{"investigation":{"slug":"cow-swap-cow-protocol","entity_name":"CoW Swap (CoW Protocol)","trust_score":50,"severity_base":null,"score_modifier":-8,"confidence":0.82,"status":"published","content_type":"investigation","summary":"CoW Protocol (trading interface: CoW Swap) is a decentralized exchange aggregator and MEV-protection protocol spun out of GnosisDAO in 2022. On April 14, 2026, the protocol's cow.fi domain was hijacked via a social engineering attack that exploited registrar Gandi SAS and the Finnish .fi registry authority Traficom using forged identity documents, redirecting users to a phishing interface for approximately 90 minutes and causing confirmed losses of approximately $1.2 million. The protocol's smart contracts were not compromised; CoW DAO subsequently passed CIP-86 in May 2026 to offer discretionary grants reimbursing verified victims up to 100% of their losses.","sections":[{"content":"CoW Protocol is a decentralized intent-based trading protocol that uses batch auctions and Coincidence of Wants (CoW) matching to offer MEV protection for traders on Ethereum and related networks. It originated as a product within Gnosis and was formally spun out as an independent DAO in early 2022 following a $23 million fundraise from investors including Blockchain Capital and Cherry Ventures. The trading interface, CoW Swap, launched as a proof of concept in April 2021. The protocol also operates CoW AMM, launched in February 2024, which was marketed as the first live AMM designed to address loss-versus-rebalancing (LVR) for liquidity providers. Governance is conducted through CoW DAO, with proposals following a CIP (CoW Improvement Proposal) process and votes held on Snapshot.","heading":"Protocol Overview","sources":[{"url":"https://www.theblock.co/linked/139692/cow-protocol-raises-23-million-and-spins-out-from-gnosis-dao","name":"CoW Protocol raises $23 million and spins out from Gnosis DAO — The Block","type":"news_article","credibility":2},{"url":"https://cow.fi/","name":"CoW DAO official website","type":"official","credibility":1}],"severity":"low"},{"content":"On April 14, 2026 at approximately 14:54 UTC, an attacker gained control of DNS records for cow.fi and swap.cow.fi by exploiting the .fi domain management process. According to post-incident reporting, the attacker impersonated a senior CoW DAO contributor and submitted forged identification documents to Traficom (the Finnish Communications Regulatory Authority, which operates the .fi country-code top-level domain registry). This triggered a registrar dispute process against Gandi SAS, the registrar managing the cow.fi domain through Amazon Route 53. Gandi did not respond to the dispute, which allowed the attacker to gain effective control over the domain's DNS records. The redirected traffic pointed users to a pixel-perfect phishing interface designed to prompt wallet connections and obtain signatures on malicious transactions. Security firm Blockaid detected the breach at 14:54 UTC. CoW DAO's team identified the issue within approximately 19 minutes and migrated operations to an alternate domain (cow.finance) within roughly 3.5 hours. The cow.fi domain was fully restored on April 15, 2026, with RegistryLock subsequently enabled — a protection that had not been available through Amazon Route 53 prior to the incident. The attack surface was limited to the front-end interface; the underlying smart contracts, backend systems, and APIs were not compromised.","heading":"April 2026 DNS Hijacking Attack","sources":[{"url":"https://domainnamewire.com/2026/04/17/domain-hijack-led-to-crypto-heist/","name":"Domain hijack led to crypto heist — Domain Name Wire","type":"news_article","credibility":2},{"url":"https://financefeeds.com/cow-swap-protocol-halts-services-following-major-dns-hijacking-incident/","name":"CoW Swap Protocol Halts Services Following Major DNS Hijacking Incident — FinanceFeeds","type":"news_article","credibility":2},{"url":"https://www.coindesk.com/tech/2026/04/14/popular-defi-platform-warns-users-to-stay-away-from-its-site-after-security-breach","name":"Popular DeFi platform CoW Swap warns users to stay away from its site after security breach — CoinDesk","type":"news_article","credibility":1},{"url":"https://protos.com/cow-swap-hit-by-dns-hijack-warns-users-to-stay-clear-of-site/","name":"CoW Swap hit by DNS hijack, warns users to stay clear of site — Protos","type":"news_article","credibility":2},{"url":"https://en.cryptonomist.ch/2026/04/17/cow-swap-domain-hijack/","name":"CoW Swap lost $1.2M in a domain hijack phishing attack — Cryptonomist","type":"news_article","credibility":2}],"severity":"critical"},{"content":"Post-incident analysis identified two compounding security failures at the infrastructure layer. First, Gandi SAS, the domain registrar, allegedly did not respond to the dispute raised against the cow.fi domain, effectively allowing the attacker's claim to proceed without challenge. Second, Amazon Route 53 — the DNS provider CoW DAO used to manage its .fi domain records prior to the attack — did not support RegistryLock for .fi domains at the time of the incident. RegistryLock is a domain security feature that prevents unauthorized DNS or registrar changes without out-of-band verification. The absence of this protection created an exploitable gap in CoW's domain security posture. Following recovery, CoW DAO enabled RegistryLock on cow.fi through a new registrar configuration. A parallel social engineering attack targeting the easyDNS registrar to hijack the eth.limo gateway was reported around the same period, suggesting a broader pattern of .fi and crypto-adjacent domain attacks using impersonation tactics.","heading":"Registrar Security Failures","sources":[{"url":"https://domainnamewire.com/2026/04/17/domain-hijack-led-to-crypto-heist/","name":"Domain hijack led to crypto heist — Domain Name Wire","type":"news_article","credibility":2},{"url":"https://www.gncrypto.news/news/social-engineering-easydns-eth-limo-hijack-dnssec/","name":"Social engineering at easyDNS hijacks eth.limo gateway — GNCrypto News","type":"news_article","credibility":2}],"severity":"high"},{"content":"Confirmed user losses from the April 14, 2026 attack totaled approximately $1.2 million USD. The single largest confirmed loss involved one trader who lost 219 ETH, valued at approximately $750,000 at the time of the attack. The phishing interface operated for approximately 90 minutes during which users who visited the official cow.fi URL and connected their wallets were prompted to sign malicious transactions that drained assets to the attacker's drainer contract. The CIP-86 governance proposal acknowledged approximately $1.2 million USD in aggregate user losses, funded from a one-time allocation from CoW DAO's Legal Defense Reserve, with the reserve subsequently replenished to 5 million USDC. The number of individual victims beyond the 219-ETH trader has not been publicly disclosed in detail by CoW DAO.","heading":"User Losses and Victim Impact","sources":[{"url":"https://bingx.com/en/flash-news/post/cow-swap-confirms-m-user-loss-after-cow-fi-domain-hijack-redirected-swap-cow-fi-to-phishing-site","name":"CoW Swap Says Domain Hijack Led to $1.2M in User Losses — BingX Flash News","type":"news_article","credibility":2},{"url":"https://www.bitget.com/news/detail/12560605371175","name":"CoW Swap releases full post-incident report — Bitget News","type":"news_article","credibility":2},{"url":"https://forum.cow.fi/t/cip-86-discretionary-grants-program-for-victims-of-the-cow-fi-domain-hijacking/3431","name":"CIP-86: Discretionary grants program for victims of the cow.fi domain hijacking — CoW DAO Forum","type":"official","credibility":1}],"severity":"high"},{"content":"Following community discussion that began in late April 2026, CoW DAO put CIP-86 — titled 'Discretionary grants program for victims of the cow.fi domain hijacking' — to a Snapshot vote. The proposal passed on May 8, 2026, after a vote period of April 30 to May 7. CIP-86 authorized discretionary grants of up to 100% of verified losses to eligible victims, funded from the Legal Defense Reserve. The compensation is explicitly framed as voluntary and ex gratia, not constituting an admission of liability by CoW DAO. By accepting payment, recipients agree to a full and final settlement of any claims against CoW DAO. Eligibility required that a claimant: (1) had traded on CoW Swap at least once