Scammers created a counterfeit version of the Upbit-backed GIWA blockchain and used it to drain approximately $2 million in Ether from more than 1,300 wallets, according to reports from DYORSWAP and blockchain analysts. The fraudulent infrastructure mimicked GIWA’s anticipated Ethereum Layer 2 mainnet and included an RPC endpoint, a cross-chain bridge, and Chain ID 9134—the identifier associated with the planned production network.
GIWA, developed by Dunamu, operator of South Korea’s largest crypto exchange Upbit, using Optimism’s OP Stack, has not yet launched its mainnet. In an X post, the project stated that claims about a leaked production RPC were false because no mainnet RPC exists. Its documentation lists only GIWA Sepolia with Chain ID 91342, while the production network remains under development.
DYORSWAP, whose community initially interacted with the purported network, later confirmed the chain was fraudulent and warned users against unofficial RPC endpoints, bridges, and contracts. The project said the fake network used the correct GIWA Chain ID 9134, which made it appear legitimate during initial verification, and that suspicious messages and individuals in the related community may be connected to the incident.
On-chain data analyzed by pseudonymous blockchain analyst Stablemark showed that wallets tied to the operation were funded through ChangeHero on September 26. About 11 hours later, the Safe wallet controlling the scheme and the fake bridge went live. Over the following 13 hours, 1,333 wallets deposited a combined 767 ETH. The operators then changed the bridge’s portal code and drained 766 ETH in a single transaction. Stablemark reported that 177 ETH was routed through Tornado Cash, while another 589 ETH remained spread across four wallets at the time of the update.
DYORSWAP said 1,335 addresses sent roughly 767.65 ETH through the fraudulent bridge before 766.25 ETH was withdrawn. The exchange emphasized that its own contracts were not compromised; instead, the attackers built infrastructure that appeared to represent the unreleased GIWA mainnet. The project has begun compensating some victims using its own funds, reimbursing more than 200 ETH so far. Wallets that bridged less than 5 ETH will receive compensation equal to 40% of their cross-chain amount, while larger claims require identity and address verification because some larger wallets could be linked to phishing or other fraudulent activity.
The incident highlights a security risk outside traditional smart contract auditing: counterfeit blockchain infrastructure can become an attack surface, especially around anticipated mainnet launches when users are seeking early access. For GIWA, the immediate task is separating the legitimate project from the fraudulent network while its actual mainnet remains unreleased.