CoW Swap Hack

TOTAL LOST $180K
Low Access Control Attacks ethereum

What happened

On Feb. 7, the CoW Swap fee manager contract was drained of worth 160k $USD.

The CoW Swap uses external resolvers for swap routing to find the best exchange way. The solver also receives a protocol fee. granted approval for the malicious contract.

27 Feb the malicious contract was approved by the whitelisted solver. After that, the hacker received an opportunity to drain the fee collector contract.

Exploit TX:

https://etherscan.io/tx/0x90b46860…24379b

Malicious call:

https://etherscan.io/tx/0x92f906bc…b3bfc1

Exploiter:

https://etherscan.io/address/0xc0e82c1e…5266ff

https://etherscan.io/address/0x94b6f400…95658c

Case & protocol details

Classification Exchange (DEX) / Access Control
Protocol Type Exploit/Other
Smart Contract Language Solidity
Official Website cow.fi/
Protocol Twitter/X @CoWSwap

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.