A fraudulent Ethereum Layer 2 siphoned 766 ETH from more than 1,300 wallets in a sophisticated chain ID hijack. The scam targeted anticipation around GIWA, the unreleased L2 developed by Dunamu, parent company of South Korea's largest crypto exchange, Upbit.
The attackers deployed their counterfeit L2 on Sept. 26 using chain ID 9134—the legitimate identifier reserved for the authentic GIWA network. This single detail was the linchpin. The fake chain featured a functional cross-chain bridge accepting ETH deposits directly from mainnet, an OP Stack compatibility layer, and a transaction batcher. The infrastructure was convincing enough to fool users racing to participate in the anticipated launch.
DYORSWAP, a decentralized exchange, listed the fraudulent network as the genuine GIWA mainnet. That endorsement from a legitimate DEX accelerated deposit flow into scammer-controlled infrastructure. Approximately 767.65 ETH crossed the bridge before the attackers initiated the drain, ultimately extracting 766.25 ETH from affected wallets.
GIWA confirmed the fraud on Sept. 27, clarifying that its official mainnet had not launched and that any associated RPCs or infrastructure claims were fabricated. The project noted its network uses ETH for gas fees and has no separate native token.
DYORSWAP acknowledged its role, explaining that the fraudulent chain's reuse of reserved chain ID 9134 passed its verification checks. The platform compensated affected users from its own treasury, crediting over 200 ETH to those with larger losses and applying a flat 40 percent compensation rate to smaller ones.
Community members flagged suspicious trading activity around a meme token named $FAKER immediately before the scam's exposure, suggesting potential insider coordination.
The core vulnerability exposes a critical ecosystem gap: chain IDs are designed as unique identifiers to prevent transaction replay attacks between networks, but a window opens for malicious actors when a project reserves an ID before mainnet launch. GIWA and DYORSWAP have urged users to avoid all unofficial endpoints and contracts. Investigatory efforts are underway to trace the stolen funds and identify the perpetrators.