before April 14, 2026, or been directly funded by a wallet that had; (2) signed a malicious transaction with the specific drainer contract deployed by the attacker; and (3) was not excluded on grounds of seed-phrase/private-key exposure or wallet funding through mixers, privacy tools, or sanctioned addresses. Claims were submitted to help@cow.fi by May 14, 2026, with KYC verification handled by an external firm. Payouts were targeted to begin May 21, with the program concluding May 31, 2026.","heading":"CIP-86: Victim Compensation Program","sources":[{"url":"https://forum.cow.fi/t/cip-86-discretionary-grants-program-for-victims-of-the-cow-fi-domain-hijacking/3431","name":"CIP-86: Discretionary grants program for victims of the cow.fi domain hijacking — CoW DAO Forum","type":"official","credibility":1},{"url":"https://www.cryptotimes.io/2026/05/12/cip-86-passed-cow-dao-begins-compensation-for-april-attack/","name":"CIP-86 Passed: CoW DAO Begins Compensation for April Attack — CryptoTimes","type":"news_article","credibility":2},{"url":"https://coinspectator.com/cryptonews/2026/05/11/cow-dao-approves-compensation-for-cow-fi-hijack-victims-claims-due-may-14/","name":"CoW DAO approves compensation for cow.fi hijack victims — CoinSpectator","type":"news_article","credibility":2}],"severity":"medium"},{"content":"CoW DAO and independent observers consistently confirmed that the April 14, 2026 attack did not compromise CoW Protocol's smart contracts, solver infrastructure, or backend APIs. The vulnerability was confined to the DNS layer and the front-end web interface. CoW DAO paused backend protocols and APIs as a precautionary measure during the incident response window. The protocol's intent-based architecture, batch auction settlement, and on-chain settlement contracts remained unaffected throughout. No funds in protocol-controlled contracts or liquidity pools were at risk. The losses stemmed entirely from users who visited the phishing interface and manually signed malicious approval or transfer transactions.","heading":"Protocol Integrity and Smart Contract Security","sources":[{"url":"https://www.coindesk.com/tech/2026/04/14/popular-defi-platform-warns-users-to-stay-away-from-its-site-after-security-breach","name":"Popular DeFi platform CoW Swap warns users to stay away from its site after security breach — CoinDesk","type":"news_article","credibility":1},{"url":"https://protos.com/cow-swap-hit-by-dns-hijack-warns-users-to-stay-clear-of-site/","name":"CoW Swap hit by DNS hijack, warns users to stay clear of site — Protos","type":"news_article","credibility":2}],"severity":"low"},{"content":"CoW DAO's response to the April 14 attack proceeded in several phases. Within approximately 19 minutes of the first detection at 14:54 UTC, the team issued public warnings on X advising users not to visit cow.fi and to revoke any approvals made during the window. Backend protocols and APIs were suspended as a precaution. Within roughly 3.5 hours, the team completed migration to an alternate domain, cow.finance, restoring protocol functionality. The cow.fi domain was fully recovered on April 15, 2026. Post-incident, CoW DAO enabled RegistryLock on the cow.fi domain — a protection previously unavailable through Amazon Route 53 — and signaled intent to implement multi-signature domain management and more robust multi-factor authentication for all administrative access points. CoW DAO published a full post-mortem report approximately three days after the incident.","heading":"Incident Response and Remediation","sources":[{"url":"https://domainnamewire.com/2026/04/17/domain-hijack-led-to-crypto-heist/","name":"Domain hijack led to crypto heist — Domain Name Wire","type":"news_article","credibility":2},{"url":"https://financefeeds.com/cow-swap-protocol-halts-services-following-major-dns-hijacking-incident/","name":"CoW Swap Protocol Halts Services Following Major DNS Hijacking Incident — FinanceFeeds","type":"news_article","credibility":2},{"url":"https://bingx.com/en/flash-news/post/cow-swap-report-says-cow-fi-domain-hijack-redirected-swap-cow-fi-to-phishing-site-estimated-user-losses-m","name":"CoW Swap Publishes Post-Mortem on Domain Hijack; User Losses Estimated at $1.2 Million — BingX","type":"news_article","credibility":2}],"severity":"medium"},{"content":"The CoW Swap incident is part of a documented pattern of DNS and frontend-layer attacks targeting decentralized finance protocols. In the same period, the eth.limo gateway suffered a materially similar attack in which hackers impersonated the eth.limo team to hijack its domain through the easyDNS registrar via social engineering. These attacks highlight a structural risk in DeFi: while smart contracts may be audited and immutable, the web frontend through which most users interact remains dependent on centralized domain registrars and DNS infrastructure, which are vulnerable to social engineering, identity fraud, and registrar unresponsiveness. The cow.fi attack demonstrated that even protocols with robust on-chain security postures can cause significant user harm through infrastructure compromise at the DNS layer.","heading":"Frontend Attack Risk in DeFi","sources":[{"url":"https://www.gncrypto.news/news/social-engineering-easydns-eth-limo-hijack-dnssec/","name":"Social engineering at easyDNS hijacks eth.limo gateway — GNCrypto News","type":"news_article","credibility":2},{"url":"https://www.kucoin.com/blog/cow-swap-frontend-attack-explained-dns-hijacking-how-it-works-and-how-to-protect-your-wallet-in-defi","name":"CoW Swap Frontend Attack Explained — KuCoin Blog","type":"news_article","credibility":2}],"severity":"high"}],"timeline":[{"date":"2021-04","event":"CoW Swap launches as a proof of concept on Ethereum, developed within Gnosis.","source":"CoW Protocol official blog / The Block","source_url":"https://www.theblock.co/linked/139692/cow-protocol-raises-23-million-and-spins-out-from-gnosis-dao","date_original":"2021-04-01"},{"date":"2022-02","event":"CoW Protocol completes $23 million fundraise and formally spins out from GnosisDAO as an independent entity with its own DAO.","source":"The Block","source_url":"https://www.theblock.co/linked/139692/cow-protocol-raises-23-million-and-spins-out-from-gnosis-dao","date_original":"2022-02-01"},{"date":"2026-04-14","event":"At approximately 14:54 UTC, attacker gains control of cow.fi DNS records via social engineering against registrar Gandi SAS and Traficom (.fi registry) using forged identity documents, redirecting traffic to a phishing interface.","source":"Domain Name Wire / FinanceFeeds / CoinDesk","source_url":"https://domainnamewire.com/2026/04/17/domain-hijack-led-to-crypto-heist/"},{"date":"2026-04-14","event":"CoW DAO issues public warning on X advising users not to visit cow.fi and to revoke any wallet approvals; backend protocols and APIs suspended. Team detects issue within ~19 minutes of attack onset.","source":"CoinDesk / Protos","source_url":"https://www.coindesk.com/tech/2026/04/14/popular-defi-platform-warns-users-to-stay-away-from-its-site-after-security-breach"},{"date":"2026-04-14","event":"Within approximately 3.5 hours of the attack, CoW DAO completes migration to alternate domain cow.finance, restoring protocol functionality.","source":"Domain Name Wire","source_url":"https://domainnamewire.com/2026/04/17/domain-hijack-led-to-crypto-heist/"},{"date":"2026-04-15","event":"cow.fi domain fully recovered. CoW DAO enables RegistryLock on cow.fi, a protection not previously available through Amazon Route 53.","source":"Domain Name Wire","source_url":"https://domainnamewire.com/2026/04/17/domain-hijack-led-to-crypto-heist/"},{"date":"2026-04-17","event":"CoW DAO publishes full post-mortem report estimating total user losses at approximately $1.2 million, including a single loss of 219 ETH (~$750K) by one trader.","source":"Bitget News / BingX / Cryptonomist","source_url":"https://bingx.com/en/flash-news/post/cow-swap-report-says-cow-fi-domain-hijack-redirected-swap-cow-fi-to-phishing-site-estimated-user-losses-m"},{"date":"2026-04-30","event":"CIP-86 draft ('Discretionary grants program for victims of the cow.fi domain hijacking') opens for Snapshot vote.","source":"CoW DAO Forum","source_url":"https://forum.cow.fi/t/cip-86-discretionary-grants-program-for-victims-of-the-cow-fi-domain-hijacking/3431"},{"date":"2026-05-08","event":"CIP-86 passes Snapshot vote. CoW DAO authorizes discretionary grants of up to 100% of verified losses to eligible victims, funded from the Legal Defense Reserve.","source":"CoW DAO Forum / CryptoTimes / CoinSpectator","source_url":"https://forum.cow.fi/t/cip-86-discretionary-grants-program-for-victims-of-the-cow-fi-domain-hijacking/3431"},{"date":"2026-05-14","event":"Claim submission deadline for CIP-86 victims to email help@cow.fi with wallet addresses, affected assets, transaction hashes, and full name for KYC.