CoW DAO proposes compensation for victims of the cow.fi domain hijacking, with up to 100% reimbursement of losses

COW-2,38%
USDC0,01%

CoW DAO賠付損失

CoW DAO on April 23 published a compensation proposal (CIP) on the governance forum, suggesting the establishment of a discretionary compensation program to provide up to 100% loss reimbursement to victims of the April 14 cow.fi domain hijacking incident. The incident is estimated to have caused user losses of about US$1.2 million in USDC. CoW DAO emphasized that the compensation is of a discretionary, voluntarily disbursed nature and does not indicate any admission of legal liability.

Event Recap: How a 4.5-hour domain hijacking led to a $1.2 million loss

CoW DAO補償方案

(Source: CoW DAO)

On April 14, 2026, the domain registrar Gandi SAS used by CoW Swap’s DNS servers (AWS Route 53) was subjected to a social engineering attack. The hackers used this vulnerability to control the cow.fi domain for about 4.5 hours, setting up a phishing website to trick visitors into signing malicious transactions and stealing wallet tokens. CoW DAO emphasized that the CoW Swap protocol itself was not attacked by the hackers; the vulnerability existed at the domain registrar layer rather than in the protocol code.

Compensation Eligibility Criteria and Application Process

There are three core eligibility conditions:

Used CoW Swap: The wallet must have conducted at least one transaction on CoW Swap before the incident

Signed a specific malicious transaction: The wallet owner must be someone who signed malicious messages or transactions related to the phishing website’s specific drain contract (Note: users who entered a mnemonic phrase are not included here)

Completed KYC verification: Must pass the identity verification process (KYC information will be destroyed within 30 days after compensation is paid)

Victims need to send an email to help@cow.fi by May 14, with the subject “CoW.Fi domain hijacking incident discretionary compensation claim,” and the body including the affected wallet address(es), the specific assets that were stolen, and the wallet owner’s name.

Key Timeline and Legal Statement

Full timeline: April 30 to May 7 (governance vote) → May 14 (application deadline) → May 21 (claim verification completed) → May 31 (all compensation fully disbursed). After the compensation program ends, the finance team will additionally fund a legal defense reserve authorized up to US$5 million. CoW DAO stated that this compensation is a one-time, isolated measure and does not set a precedent for using the legal defense reserve for purposes outside the primary defensive scope in the future.

Frequently Asked Questions

How can I confirm whether I am eligible for compensation?

You must meet three conditions: you conducted a transaction on CoW Swap before the incident; you signed a malicious transaction related to the phishing website’s specific drain contract from that day; and you completed KYC verification. You can submit an application to help@cow.fi before the May 14 deadline, and the core team will compare on-chain data to verify it.

Can users who entered their wallet mnemonic phrase apply for compensation?

No. CoW DAO clearly points out that users whose mnemonics were exposed via websites requesting the mnemonic phrase are not within the scope of this compensation, because this kind of scam does not involve a phishing attack impersonating CoW Swap and does not fall under the category of victims of this domain hijacking incident.

Does accepting compensation mean waiving legal claims against CoW DAO?

According to the compensation terms, users who accept compensation agree that, to the maximum extent permitted under applicable law, the payment will ultimately resolve all related claims against CoW DAO arising from this specific incident. CoW DAO also states that any rights that cannot be waived under the law will not be affected by this clause.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

AI Agents Drive Crypto Payments Demand, x402 Processes 165M Transactions

Gate News message, April 27 — Jesse Pollak, an executive at a major CEX, has argued that autonomous AI agents are creating a new "demand center" for crypto payments, requiring software-native payment infrastructure. On April 20, it was announced that the x402 ecosystem had processed more than 165

GateNews1h ago

Developer Proposes Bitcoin Hard Fork to eCash With 1:1 Distribution, Sparks Debate Over Satoshi Address Allocation

Gate News message, April 27 — Developer Paul Sztorc has proposed a Bitcoin hard fork scheduled for August 2026 at block height 964,000 to create a new blockchain called eCash, according to CoinDesk. The fork will distribute eCash to users holding BTC at a 1:1 ratio and introduce Drivechains

GateNews1h ago

Western Union Remittance Q1 earnings call confirms: USDPT stablecoin launches in early May

According to remarks made by Western Union President and CEO Devin McGranahan during the company’s first-quarter earnings call on April 24, Western Union confirmed that its USDPT stablecoin is currently in the final preparation stage and is expected to go live in May.

MarketWhisper2h ago

Justin Sun calls TRON the world’s first post-quantum attack-resistant network, with the mainnet going live in Q3 of 2026.

TRON founder Justin Sun announced on X on April 26 that TRON plans to enable anti-quantum attack functionality on the testnet in the second quarter, with a mainnet launch planned for the third quarter. In the post, Justin Sun referred to this upgrade plan as “the world’s first anti-quantum attack network.” Although quantum threats are still largely theoretical for now, Ethereum, Solana, and others have already published post-quantum cryptography (PQC) upgrade plans or timelines.

MarketWhisper2h ago

DeFi United’s crowdfunding campaign raises 102,000+ ETH, with AAVE rebounding to $100

According to the official DeFi United page, the multi-protocol relief fund DeFi United, initiated and led by Aave service providers, has raised more than 102k ETH as of April 27. The goal is to cover the bad-debt shortfall created in the Aave V3 market after the April 18 Kelp DAO cross-chain bridge attack incident. AAVE briefly broke above $100 before falling back.

MarketWhisper3h ago

Vcitychain DPoS Mainnet Goes Live with Self-Developed Consensus System

Gate News message, April 27 — Vcitychain, a commercial-grade blockchain, officially launched its DPoS mainnet today, transitioning to a self-developed Delegated Proof of Stake (DPoS) consensus system. The upgrade aims to enhance network performance, increase decentralization, and improve on-chain g

GateNews3h ago
Comment
0/400
No comments