Fake GIWA Blockchain Scam Drains $2 Million in Ether

2 hour ago 2 sources negative

Key takeaways:

  • Fake GIWA bridge drains ETH, exposing pre-mainnet hype as a critical L2 security risk.
  • Investors should verify official RPC endpoints before bridging, as unlaunched L2s attract sophisticated phishing.
  • DYORSWAP's partial ETH refunds may ease victim losses, but GIWA trust remains damaged.

Scammers created a counterfeit version of the Upbit-backed GIWA blockchain and used it to drain approximately $2 million in Ether from more than 1,300 wallets, according to reports from DYORSWAP and blockchain analysts. The fraudulent infrastructure mimicked GIWA’s anticipated Ethereum Layer 2 mainnet and included an RPC endpoint, a cross-chain bridge, and Chain ID 9134—the identifier associated with the planned production network.

GIWA, developed by Dunamu, operator of South Korea’s largest crypto exchange Upbit, using Optimism’s OP Stack, has not yet launched its mainnet. In an X post, the project stated that claims about a leaked production RPC were false because no mainnet RPC exists. Its documentation lists only GIWA Sepolia with Chain ID 91342, while the production network remains under development.

DYORSWAP, whose community initially interacted with the purported network, later confirmed the chain was fraudulent and warned users against unofficial RPC endpoints, bridges, and contracts. The project said the fake network used the correct GIWA Chain ID 9134, which made it appear legitimate during initial verification, and that suspicious messages and individuals in the related community may be connected to the incident.

On-chain data analyzed by pseudonymous blockchain analyst Stablemark showed that wallets tied to the operation were funded through ChangeHero on September 26. About 11 hours later, the Safe wallet controlling the scheme and the fake bridge went live. Over the following 13 hours, 1,333 wallets deposited a combined 767 ETH. The operators then changed the bridge’s portal code and drained 766 ETH in a single transaction. Stablemark reported that 177 ETH was routed through Tornado Cash, while another 589 ETH remained spread across four wallets at the time of the update.

DYORSWAP said 1,335 addresses sent roughly 767.65 ETH through the fraudulent bridge before 766.25 ETH was withdrawn. The exchange emphasized that its own contracts were not compromised; instead, the attackers built infrastructure that appeared to represent the unreleased GIWA mainnet. The project has begun compensating some victims using its own funds, reimbursing more than 200 ETH so far. Wallets that bridged less than 5 ETH will receive compensation equal to 40% of their cross-chain amount, while larger claims require identity and address verification because some larger wallets could be linked to phishing or other fraudulent activity.

The incident highlights a security risk outside traditional smart contract auditing: counterfeit blockchain infrastructure can become an attack surface, especially around anticipated mainnet launches when users are seeking early access. For GIWA, the immediate task is separating the legitimate project from the fraudulent network while its actual mainnet remains unreleased.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.