{"id":21551,"date":"2026-04-16T15:31:53","date_gmt":"2026-04-16T15:31:53","guid":{"rendered":"https:\/\/www.coinspeaker.com\/fr\/?p=21551"},"modified":"2026-04-16T10:41:26","modified_gmt":"2026-04-16T10:41:26","slug":"cow-swap-suspend-son-protocole-apres-la-compromission-de-son-site-web","status":"publish","type":"post","link":"https:\/\/www.coinspeaker.com\/fr\/cow-swap-suspend-son-protocole-apres-la-compromission-de-son-site-web\/","title":{"rendered":"CoW Swap suspend son protocole apr\u00e8s la compromission de son site web"},"content":{"rendered":"<p>CoW Swap, l&rsquo;agr\u00e9gateur d&rsquo;\u00e9changes d\u00e9centralis\u00e9s bas\u00e9 sur Ethereum, a suspendu son protocole le 14 avril 2026, apr\u00e8s que des attaquants ont pris le contr\u00f4le du domaine de son site web et redirig\u00e9 les utilisateurs vers un site malveillant con\u00e7u pour siphonner les approbations de portefeuilles.<\/p>\n<p>Le chercheur en cybers\u00e9curit\u00e9 Vladimir S. estime qu&rsquo;environ 500 000 USD d&rsquo;actifs num\u00e9riques ont \u00e9t\u00e9 d\u00e9rob\u00e9s, au moins un utilisateur ayant signal\u00e9 des pertes individuelles d\u00e9passant 50 000 USD.<\/p>\n<p>Les contrats intelligents sous-jacents et les API backend du protocole ont \u00e9t\u00e9 confirm\u00e9s comme non affect\u00e9s ; la surface d&rsquo;attaque se limitait \u00e0 la seule interface front-end.<\/p>\n<p>Nous soup\u00e7onnons qu&rsquo;il s&rsquo;agit moins d&rsquo;une faille sp\u00e9cifique \u00e0 la posture de s\u00e9curit\u00e9 de CoW Swap que d&rsquo;un signal structurel sur l&rsquo;exposition persistante et sous-estim\u00e9e du secteur DeFi aux attaques d&rsquo;infrastructure de la couche UI \u2014 un vecteur de menace que les audits de contrats intelligents ne couvrent pas.<\/p>\n<h2>Compromission du front-end de CoW Swap : d\u00e9tournement de DNS, approbations malveillantes et confirmations du protocole<\/h2>\n<p>Le m\u00e9canisme fonctionne comme suit : les attaquants ont obtenu le contr\u00f4le administratif du domaine du site web de CoW Swap \u2014 l&rsquo;adresse cow.fi vers laquelle les utilisateurs naviguent avant d&rsquo;interagir avec le protocole \u2014 et ont redirig\u00e9 ce domaine vers un site malveillant con\u00e7u pour imiter l&rsquo;interface l\u00e9gitime.<\/p>\n<p>Les utilisateurs ayant visit\u00e9 le site et sign\u00e9 des approbations de transactions durant la fen\u00eatre suivant 14h54 UTC le 14 avril ont \u00e9t\u00e9 expos\u00e9s \u00e0 des transferts de vidage de portefeuille, sans aucune indication au niveau du domaine que quelque chose d&rsquo;anormal se produisait.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"474\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">UPDATE: The swap dot cow dot fi domain is currently locked and not accessible. We are working with security experts to assert control over the domain while it is locked, but we *do not* expect it to be live again tonight.<\/p>\n<p>For those who rely on CoW Swap daily, we have spun up a\u2026 <a rel=\"noopener noreferrer\" target=\"_blank\" rel=\"noopener nofollow sponsored\" href=\"https:\/\/t.co\/gtoeMfxYEy\">https:\/\/t.co\/gtoeMfxYEy<\/a><\/p>\n<p>&mdash; CoW DAO (@CoWSwap) <a rel=\"noopener noreferrer\" target=\"_blank\" rel=\"noopener nofollow sponsored\" href=\"https:\/\/twitter.com\/CoWSwap\/status\/2044168242743390364?ref_src=twsrc%5Etfw\">April 14, 2026<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>La soci\u00e9t\u00e9 de s\u00e9curit\u00e9 blockchain Blockaid a d\u00e9tect\u00e9 et signal\u00e9 l&rsquo;activit\u00e9 malveillante sur le domaine cow.fi, l&rsquo;identifiant comme une attaque front-end capable de tromper les utilisateurs pour leur faire signer des transactions de drainage.