# CoW DAO Approves $1.2M Payouts for April Phishing Attack Victims

**Published:** 2026-05-11T18:33:19.000Z  
**Topic:** Dao Crypto  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/30a9ac70-1451-42b7-a739-da9fca47cb60

CoW DAO approved CIP-86 to compensate users up to 100% for $1.2 million lost in an April 14 domain hijack. Claims are due May 14, with payouts by May 31.

CoW DAO has approved governance proposal CIP-86, establishing a discretionary fund to reimburse users who lost an estimated $1.2 million in a phishing attack on April 14 [2, 3]. Affected users must submit claims by May 14 to receive compensation, with payouts expected to begin May 21 and conclude by May 31 [1, 2].

The incident occurred when attackers used social engineering against CoW Swap's domain registrar, Gandi SAS, to briefly control the cow.fi domain for about 4.5 hours [1, 2]. During this window, visitors were redirected to a phishing website that mimicked the official interface, tricking them into signing malicious transactions that drained assets like USDC from their wallets [2, 3]. CoW DAO emphasized that the CoW Protocol's smart contracts and backend infrastructure were not compromised; the vulnerability was entirely at the domain registrar layer [1, 3]. Security firm Blockaid issued an early warning, flagging cow.fi as malicious [2].

CIP-86 authorizes "ex gratia" payments from CoW DAO's Legal Defense Reserve, meaning the compensation is a goodwill gesture and not an admission of legal liability [2, 3]. The proposal allows for up to 100% reimbursement for verified losses [3]. To claim, users must email help@cow.fi with the subject "Discretionary Grant Claim for CoW.Fi Domain Hijack Incident," including their affected wallet address, asset information, transaction hashes, and full name [1, 2]. CoW DAO has hired an external firm for identity verification, and eligible claimants will receive a secure KYC link after initial review [2].

This approach follows a pattern seen in other DeFi projects that have compensated users for frontend incidents even when core protocols remained secure [2]. The decision highlights how DAOs may prioritize community trust and reputation by using treasury funds for voluntary compensation, despite the added friction of KYC requirements for claimants [2]. The process for verifying and reimbursing claims is set to conclude by May 31 [2, 3].

## Sources
1. Chaincatcher — [The user compensation plan for the CoW DAO... - ChainCatcher](https://www.chaincatcher.com/en/article/2264035)
2. Daotimes — [CoW DAO Passes CIP-86 To Compensate Victims of the April DNS...](https://daotimes.com/cow-dao-passes-cip-86-to-compensate-victims-of-the-april-dns-hijack/)
3. Crypto — [CoW DAO approves compensation for cow.fi hijack victims, claims...](https://crypto.news/cow-dao-approves-compensation-for-cow-fi-hijack-victims-claims-due-may-14/)
4. CoinMarketCap — [Latest CoW Protocol News - (COW) Future Outlook, Trends & Market...](https://coinmarketcap.com/cmc-ai/cow-protocol/latest-updates/)

---
Cite as: TrendWatcher, "CoW DAO Approves $1.2M Payouts for April Phishing Attack Victims", https://www.trendwatcher.in/article/30a9ac70-1451-42b7-a739-da9fca47cb60
