Newsroom

Scammers Drain $2 Million Through Fake GIWA Network

28 September, 2026   /   News   /  AI   /   Tags:  dyorswap, giwa, bridge, mainnet, fake

Scammers Drain $2 Million Through Fake GIWA Network

DYORSWAP lost more than $2 million in ETH after connecting to a counterfeit Ethereum Layer 2 that mimicked the unreleased GIWA mainnet, but the exchange compensated users with its own funds and continues tracing the operators

The fraudulent network launches on September 27

Scammers deployed a fake GIWA Ethereum Layer 2 network on September 27 at 2:10:59 p.m. ET. The counterfeit chain used the exact same Chain ID of 9134 that the real GIWA project planned for its mainnet. It featured a bridge, batcher and other infrastructure modeled on Optimism’s OP Stack, allowing it to post transactions directly to Ethereum.

The bridge contract was deployed at address 0xbA9938C0b96A70E6479661B915e7E481fE435ab2 by operator address 0x119e68B59C44291F76324c76377B776D0b4Dd38c. The deployment transaction appears in Ethereum block 26,063,309.

Deployment time: September 27, 2026 — 02:10:59 UTC+8 Deployment transaction: 0x15146622a9b0f539670b527c488f9f4d789f77241202b852f16ce4d9c63e0c9a

The network became live with a functioning bridge that immediately began accepting deposits.

Deposits flood the fake bridge

Within eight hours of deployment, the bridge received deposits from 1,335 addresses totaling approximately 767.65 ETH. Scammers then withdrew 766.25 ETH in a single transaction recorded in Ethereum block 26,067,309.

The draining transaction was: 0x1f3c0a2375a6f043a4f2473f822398587d9af5225e4dc1275ca0eeda67dc7306.

DYORSWAP identified three wallets that deposited in the exact same second, block 26,063,370, shortly after the bridge launched. Two of these wallets had been funded by Binance and Gate addresses roughly 25 days earlier and remained inactive until the fraudulent network went live. These deposits totaled exactly 0.4 ETH and appeared consistent with test wallets used to verify the bridge’s functionality.

DYORSWAP reconstructs the events

DYORSWAP stated its own smart contracts were not compromised. The DEX had simply connected users to what it initially believed was the real GIWA mainnet because the Chain ID matched official documentation. The exchange quickly traced the bridge, funding sources, batcher infrastructure and recipient addresses.

From the Ethereum data published by the fake chain, DYORSWAP reconstructed 1,479 actions on the counterfeit network, including 1,148 successful trades, token launches and pool interactions involving 298 wallets and 104 liquidity pools.

The funds drained from the bridge left the fake L2 without real ETH backing, causing the value of assets shown on the network, including DYOR liquidity pools, to lose their underlying redemption.

Compensation begins immediately

DYORSWAP used its own treasury to distribute more than 200 ETH to affected users. Compensation criteria include 40 percent of bridged amounts for deposits under 5 ETH, with larger claims reviewed separately. The exchange preserved all RPC records, bridge addresses, transaction data and community communications for the investigation.

In a detailed post on X, DYORSWAP explained the decision: “Although DYOR did not control the fraudulent bridge and did not execute the drain, we did not want affected users to face the consequences alone. We moved as quickly as possible to reconstruct the affected-address dataset and begin compensation.”

DYOR has already distributed more than 200 ETH to affected users
DYORSWAP

GIWA officially denies mainnet claims

GIWA, developed by Upbit operator Dunamu, issued a clear statement that its mainnet was not running. “We DO NOT have our mainnet running currently. Any of those posts claiming that they have GIWA mainnet RPC information are NOT TRUE,” the project posted on X.

Dunamu had launched only the Sepolia testnet in September 2025 using Optimism’s OP Stack. In April, the company had announced plans with Hana Financial and POSCO International to test a cross-border remittance system on the real GIWA Chain using live trade transactions. Official documentation listed the mainnet as under development.

GIWA provided contract details only for the Sepolia testnet, with Chain ID 91342, confirming the mainnet Chain ID 9134 used by the scammers had never been active.

Investigation continues

DYORSWAP is tracing the bridge deployer, funding sources including ChangeHero, early test wallets, batcher addresses and subsequent fund movements. The company has not yet identified the drain recipient or established the final recovery amount.

In its September 27 post, DYORSWAP noted suspicious community messages and individuals that may be linked to the incident but emphasized that every conclusion would be based on verifiable on-chain evidence. The exchange stated it would distinguish between confirmed infrastructure, linked wallets, suspicious addresses and genuine victims.

The fake network operated for only a short period before shutting down. Identities of the operators and the exact recovery of the stolen ETH remain under investigation.

Key detailsDetails
Bridge contract address0xbA9938C0b96A70E6479661B915e7E481fE435ab2
Deployer address0x119e68B59C44291F76324c76377B776D0b4Dd38c
Funding source before deploymentChangeHero-associated address: 0x016606Acc6B0cFE537acc221e3bf1bb44B4049Ee
Deposits received767.65 ETH from 1,335 addresses
Funds drained766.25 ETH
DYORSWAP compensationMore than 200 ETH distributed
Real GIWA statusMainnet not launched; only Sepolia testnet active
```
Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.