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/05/12/cip-86-passed-cow-dao-begins-compensation-for-april-attack/"},{"date":"2026-05-21","event":"CIP-86 grant payouts targeted to begin following review and KYC verification by an external firm.","source":"CoW DAO Forum","source_url":"https://forum.cow.fi/t/cip-86-discretionary-grants-program-for-victims-of-the-cow-fi-domain-hijacking/3431"},{"date":"2026-05-31","event":"CIP-86 compensation program scheduled to conclude.","source":"CoW DAO Forum / CoinSpectator","source_url":"https://coinspectator.com/cryptonews/2026/05/11/cow-dao-approves-compensation-for-cow-fi-hijack-victims-claims-due-may-14/"}],"sources_used":[{"url":"https://domainnamewire.com/2026/04/17/domain-hijack-led-to-crypto-heist/","name":"Domain hijack led to crypto heist — Domain Name Wire","type":"news_article","archive_url":"http://web.archive.org/web/20260515191610/https://domainnamewire.com/2026/04/17/domain-hijack-led-to-crypto-heist/","credibility":2,"archive_timestamp":"2026-05-15T19:16:10+00:00"},{"url":"https://www.coindesk.com/tech/2026/04/14/popular-defi-platform-warns-users-to-stay-away-from-its-site-after-security-breach","name":"Popular DeFi platform CoW Swap warns users to stay away from its site after security breach — CoinDesk","type":"news_article","archive_url":"http://web.archive.org/web/20260425093713/https://www.coindesk.com/tech/2026/04/14/popular-defi-platform-warns-users-to-stay-away-from-its-site-after-security-breach","credibility":1,"archive_timestamp":"2026-04-25T09:37:13+00:00"},{"url":"https://protos.com/cow-swap-hit-by-dns-hijack-warns-users-to-stay-clear-of-site/","name":"CoW Swap hit by DNS hijack, warns users to stay clear of site — Protos","type":"news_article","archive_url":"http://web.archive.org/web/20260515171416/https://protos.com/cow-swap-hit-by-dns-hijack-warns-users-to-stay-clear-of-site/","credibility":2,"archive_timestamp":"2026-05-15T17:14:16+00:00"},{"url":"https://financefeeds.com/cow-swap-protocol-halts-services-following-major-dns-hijacking-incident/","name":"CoW Swap Protocol Halts Services Following Major DNS Hijacking Incident — FinanceFeeds","type":"news_article","archive_url":"https://web.archive.org/web/20260725203413/https://financefeeds.com/cow-swap-protocol-halts-services-following-major-dns-hijacking-incident/","credibility":2,"archive_timestamp":"2026-07-25T20:34:13+00:00"},{"url":"https://www.coinspeaker.com/cow-swap-halts-protocol-website-compromise/","name":"CoW Swap Halts Protocol After Website Compromise — Coinspeaker","type":"news_article","archive_url":"http://web.archive.org/web/20260520155554/https://www.coinspeaker.com/cow-swap-halts-protocol-website-compromise/","credibility":2,"archive_timestamp":"2026-05-20T15:55:54+00:00"},{"url":"https://en.cryptonomist.ch/2026/04/17/cow-swap-domain-hijack/","name":"CoW Swap lost $1.2M in a domain hijack phishing attack — Cryptonomist","type":"news_article","archive_url":"https://web.archive.org/web/20260726221947/https://en.cryptonomist.ch/2026/04/17/cow-swap-domain-hijack/","credibility":2,"archive_timestamp":"2026-07-26T22:19:47+00:00"},{"url":"https://www.bitget.com/news/detail/12560605371175","name":"CoW Swap releases full post-incident report — Bitget News","type":"news_article","archive_url":"https://web.archive.org/web/20260725151841/https://www.bitget.com/news/detail/12560605371175","credibility":2,"archive_timestamp":"2026-07-25T15:18:41+00:00"},{"url":"https://bingx.com/en/flash-news/post/cow-swap-confirms-m-user-loss-after-cow-fi-domain-hijack-redirected-swap-cow-fi-to-phishing-site","name":"CoW Swap Says Domain Hijack Led to $1.2M in User Losses — BingX","type":"news_article","archive_url":"https://web.archive.org/web/20260726040718/https://bingx.com/en/flash-news/post/cow-swap-confirms-m-user-loss-after-cow-fi-domain-hijack-redirected-swap-cow-fi-to-phishing-site","credibility":2,"archive_timestamp":"2026-07-26T04:07:18+00:00"},{"url":"https://bingx.com/en/flash-news/post/cow-swap-report-says-cow-fi-domain-hijack-redirected-swap-cow-fi-to-phishing-site-estimated-user-losses-m","name":"CoW Swap Publishes Post-Mortem on Domain Hijack — BingX","type":"news_article","archive_url":"http://web.archive.org/web/20260509111244/https://bingx.com/en/flash-news/post/cow-swap-report-says-cow-fi-domain-hijack-redirected-swap-cow-fi-to-phishing-site-estimated-user-losses-m","credibility":2,"archive_timestamp":"2026-05-09T11:12:44+00:00"},{"url":"https://forum.cow.fi/t/cip-86-discretionary-grants-program-for-victims-of-the-cow-fi-domain-hijacking/3431","name":"CIP-86: Discretionary grants program for victims of the cow.fi domain hijacking — CoW DAO Forum","type":"official","archive_url":"http://web.archive.org/web/20260516144553/https://forum.cow.fi/t/cip-86-discretionary-grants-program-for-victims-of-the-cow-fi-domain-hijacking/3431","credibility":1,"archive_timestamp":"2026-05-16T14:45:53+00:00"},{"url":"https://www.cryptotimes.io/2026/05/12/cip-86-passed-cow-dao-begins-compensation-for-april-attack/","name":"CIP-86 Passed: CoW DAO Begins Compensation for April Attack — CryptoTimes","type":"news_article","archive_url":"https://web.archive.org/web/20260725160452/https://www.cryptotimes.io/2026/05/12/cip-86-passed-cow-dao-begins-compensation-for-april-attack/","credibility":2,"archive_timestamp":"2026-07-25T16:04:52+00:00"},{"url":"https://coinspectator.com/cryptonews/2026/05/11/cow-dao-approves-compensation-for-cow-fi-hijack-victims-claims-due-may-14/","name":"CoW DAO approves compensation for cow.fi hijack victims — CoinSpectator","type":"news_article","archive_url":"http://web.archive.org/web/20260725201311/https://coinspectator.com/cryptonews/2026/05/11/cow-dao-approves-compensation-for-cow-fi-hijack-victims-claims-due-may-14/","credibility":2,"archive_timestamp":"2026-07-25T20:13:11+00:00"},{"url":"https://www.theblock.co/linked/139692/cow-protocol-raises-23-million-and-spins-out-from-gnosis-dao","name":"CoW Protocol raises $23 million and spins out from Gnosis DAO — The Block","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.gncrypto.news/news/social-engineering-easydns-eth-limo-hijack-dnssec/","name":"Social engineering at easyDNS hijacks eth.limo gateway — GNCrypto News","type":"news_article","archive_url":"https://web.archive.org/web/20260725161325/https://www.gncrypto.news/news/social-engineering-easydns-eth-limo-hijack-dnssec/","credibility":2,"archive_timestamp":"2026-07-25T16:13:25+00:00"},{"url":"https://www.kucoin.com/blog/cow-swap-frontend-attack-explained-dns-hijacking-how-it-works-and-how-to-protect-your-wallet-in-defi","name":"CoW Swap Frontend Attack Explained — KuCoin Blog","type":"news_article","archive_url":"https://web.archive.org/web/20260726044714/https://www.kucoin.com/blog/cow-swap-frontend-attack-explained-dns-hijacking-how-it-works-and-how-to-protect-your-wallet-in-defi","credibility":2,"archive_timestamp":"2026-07-26T04:47:14+00:00"},{"url":"https://theorg.com/org/cow/org-chart/anna-george","name":"Anna George — CEO / Co-Founder at CoW (The Org)","type":"other","archive_url":"https://web.archive.org/web/20260726184656/https://theorg.com/org/cow?p=anna-george","credibility":2,"archive_timestamp":"2026-07-26T18:46:56+00:00"},{"url":"https://cow.fi/","name":"CoW DAO official website","type":"official","archive_url":"http://web.archive.org/web/20260526170415/https://cow.fi/","credibility":1,"archive_timestamp":"2026-05-26T17:04:15+00:00"},{"url":"https://github.com/cowprotocol","name":"CoW Protocol GitHub","type":"official","archive_url":"http://web.archive.org/web/20260706115101/https://github.com/cowprotocol","credibility":1,"archive_timestamp":"2026-07-06T11:51:01+00:00"},{"url":"https://docs.cow.fi/","name":"CoW Protocol Documentation","type":"official","archive_url":"http://web.archive.org/web/20260520005042/https://docs.cow.fi/","credibility":1,"archive_timestamp":"2026-05-20T00:50:42+00:00"}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-31T07:08:45.132852+00:00","updated_at":"2026-07-26T22:26:11.048699+00:00"}}