Fake GIWA mainnet tricks users into losing 766 ETH
Security & Exploits ·
A counterfeit version of Upbit's layer-2 network GIWA was used to lure deposits before more than 766 ETH disappeared through a fraudulent bridge listed as live on DYORswap.
Official channels have stated that GIWA's actual mainnet has not gone live, meaning any RPC endpoint claiming to connect to a functioning GIWA network is not genuine. Despite this, a counterfeit chain was constructed and circulated with enough polish to pass as the real deployment. DYORswap has acknowledged that it had listed this fake network under the belief it was operational, and that users who bridged funds through it lost over 766 ETH in the process.
The scheme worked in part because the fabricated network used GIWA's correct chain identifier, numbered 9134, which allowed it to clear initial checks and appear authentic during listing review. That detail helped the fraudulent bridge blend in alongside legitimate infrastructure long enough for deposits to flow in before the deception was caught.
DYORswap says it is now working with outside security specialists to trace the movement of funds on-chain and examine the wallets and transactions tied to the incident. The platform has also said it is preserving records, including community chat logs, the fake RPC details, and bridge contract data, and has flagged individuals and messages in related community channels that may be linked to the operation.
The exchange has said it intends to draw on its own treasury to reimburse affected users, though it has not yet defined who qualifies, how losses will be verified, or how large the compensation pool will be, pending completion of its investigation. Separate reporting on the episode has described total losses from the fake layer-2 scam as exceeding $2 million, suggesting the drained amount may extend beyond the 766 ETH figure tied specifically to DYORswap.
What remains unclear is the full scope of addresses involved, whether any funds can be recovered or frozen, and when GIWA's genuine mainnet will actually launch, a step that would remove the ambiguity scammers exploited in the first place. DYORswap has said further updates will follow as the inquiry progresses.