<\/p>\n<p>L&rsquo;\u00e9quipe de CoW Swap a confirm\u00e9 la situation dans une d\u00e9claration publique : \u00ab Nous travaillons activement \u00e0 la r\u00e9solution de la situation. Le backend et les API du protocole CoW n&rsquo;ont pas \u00e9t\u00e9 impact\u00e9s, mais nous les avons temporairement suspendus par mesure de pr\u00e9caution. \u00bb<\/p>\n<p>MooKeeper, un membre pseudonyme de l&rsquo;\u00e9quipe CoW Swap, a pr\u00e9cis\u00e9 que l&rsquo;ampleur des pertes fait l&rsquo;objet d&rsquo;une enqu\u00eate active et qu&rsquo;une \u00e9valuation plus compl\u00e8te suivra, ajoutant : \u00ab Nous avons la preuve qu&rsquo;un petit nombre d&rsquo;utilisateurs ont sign\u00e9 des approbations malveillantes pour de tr\u00e8s petits montants. \u00bb<\/p>\n<p>Cette caract\u00e9risation entre en contradiction avec l&rsquo;estimation on-chain de Vladimir S., qui \u00e9value \u00e0 500 000 USD les fonds drain\u00e9s sur plusieurs adresses \u2014 un chiffre qui, selon certains rapports, pourrait approcher le million de dollars dans les trois heures suivant la divulgation de l&rsquo;attaque, bien que ce chiffre plus \u00e9lev\u00e9 n&rsquo;ait pas \u00e9t\u00e9 confirm\u00e9 de mani\u00e8re ind\u00e9pendante.<\/p>\n<p>Il est n\u00e9cessaire de souligner que plusieurs d\u00e9tails restent au stade de l&rsquo;estimation : le montant total pr\u00e9cis des fonds vol\u00e9s, l&rsquo;identit\u00e9 des attaquants et la liste compl\u00e8te des portefeuilles affect\u00e9s ne sont pas encore confirm\u00e9s publiquement au moment de la r\u00e9daction.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"474\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">The CoW Swap frontend is back up at <a rel=\"noopener noreferrer\" target=\"_blank\" rel=\"noopener nofollow sponsored\" href=\"https:\/\/t.co\/428UojJIdq\">https:\/\/t.co\/428UojJIdq<\/a>. <\/p>\n<p>Make sure you only sign approvals to 0xc92e8bdf79f0507f65a392b0ab4667716bfe0110 (the original GPv2VaultRelayer contract) <a rel=\"noopener noreferrer\" target=\"_blank\" rel=\"noopener nofollow sponsored\" href=\"https:\/\/t.co\/phQqIbzPAR\">https:\/\/t.co\/phQqIbzPAR<\/a><\/p>\n<p>&mdash; Felix Leupold (@fleupold_) <a rel=\"noopener noreferrer\" target=\"_blank\" rel=\"noopener nofollow sponsored\" href=\"https:\/\/twitter.com\/fleupold_\/status\/2044173375023501690?ref_src=twsrc%5Etfw\">April 14, 2026<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>CoW DAO a conseill\u00e9 \u00e0 tous les utilisateurs de r\u00e9voquer toute approbation accord\u00e9e \u00e0 CoW Swap apr\u00e8s 14h54 UTC le 14 avril, recommandant l&rsquo;utilisation d&rsquo;outils tels que revoke.cash pour ce processus.<\/p>\n<p>Martin K\u00f6ppelmann, cofondateur et PDG du fournisseur d&rsquo;infrastructure d\u00e9centralis\u00e9e Gnosis, a not\u00e9 que l&rsquo;exposition semble limit\u00e9e aux utilisateurs ayant approuv\u00e9 des interactions avec le protocole durant les quelques heures o\u00f9 le domaine compromis \u00e9tait actif.<\/p>\n<p>De son c\u00f4t\u00e9, Aave a d\u00e9sactiv\u00e9 les points de terminaison CoW Swap pour ses int\u00e9grateurs par mesure de pr\u00e9caution, confirmant que sa propre interface et son protocole n&rsquo;\u00e9taient pas affect\u00e9s.