GIWA official brand image
Scammers steal over $2M by creating fake GIWA blockchain
A fraudulent Ethereum Layer 2 network impersonating the unreleased GIWA mainnet drained roughly 766 ETH from over 1,300 wallets before the scheme was exposed
A group of scammers built an entire fake blockchain, complete with a bridge, a batcher, and OP Stack compatibility, to impersonate a real project that hadn’t even launched yet. The result: approximately 766 ETH drained from 1,335 addresses, with community estimates putting total losses near $2M.
The fraudulent network posed as the GIWA mainnet, a Layer 2 developed by Dunamu, the parent company behind South Korea’s largest crypto exchange, Upbit. GIWA’s actual mainnet hasn’t gone live. The scammers just got there first.
How the scam worked
On September 26, the attackers launched their counterfeit Ethereum L2 using chain ID 9134, the legitimate identifier reserved for the real GIWA network. That single detail, the correct chain ID, turned out to be the linchpin of the entire operation.
The fake chain featured a functional cross-chain bridge that accepted ETH deposits from Ethereum mainnet, a compatibility layer built on OP Stack technology, and a batcher to process transactions.
Things got worse when DYORSWAP, a decentralized exchange, inadvertently listed the fraudulent network as the genuine GIWA mainnet. With a legitimate DEX pointing users toward the fake chain, deposits accelerated. Roughly 767.65 ETH flowed across the bridge before the attackers moved to drain wallets, siphoning off approximately 766.25 ETH in total.
By September 27, GIWA publicly confirmed that its official mainnet had not launched and that any associated RPCs or infrastructure claims were entirely fabricated. The project stressed that no separate native token exists for GIWA, as the network is designed to use ETH for gas fees.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
DYORSWAP steps in to compensate victims
DYORSWAP acknowledged its role in the debacle relatively quickly. The platform explained that the fraudulent chain’s reuse of the reserved chain ID gave it an appearance of legitimacy that passed initial checks.
DYORSWAP moved to compensate affected users from its own treasury. The platform has already credited over 200 ETH in reparations to those who lost larger sums. Smaller losses are being handled at a flat 40% compensation rate.
Community members also flagged suspicious trading activity around a meme token called $FAKER in the period before the fraud was fully exposed.
A new playbook for crypto fraud
The core vulnerability exploited here is a gap in how chain IDs are managed and verified. Chain IDs are meant to be unique identifiers that prevent transaction replay attacks across different networks. When a project reserves one but hasn’t launched yet, there’s a window where bad actors can claim it.
Both GIWA and DYORSWAP have urged users to avoid unofficial endpoints and contracts. Investigatory efforts to trace the stolen funds and identify the perpetrators are ongoing.