims need to send an email to help@cow.fi by May 14, with the subject “CoW.Fi domain hijacking incident discretionary compensation claim,” and the body including the affected wallet address(es), the specific assets that were stolen, and the wallet owner’s name.

Key Timeline and Legal Statement

Full timeline: April 30 to May 7 (governance vote) → May 14 (application deadline) → May 21 (claim verification completed) → May 31 (all compensation fully disbursed). After the compensation program ends, the finance team will additionally fund a legal defense reserve authorized up to US$5 million. CoW DAO stated that this compensation is a one-time, isolated measure and does not set a precedent for using the legal defense reserve for purposes outside the primary defensive scope in the future.

Frequently Asked Questions

How can I confirm whether I am eligible for compensation?

You must meet three conditions: you conducted a transaction on CoW Swap before the incident; you signed a malicious transaction related to the phishing website’s specific drain contract from that day; and you completed KYC verification. You can submit an application to help@cow.fi before the May 14 deadline, and the core team will compare on-chain data to verify it.

Can users who entered their wallet mnemonic phrase apply for compensation?

No. CoW DAO clearly points out that users whose mnemonics were exposed via websites requesting the mnemonic phrase are not within the scope of this compensation, because this kind of scam does not involve a phishing attack impersonating CoW Swap and does not fall under the category of victims of this domain hijacking incident.

Does accepting compensation mean waiving legal claims against CoW DAO?

According to the compensation terms, users who accept compensation agree that, to the maximum extent permitted under applicable law, the payment will ultimately resolve all related claims against CoW DAO arising from this specific incident. CoW DAO also states that any rights that cannot be waived under the law will not be affected by this clause.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

B.AI Upgrades Infrastructure, Launches Major Skills Features

Gate News message, April 27 — B.AI announced multiple product and ecosystem advancements this week. The BAIclaw landing page received a complete visual and interaction overhaul, with website multilingual support expanded to 10 languages, strengthening its global usability. On the infrastructure

GateNews1h ago

JUST Releases Q1 2026 Results: $60M in Token Buybacks, JustLend DAO TVL Hits $6.91B

Gate News message, April 27 — JUST has released its Q1 2026 financial results, showing strong growth across key metrics. The project burned 1.356 billion JST tokens (13.70% of total supply) through cumulative buybacks worth $60.03 million, driving significant deflationary pressure. JustLend DAO's t

GateNews1h ago

AI Agents Drive Crypto Payments Demand, x402 Processes 165M Transactions

Gate News message, April 27 — Jesse Pollak, an executive at a major CEX, has argued that autonomous AI agents are creating a new "demand center" for crypto payments, requiring software-native payment infrastructure. On April 20, it was announced that the x402 ecosystem had processed more than 165

GateNews2h ago

Developer Proposes Bitcoin Hard Fork to eCash With 1:1 Distribution, Sparks Debate Over Satoshi Address Allocation

Gate News message, April 27 — Developer Paul Sztorc has proposed a Bitcoin hard fork scheduled for August 2026 at block height 964,000 to create a new blockchain called eCash, according to CoinDesk. The fork will distribute eCash to users holding BTC at a 1:1 ratio and introduce Drivechains

GateNews3h ago

Western Union Remittance Q1 earnings call confirms: USDPT stablecoin launches in early May

According to remarks made by Western Union President and CEO Devin McGranahan during the company’s first-quarter earnings call on April 24, Western Union confirmed that its USDPT stablecoin is currently in the final preparation stage and is expected to go live in May.

MarketWhisper4h ago

Justin Sun calls TRON the world’s first post-quantum attack-resistant network, with the mainnet going live in Q3 of 2026.

TRON founder Justin Sun announced on X on April 26 that TRON plans to enable anti-quantum attack functionality on the testnet in the second quarter, with a mainnet launch planned for the third quarter. In the post, Justin Sun referred to this upgrade plan as “the world’s first anti-quantum attack network.” Although quantum threats are still largely theoretical for now, Ethereum, Solana, and others have already published post-quantum cryptography (PQC) upgrade plans or timelines.

MarketWhisper4h ago
Comment
0/400
No comments