Newsroom
28 September, 2026 / News / AI / Tags: dyorswap, giwa, bridge, mainnet, fake

DYORSWAP lost more than $2 million in ETH after connecting to a counterfeit Ethereum Layer 2 that mimicked the unreleased GIWA mainnet, but the exchange compensated users with its own funds and continues tracing the operators
Scammers deployed a fake GIWA Ethereum Layer 2 network on September 27 at 2:10:59 p.m. ET. The counterfeit chain used the exact same Chain ID of 9134 that the real GIWA project planned for its mainnet. It featured a bridge, batcher and other infrastructure modeled on Optimism’s OP Stack, allowing it to post transactions directly to Ethereum.
The bridge contract was deployed at address 0xbA9938C0b96A70E6479661B915e7E481fE435ab2 by operator address 0x119e68B59C44291F76324c76377B776D0b4Dd38c. The deployment transaction appears in Ethereum block 26,063,309.
The network became live with a functioning bridge that immediately began accepting deposits.
Within eight hours of deployment, the bridge received deposits from 1,335 addresses totaling approximately 767.65 ETH. Scammers then withdrew 766.25 ETH in a single transaction recorded in Ethereum block 26,067,309.
The draining transaction was: 0x1f3c0a2375a6f043a4f2473f822398587d9af5225e4dc1275ca0eeda67dc7306.
DYORSWAP identified three wallets that deposited in the exact same second, block 26,063,370, shortly after the bridge launched. Two of these wallets had been funded by Binance and Gate addresses roughly 25 days earlier and remained inactive until the fraudulent network went live. These deposits totaled exactly 0.4 ETH and appeared consistent with test wallets used to verify the bridge’s functionality.
DYORSWAP stated its own smart contracts were not compromised. The DEX had simply connected users to what it initially believed was the real GIWA mainnet because the Chain ID matched official documentation. The exchange quickly traced the bridge, funding sources, batcher infrastructure and recipient addresses.
From the Ethereum data published by the fake chain, DYORSWAP reconstructed 1,479 actions on the counterfeit network, including 1,148 successful trades, token launches and pool interactions involving 298 wallets and 104 liquidity pools.
The funds drained from the bridge left the fake L2 without real ETH backing, causing the value of assets shown on the network, including DYOR liquidity pools, to lose their underlying redemption.
DYORSWAP used its own treasury to distribute more than 200 ETH to affected users. Compensation criteria include 40 percent of bridged amounts for deposits under 5 ETH, with larger claims reviewed separately. The exchange preserved all RPC records, bridge addresses, transaction data and community communications for the investigation.
In a detailed post on X, DYORSWAP explained the decision: “Although DYOR did not control the fraudulent bridge and did not execute the drain, we did not want affected users to face the consequences alone. We moved as quickly as possible to reconstruct the affected-address dataset and begin compensation.”
GIWA, developed by Upbit operator Dunamu, issued a clear statement that its mainnet was not running. “We DO NOT have our mainnet running currently. Any of those posts claiming that they have GIWA mainnet RPC information are NOT TRUE,” the project posted on X.
Dunamu had launched only the Sepolia testnet in September 2025 using Optimism’s OP Stack. In April, the company had announced plans with Hana Financial and POSCO International to test a cross-border remittance system on the real GIWA Chain using live trade transactions. Official documentation listed the mainnet as under development.
GIWA provided contract details only for the Sepolia testnet, with Chain ID 91342, confirming the mainnet Chain ID 9134 used by the scammers had never been active.
DYORSWAP is tracing the bridge deployer, funding sources including ChangeHero, early test wallets, batcher addresses and subsequent fund movements. The company has not yet identified the drain recipient or established the final recovery amount.
In its September 27 post, DYORSWAP noted suspicious community messages and individuals that may be linked to the incident but emphasized that every conclusion would be based on verifiable on-chain evidence. The exchange stated it would distinguish between confirmed infrastructure, linked wallets, suspicious addresses and genuine victims.
The fake network operated for only a short period before shutting down. Identities of the operators and the exact recovery of the stolen ETH remain under investigation.
| Key details | Details |
|---|---|
| Bridge contract address | 0xbA9938C0b96A70E6479661B915e7E481fE435ab2 |
| Deployer address | 0x119e68B59C44291F76324c76377B776D0b4Dd38c |
| Funding source before deployment | ChangeHero-associated address: 0x016606Acc6B0cFE537acc221e3bf1bb44B4049Ee |
| Deposits received | 767.65 ETH from 1,335 addresses |
| Funds drained | 766.25 ETH |
| DYORSWAP compensation | More than 200 ETH distributed |
| Real GIWA status | Mainnet not launched; only Sepolia testnet active |









