Scammers stole 766.25 Ether, valued at over $2 million, from a fake GIWA blockchain bridge after decentralized exchange DYORSWAP initially identified it as the legitimate project's mainnet. The fraudulent bridge received 767.65 ETH from 1,335 distinct addresses before the funds were drained.
DYORSWAP published a reconstruction of the incident on Monday, detailing the scam's mechanics. The exchange confirmed its own smart contracts were not compromised during the exploit and initiated a reimbursement process, distributing over 200 ETH from its own treasury to affected users.
GIWA, an Ethereum Layer 2 network developed by Upbit operator Dunamu, issued a warning on Sunday, clarifying its mainnet had not yet launched. The project stated it does not have its mainnet running currently and cautioned against any purported mainnet connection details circulating online.
The fake chain, using 9134 as its Chain ID, deployed an OP Stack-style infrastructure, a bridge, and a batcher—demonstrating significant technical sophistication. The impersonating chain showed real-time user activity, including buys, sells, and token launches, before the theft occurred.
After detecting the fund drain, DYORSWAP declared: "Until further notice, DO NOT use any unofficial GIWA Mainnet RPC, bridge, or contract, and DO NOT send funds to any related addresses." The DEX is continuing to investigate the incident, tracing the bridge deployer, funding sources, suspected test wallets and final recipient addresses.
Dunamu launched GIWA's Sepolia testnet in September 2025. In April, Dunamu partnered with Hana Financial and POSCO International to test a cross-border remittance system based on GIWA Chain, using real trade transactions.
Users criticized DYORSWAP's role in initially validating the fake chain as legitimate, arguing the DEX's endorsement directly enabled the bridge attacks. The incident underscores how social engineering exploits persist in crypto—attackers don't need to break code when they can break trust.

