Live Prices
Ethereum

Fake GIWA Blockchain Scam Steals $2M in Ethereum From 1,333 Wallets

TheCryptoDesk Editorial · 3m read
Fake GIWA Blockchain Scam Steals $2M in Ethereum From 1,333 Wallets

Fraudsters created a fully functional counterfeit network disguised as Upbit-backed GIWA's upcoming Ethereum Layer 2 mainnet, stealing 767 ETH (worth roughly $2 million) from 1,333 wallets.

How the Fake Chain Deceived Users

The scam leveraged anticipation surrounding GIWA, a self-managed enterprise chain being developed on Optimism's OP Stack by Dunamu, the operator of South Korea's largest cryptocurrency exchange, Upbit. Dunamu and the Optimism Foundation announced in May that GIWA is planned as the first Self-Managed OP Enterprise chain. To fool users, the fraudulent network operated an RPC endpoint, cross-chain bridge, and Chain ID 9134—the expected identifier for GIWA's planned production network.

However, GIWA confirmed on X that claims of a leaked production RPC were false, clarifying that no mainnet currently exists. Its official documentation lists only the GIWA Sepolia testnet, which uses Chain ID 91342.

Community members from DYORSWAP initially interacted with the fraudulent environment before discovering the deception. DYORSWAP stated: "The fake network used the correct GIWA Chain ID (9134), which made it appear legitimate during our initial verification. We have also identified specific suspicious messages and individuals in the related community that may be connected to this incident."

On-Chain Traces and Fund Movements

According to pseudonymous blockchain analyst Stablemark, wallets tied to the attack were funded through ChangeHero on Sept. 26. Approximately 11 hours later, the Safe wallet controlling the scheme and fake bridge went live. Over the following 13 hours, 1,333 wallets deposited 767 ETH.

Once deposits accumulated, the operators altered the bridge's portal code and drained 766 ETH in a single transaction. The security incident highlights ongoing threat risks across web3, coming alongside other recent exploits like Bitget freezing withdrawals after a $387.5M breach.

Following the drain, 177 ETH was routed through Tornado Cash, while 589 ETH remained distributed across four wallets at the time of Stablemark's update.

Compensation Details and Investigations

DYORSWAP has initiated a compensation plan after reviewing affected addresses. Wallets that bridged less than 5 ETH will receive 40% compensation of their cross-chain deposit. Claims involving more than 5 ETH are subject to individual identity and address verification due to potential links to fraudulent activity.

DYORSWAP published a distribution address and warned victims to verify details through official channels to avoid secondary scams. It is also preserving RPC logs, bridge addresses, transaction data, and community communications to assist investigators.

Key Takeaways

  • Deceptive Setup: Attackers cloned GIWA's anticipated Layer 2 mainnet using its planned Chain ID 9134 to lure users.
  • Drained Funds: A total of 1,333 wallets deposited 767 ETH, after which operators modified bridge code to steal 766 ETH in one transaction.
  • Laundering Activity: The attackers sent 177 ETH through Tornado Cash, leaving 589 ETH across four wallets.
  • Partial Compensation: DYORSWAP is covering 40% of losses for wallets that bridged under 5 ETH.

Why It Matters

This incident illustrates an escalating tactic where attackers build full-featured, fake Layer 2 environments mimicking anticipated blockchain releases. Because EVM chain IDs are self-reported and do not validate RPC or bridge ownership, users cannot rely solely on wallet network matching for security. Traders must verify production launch announcements exclusively through official core developer feeds before interacting with new cross-chain bridges.

Terms in this article

Read next