Choose Rich Live
Crypto News

Scammers steal over $2 million using counterfeit GIWA network and bridge

Attackers created a fake version of the unreleased GIWA blockchain, tricking more than 1,300 wallets into depositing over 766 ETH into a fraudulent bridge that was drained hours later.

Screenshot of a blockchain transaction showing the transfer of 766.25 ETH at block 26067309.
Image: @CryptoPatel

Scammers established a counterfeit version of GIWA, an upcoming Ethereum Layer 2 network backed by Upbit operator Dunamu, draining roughly $2 million in ether before the legitimate mainnet had launched. By configuring the network with GIWA's expected Chain ID 9134 alongside a working RPC endpoint and cross-chain bridge, the perpetrators misled decentralized exchange DYORSWAP and over 1,330 depositing addresses into believing the mainnet was live.[1][2][3]

According to pseudonymous blockchain analyst Stablemark, wallets tied to the operation were funded through ChangeHero on Sept. 26, with the bridge going live about 11 hours later. Over the next 12 to 13 hours, users deposited approximately 767 ETH before the operators changed the bridge portal code and drained 766 ETH in a single transaction at block 26067309. Stablemark reported that 177 ETH was routed into Tornado Cash while 589 ETH remained across four wallets. DYORSWAP stated the event was not a direct smart-contract exploit and indicated the suspected perpetrator wallets received funding from Binance and Gate.[1][2][3]

The official GIWA team warned on X that no mainnet existed, explaining that its only live public environment was the GIWA Sepolia testnet using Chain ID 91342, though the clarification was posted just minutes before the fake bridge was drained. DYORSWAP later admitted the network was fraudulent and launched a compensation plan offering a 40% refund to wallets that bridged less than 5 ETH, with larger amounts subject to individual verification. The exchange reported distributing more than 200 ETH in compensation to affected users.[1][2][3][4]

Key facts

  • Scammers spoofed the unlaunched GIWA Ethereum Layer 2 network using its expected Chain ID 9134, drawing around 767 ETH (worth approximately $2 million) into a fraudulent bridge contract.
  • More than 1,330 wallets interacted with the fake bridge before operators altered its portal code and withdrew 766 ETH in a single transaction.
  • Blockchain analyst Stablemark reported that the scammers routed 177 ETH through Tornado Cash while leaving 589 ETH across four wallets.
  • GIWA clarified that its mainnet had not launched and that its official documentation lists only the GIWA Sepolia testnet with Chain ID 91342.
  • DYORSWAP offered a 40% refund to users who bridged less than 5 ETH and stated it distributed more than 200 ETH in compensation.
  • DYORSWAP stated the incident was not a smart-contract vulnerability and traced suspected scammer addresses to funding from Binance and Gate.

Sources · 4 sources

  1. CR

    CryptoSlateArticle ·

    Crypto scammers built an entire fake blockchain to steal over $2 million Scammers built a counterfeit version of Upbit -backed GIWA blockchain and lured 1,333 wallets into depositing 767 ETH, worth about $2 million, before draining almost all of it. The fake network appeared to be GIWA’s anticipated Ethereum Layer 2 mainnet, complete with an RPC endpoint, cross-chain bridge, and Chain ID 9134, the identifier associated with the planned launch. But GIWA’s mainnet was not live. In an X post, GIWA said claims that its production RPC had leaked were false because no mainnet RPC exists. Its documentation lists only GIWA Sepolia, which uses Chain ID 91342, while the production network remains under development. DYORSWAP, whose community initially interacted with the purported network, later said the chain was fraudulent and warned users against unofficial RPC endpoints, bridges and contracts. It stated: “The fake network used the correct GIWA Chain ID (9134), which made it appear legitimate during our initial verification. We have also identified specific suspicious messages and individuals in the related community that may be connected to this incident.” Dunamu, operator of South Korea’s largest crypto exchange, Upbit, is developing GIWA using Optimism’s OP Stack. Dunamu and the Optimism Foundation announced in May that GIWA is planned as the first Self-Managed OP Enterprise chain, allowing Upbit to retain operational control while Optimism provides backup infrastructure and support. Attackers waited for deposits before changing the bridge On-chain data suggests the attackers spent hours preparing the infrastructure before the first significant deposits arrived. Pseudonymous blockchain analyst Stablemark said wallets tied to the operation were funded through ChangeHero on Sept. 26. About 11 hours later, the Safe wallet controlling the scheme and the fake bridge went live. Over the next 13 hours, 1,333 wallets deposited a combined 767 ETH. How Attackers Moved Stolen Funds on the Fake GIWA Chain (Source: Stablemark) The operators then changed the bridge’s portal code and drained 766 ETH in a single transaction, according to Stablemark. The sequence suggests the bridge remained operational long enough to accumulate deposits before the operators replaced its controlling code and removed the funds. The attack relied in part on how EVM networks are identified. A Chain ID can tell a wallet which network it is connected to, but it does not verify who controls the RPC endpoint or bridge behind that network. By using GIWA’s expected Chain ID 9134, the operators could make the environment appear consistent with the anticipated mainnet while retaining control of the infrastructure receiving user funds. The stolen ETH has since begun to move. Stablemark said 177 ETH was routed through Tornado Cash, complicating efforts to trace its subsequent destination, while another 589 ETH remained spread across four wallets at the time of his update. That leaves most of the stolen funds visible on-chain for now, though further transfers to mixers, exchanges, or other services could narrow the window for investigators to freeze or recover them. DYORSWAP offers 40% compensation to smaller victims DYORSWAP has moved to compensate some users caught in the fake blockchain scheme after reviewing affected addresses. The project said wallets that bridged less than 5 ETH would receive compensation equal to 40% of their cross-chain amount. Claims involving more than 5 ETH will be handled separately and require identity and address verification, because DYORSWAP said some larger wallets could be linked to phishing or other fraudulent activity. It also published an address for compensation distributions and warned victims to verify it through official channels, citing the risk that scammers could exploit the incident again using fake reimbursement requests. The compensation plan leaves substantial losses with users even where claims are approved. Smaller victims would recover less than half of what they deposited under the announced terms, while outcomes for larger wallets remain subject to individual review. DYORSWAP has said it is preserving RPC records, bridge addresses, transaction data and community communications as investigators reconstruct how the fraudulent network spread. The post Crypto scammers built an entire fake blockchain to steal over $2 million appeared first on CryptoSlate .