<\/p>\n<p><strong>\u00c0 EXPLORER :\u00a0<a href=\"https:\/\/www.coinspeaker.com\/fr\/guides\/memecoin\/\" target=\"_blank\" rel=\"nofollow\">Meilleurs meme coins \u00e0 surveiller \u2013 Classements mis \u00e0 jour de CoinSpeaker<\/a><\/strong><\/p>\n<p><a target=\"_blank\" rel=\"noopener nofollow sponsored\" class=\"infinscroll_next_page_link\" style=\"display: none;\" href=\"https:\/\/www.coinspeaker.com\/kraken-refuses-negotiate-extortion-threat\/\" rel=\"prev\">next<\/a><\/p>\n<a class=\"infinscroll_next_page_link\" style=\"display:none\" href=\"https:\/\/www.coinspeaker.com\/fr\/dogecoin-bloque-sous-010-maxi-doge\/\" rel=\"prev\">next<\/a>","protected":false},"excerpt":{"rendered":"<p>CoW Swap suspend son protocole apr\u00e8s la compromission de son site web<\/p>\n","protected":false},"author":200,"featured_media":21549,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-21551","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-actu"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>CoW Swap suspend son protocole apr\u00e8s un hack de son site<\/title>\n<meta name=\"description\" content=\"CoW Swap suspend son protocole apr\u00e8s que des attaquants ont pris le contr\u00f4le du domaine de son site et redirig\u00e9 vers un site malveillant\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.coinspeaker.com\/fr\/cow-swap-suspend-son-protocole-apres-la-compromission-de-son-site-web\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CoW Swap suspend son protocole apr\u00e8s un hack de son site\" \/>\n<meta property=\"og:description\" content=\"CoW Swap suspend son protocole apr\u00e8s que des attaquants ont pris le contr\u00f4le du domaine de son site et redirig\u00e9 vers un site malveillant\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.coinspeaker.com\/fr\/cow-swap-suspend-son-protocole-apres-la-compromission-de-son-site-web\/\" \/>\n<meta property=\"og:site_name\" content=\"Coinspeaker France\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-16T15:31:53+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.coinspeaker.com\/fr\/wp-content\/uploads\/sites\/6\/2026\/04\/cow-swap-website-compromise-dns-hijacking.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1792\" \/>\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Emmanuel Roux\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Emmanuel Roux\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CoW Swap suspend son protocole apr\u00e8s un hack de son site","description":"CoW Swap suspend son protocole apr\u00e8s que des attaquants ont pris le contr\u00f4le du domaine de son site et redirig\u00e9 vers un site malveillant","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.coinspeaker.com\/fr\/cow-swap-suspend-son-protocole-apres-la-compromission-de-son-site-web\/","og_locale":"fr_FR","og_type":"article","og_title":"CoW Swap suspend son protocole apr\u00e8s un hack de son site","og_description":"CoW Swap suspend son protocole apr\u00e8s que des attaquants ont pris le contr\u00f4le du domaine de son site et redirig\u00e9 vers un site malveillant","og_url":"https:\/\/www.coinspeaker.com\/fr\/cow-swap-suspend-son-protocole-apres-la-compromission-de-son-site-web\/","og_site_name":"Coinspeaker France","article_published_time":"2026-04-16T15:31:53+00:00","og_image":[{"width":1792,"height":1024,"url":"https:\/\/www.coinspeaker.com\/fr\/wp-content\/uploads\/sites\/6\/2026\/04\/cow-swap-website-compromise-dns-hijacking.webp","type":"image\/webp"}],"author":"Emmanuel Roux","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Emmanuel Roux","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.coinspeaker.com\/fr\/cow-swap-suspend-son-protocole-apres-la-compromission-de-son-site-web\/","url":"https:\/\/www.coinspeaker.com\/fr\/cow-swap-suspend-son-protocole-apres-la-compromission-de-son-site-web\/","name":"CoW Swap suspend son protocole apr\u00e8s un hack de son site","isPartOf":{"@id":"https:\/\/www.coinspeaker.com\/fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.coinspeaker.com\/fr\/cow-swap-suspend-son-protocole-apres-la-compromission-de-son-site-web\/#primaryimage"},"image":{"@id":"https:\/\/www.coinspeaker.com\/fr\/cow-swap-suspend-son-protocole-apres-la-compromission-de-son-site-web\/#primaryimage"},"thumbnailUrl":"https:\/\/www.coinspeaker.com\/fr\/wp-content\/uploads\/sites\/6\/2026\/04\/cow-swap-website-compromise-dns-hijacking.webp","datePublished":"2026-04-16T15:31:53+00:00","author":{"@id":"https:\/\/www.coinspeaker.com\/fr\/#\/schema\/person\/cfb5df450a3f98d6cbdac45264af1e5d"},"description":"CoW