CoW DAO approved CIP‑86 to offer discretionary grants of up to 100% to victims of April’s cow.fi domain hijack, with detailed claims due by May 14 and payouts targetedCoW DAO approved CIP‑86 to offer discretionary grants of up to 100% to victims of April’s cow.fi domain hijack, with detailed claims due by May 14 and payouts targeted

CoW DAO approves compensation for cow.fi hijack victims, claims due May 14

2026/05/12 02:30
4분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

CoW DAO approved CIP‑86 to offer discretionary grants of up to 100% to victims of April’s cow.fi domain hijack, with detailed claims due by May 14 and payouts targeted by May 31.

Summary
  • CIP‑86 sets up a one‑off discretionary grants program from CoW DAO’s Legal Defense Reserve, aiming to reimburse verified cow.fi hijack victims up to 100% without admitting legal liability.
  • The April 14 attack exploited social engineering at registrar Gandi SAS to hijack cow.fi DNS for 4.5 hours, redirecting users to a phishing UI that drained about $1.2m in USDC and other tokens.
  • Eligible users must email [email protected] by May 14 with wallet, assets, tx hashes and ID; claims will be verified on‑chain and, if approved, reimbursed by May 31, possibly after KYC checks.

CoW DAO has formally approved a user compensation plan for victims of April’s cow.fi domain hijacking and is now asking affected users to file claims by May 14. The decision follows a community vote on governance proposal CIP‑86, which establishes a discretionary grants program to reimburse losses of up to 100% for users who were phished while the project’s domain registrar was under attacker control.

Social engineering at the registrar layer

According to the CIP‑86 proposal and the DAO’s post‑mortem, the incident occurred on April 14, 2026, when CoW Swap’s .fi domain registrar, Gandi SAS, was compromised in a social engineering attack. Attackers exploited the registrar’s controls over DNS records used by CoW Swap’s AWS Route 53 servers, briefly taking over the cow.fi domain for approximately 4.5 hours and redirecting users to a phishing website that mimicked the real interface.

During that window, users who visited the hijacked domain were served a fake trading UI and tricked into signing malicious transactions, which drained tokens from their wallets. CoW DAO has repeatedly stressed that CoW Protocol’s smart contracts and backend infrastructure were never breached, and that the vulnerability was “entirely at the domain registrar layer rather than in protocol code.” A KuCoin incident report estimated user losses at roughly $1.2 million in USDC and other assets, a figure echoed by multiple follow‑up analyses.

CIP‑86: discretionary grants and strict criteria

To address those losses, CoW DAO’s community approved CIP‑86, which sets up a one‑time discretionary grants program funded from the DAO’s Legal Defense Reserve. Under the plan, eligible victims can receive up to 100% compensation for verified losses, but the DAO emphasizes that payments are voluntary “goodwill” grants and do not constitute an admission of legal liability. The proposal also gives the core team a mandate to pursue legal action against third parties where necessary, including entities involved in the registrar supply‑chain attack.

CIP‑86 lays out strict criteria for relief grants. Claimants must have interacted with the malicious contract during the hijack window, demonstrate a history of using CoW Swap prior to the attack, and provide sufficient on‑chain evidence to link their losses to the phishing incident rather than unrelated scams. A Binance‑hosted summary notes that claims will be processed as “discretionary grants” rather than automatic reimbursements, with the verification process comparing submitted data to on‑chain records before any payout is authorized.

Claim process and May 14 deadline

CoW DAO and its ecosystem channels are now urging affected users to file claims before the May 14 cutoff. To qualify, users must send an email to [email protected] with the subject line “Discretionary Grant Claim for CoW.Fi Domain Hijack Incident,” including the affected wallet address, a list of assets and amounts drained, relevant transaction hashes, and the claimant’s name. Once support staff match the request with on‑chain data, users will receive a follow‑up email outlining any additional steps, which may include KYC checks before funds are released.

The CIP‑86 timeline anticipates that all valid claims will be submitted by May 14, reviewed over the following weeks, and reimbursed by May 31, subject to DAO treasury and verification outcomes. For CoW DAO, the episode has become a case study in how DeFi protocols can respond to off‑chain supply‑chain attacks: by treating domain‑level security as critical infrastructure, separating protocol integrity from web‑layer exploits, and using governance to authorize voluntary, time‑boxed compensation without rewriting history on-chain.

시장 기회
카우 프로토콜 로고
카우 프로토콜 가격(COW)
$0.1889
$0.1889$0.1889
+1.66%
USD
카우 프로토콜 (COW) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

KAIO Global Debut

KAIO Global DebutKAIO Global Debut

Enjoy 0-fee KAIO trading and tap into the RWA boom