Markmonitor retweetledi

CoW Swap went dark today. DNS hijack
what made it serious wasn't the site going down. it was what could've happened while it was up
DNS got redirected to a fake version of the site. looked identical. if you connected your wallet during that window, you weren't signing on @CoWSwap you were signing on something else
they told users to revoke approvals made after 14:54 UTC
backend was fine. APIs fine. the protocol itself didn't get touched
the hole was the frontend. and frontend runs on DNS
so i looked at what the protocols that haven't been hit do differently
@markmonitor - what stood out:
most registrars let you change DNS settings with just a login and an email confirmation. one link, one click, done
MarkMonitor has something called Registry Lock. even if someone gets into your account, they can't change DNS without a separate high-security verification at the registry level. two doors, not one
your team probably hasn't heard of it. DNS feels like infrastructure. it became an attack vector for CoW Swap users today
English
