Swap suspend son protocole apr\u00e8s que des attaquants ont pris le contr\u00f4le du domaine de son site et redirig\u00e9 vers un site malveillant","breadcrumb":{"@id":"https:\/\/www.coinspeaker.com\/fr\/cow-swap-suspend-son-protocole-apres-la-compromission-de-son-site-web\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.coinspeaker.com\/fr\/cow-swap-suspend-son-protocole-apres-la-compromission-de-son-site-web\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.coinspeaker.com\/fr\/cow-swap-suspend-son-protocole-apres-la-compromission-de-son-site-web\/#primaryimage","url":"https:\/\/www.coinspeaker.com\/fr\/wp-content\/uploads\/sites\/6\/2026\/04\/cow-swap-website-compromise-dns-hijacking.webp","contentUrl":"https:\/\/www.coinspeaker.com\/fr\/wp-content\/uploads\/sites\/6\/2026\/04\/cow-swap-website-compromise-dns-hijacking.webp","width":1792,"height":1024},{"@type":"BreadcrumbList","@id":"https:\/\/www.coinspeaker.com\/fr\/cow-swap-suspend-son-protocole-apres-la-compromission-de-son-site-web\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.coinspeaker.com\/fr\/"},{"@type":"ListItem","position":2,"name":"CoW Swap suspend son protocole apr\u00e8s la compromission de son site web"}]},{"@type":"WebSite","@id":"https:\/\/www.coinspeaker.com\/fr\/#website","url":"https:\/\/www.coinspeaker.com\/fr\/","name":"Coinspeaker France","description":"Bitcoin, Ethereum, Altcoins et actualit\u00e9s crypto avec analyses, cours en direct, graphiques de donn\u00e9es et guides","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.coinspeaker.com\/fr\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Person","@id":"https:\/\/www.coinspeaker.com\/fr\/#\/schema\/person\/cfb5df450a3f98d6cbdac45264af1e5d","name":"Emmanuel Roux","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.coinspeaker.com\/fr\/#\/schema\/person\/image\/","url":"https:\/\/www.coinspeaker.com\/fr\/wp-content\/uploads\/sites\/6\/2025\/06\/cropped-pp-1-96x96.png","contentUrl":"https:\/\/www.coinspeaker.com\/fr\/wp-content\/uploads\/sites\/6\/2025\/06\/cropped-pp-1-96x96.png","caption":"Emmanuel Roux"},"description":"Issu de la finance traditionnelle, j\u2019ai naturellement bascul\u00e9 vers l\u2019univers crypto, attir\u00e9 par son potentiel. Je souhaite y apporter mon approche analytique et rationnelle, tout en conservant ma curiosit\u00e9. En dehors de l\u2019\u00e9cran, je lis beaucoup (\u00e9conomie, essais, un peu de science-fiction) et je prends plaisir \u00e0 bricoler. Le DIY, pour moi, c\u2019est comme la crypto : comprendre, tester, construire soi-m\u00eame.","url":"https:\/\/www.coinspeaker.com\/fr\/author\/emmanuel\/"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/posts\/21551","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/users\/200"}],"replies":[{"embeddable":true,"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/comments?post=21551"}],"version-history":[{"count":2,"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/posts\/21551\/revisions"}],"predecessor-version":[{"id":21560,"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/posts\/21551\/revisions\/21560"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/media\/21549"}],"wp:attachment":[{"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/media?parent=21551"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/categories?post=21551"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/tags?post=21551"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}