    Open source
  2. CP

    Crypto Patel@CryptoPatelPost on X ·

    Fake GIWA Mainnet Scam: $2M $ETH Drained Via Counterfeit Upbit Layer 2 Bridge A major crypto scam targeted users through a fake GIWA network impersonating the upcoming GIWA Layer 2 mainnet. WHAT HAPPENED? 🔸 @GIWA_by_Upbit mainnet has NOT launched yet 🔸 Scammers created a fake network using GIWA’s Chain ID 9134 🔸 A fraudulent bridge was used to attract ETH 🔸 1,335+ addresses interacted with it 🔸 ~767.65 ETH was deposited 🔸 766.25 ETH ($2.08M) was drained ON-CHAIN PROOF: An Ethereum transaction shows 766.254 ETH transferred, worth approximately $2.08M. Block: 26067309 IMPORTANT: GIWA had repeatedly warned that its mainnet was not live. DYORSWAP also clarified this was not a direct smart-contract hack. VICTIM COMPENSATION: DYORSWAP says it has already compensated affected users with 200+ ETH from its own funds, while investigations into the attackers and fund flows continue. KEY LESSON: Never trust an RPC, bridge, Chain ID or network simply because it looks legitimate. Always verify through official sources. #GIWA

    Open source
  3. PR

    ProtosArticle ·

    DYORSWAP users tricked into sending 767 ETH to fake bridge contract Crypto scammers managed to trick DYORSWAP, a multi-chain decentralized exchange, into integrating a spoofed version of upcoming blockchain GIWA over the weekend, leading to losses of $2 million. Over one thousand users eager to be early to a new chain sent a total of 767 ETH to the fake bridge contract, which was later withdrawn by the scammers before the proceeds were funnelled into Tornado Cash. stop bridge and trade in giwa and we are checking — DYORSWAP (@DYORSWAPDEX) September 27, 2026 Read more: Bitget’s eighth birthday ends with a $352M hack Shortly after the bridged funds were drained, DYORSWAP admitted that “the so-called GIWA Mainnet we previously identified was in fact a fake chain set up by scammers.” Ironically, DYORSWAP takes its name from the abbreviation of the popular phrase “do your own research,” which is often touted as the key to staying safe in crypto. In using the same chain ID as the legitimate GIWA network, 9134, the falsified OP Stack chain was made to “appear legitimate during [DYORSWAP’s] initial verification.” DYORSWAP’s statement also mentions “specific suspicious messages” which may have planted the false information among the DYORSWAP community. The spoofed bridge, which had been deployed shortly after 6 PM UTC on Saturday, was drained just over 12 hours later. DYORSWAP offered users who had bridged less than five ETH a 40% refund. Addresses that surpassed that threshold are to be considered on a case by case basis. That’s not my chain “Powered by UPbit,” the South Korean centralized exchange, GIWA is an upcoming Layer 2 network, built on the OP Stack, which launched its testnet last year. The official GIWA X account was forced to emphatically debunk the existence of its mainnet. However, the post came too late, just minutes before the fake GIWA bridge contract was emptied. One onlooker called the heist “social engineering at the highest level.” someone faked the entire GIWA chain setup, got the bridge/RPC picked up by DYOR, and made $2m+ in a few hours social engineering at the highest level https://t.co/RpUX7yvZux pic.twitter.com/E5MS97OOgA — stablemark (@stablemark_) September 27, 2026 Read more: DeFi hack attack: Three exploits snatch $11M in a single day DYORSWAP published a later update identifying addresses that, “based on timing and behavior,” it believes were behind the scam, funded from exchanges Binance and Gate. The post also tallied 1,335 addresses which had bridged a total of 767.65 ETH, almost all of which was later drained. It paints DYORSWAP as a victim alongside its users, and claims to have distributed over 200 ETH in compensation. An address claiming to be from the DYORSWAP team has reached out to the scammers on-chain requesting the return of the stolen funds. Got a tip? Send us an email securely via Protos Leaks . For more informed news and investigations, follow us on X , Bluesky , and Google News , or subscribe to our YouTube channel. The post DYORSWAP users tricked into sending 767 ETH to fake bridge contract appeared first on Protos .

    Open source
  4. CT

    Coin TelegraphArticle ·

    Scammers steal $2M in ETH as fake GIWA network fools DYORSWAP DYORSWAP said it paid more than 200 ETH in compensation, while Upbit operator Dunamu’s GIWA warned that its mainnet had not launched.

    Open source