Skip to content
Est. MMXXVIVol. VI · № 343RSS
Blockchain Breaches

An archive of cryptocurrency security incidents — hacks, exploits, bridge failures and rug pulls, documented with on-chain evidence.

Dossier № 343Phishing / Social Engineering

Fake GIWA Blockchain Bridge Scam

Scammers spun up a counterfeit GIWA Layer-2 network with the real chain ID, tricked a DEX into listing it as the mainnet, and drained about $2 million in ETH from 1,335 wallets through a fake bridge.

Date
Chain(s)
Status
Funds Stolen

On September 26, 2026, scammers stole roughly $2 million in ETH by building an entire counterfeit GIWA blockchain — a fake Ethereum Layer 2 — and luring users to bridge real funds into it. GIWA, the genuine L2 developed by Upbit operator Dunamu, had not launched, and the impostor exploited the confusion.

What happened

The attackers stood up a fraudulent network using chain ID 9134 — the exact identifier reserved for GIWA's planned mainnet — complete with an RPC endpoint and a cross-chain bridge, so it looked authentic to wallets and tooling. Wallets tied to the operation were funded through the ChangeHero swap service, and roughly 11 hours later the Safe wallet controlling the scheme and the fake bridge went live. The decisive break came when the decentralized exchange DYORSWAP mistook the counterfeit for GIWA's real mainnet and listed it, lending the scam credibility and accelerating deposits. Users who bridged in sent about 767.65 ETH from 1,335 addresses; the scammers drained roughly 766.25 ETH — around $2 million.

Aftermath

The real GIWA team, backed by Dunamu, stated that its mainnet had not launched and warned that any "mainnet connection details" circulating online were fraudulent. DYORSWAP acknowledged its error, warned users, and offered 40% compensation to smaller victims. The stolen ETH itself was not recovered, so the status here is stolen.

Why it matters

This was social engineering at the infrastructure layer: rather than phishing individual signatures, the attackers forged an entire chain, reusing the legitimate chain ID so that everything — RPC, bridge, explorer cues — looked real. A single trusted intermediary getting it wrong (a DEX listing the fake as genuine) turned a plausible imposter into a $2 million drain. As with wallet-drainer phishing such as the repeat whale phishing drain, users must verify official contract and network details directly from the project, never from a third-party listing — and treat an unlaunched mainnet as a bright red flag.

Sources & on-chain evidence

  1. [01]cointelegraph.comhttps://cointelegraph.com/news/fake-giwa-blockchain-scam-drains-2m-eth
  2. [02]cryptobriefing.comhttps://cryptobriefing.com/scammers-steal-2m-fake-giwa-blockchain/
  3. [03]crypto-economy.comhttps://crypto-economy.com/fake-giwa-bridge-scammers-drain-2m-in-ether-from-1335-wallets/

Related filings