DYORSWAP Users Lose 767 ETH to Fake GIWA Bridge Scam
Massive loss from spoofed bridge
Crypto scammers deceived users of DYORSWAP, a multi-chain decentralized exchange, into sending 767 ETH to a fake bridge contract. This incident resulted in approximately $2 million in losses over the weekend.
The attackers created a counterfeit version of the upcoming GIWA blockchain. They convinced the exchange to integrate this fake network, leading more than 1,000 eager users to transfer their funds before the scammers withdrew the assets.
How the deception worked
- Scammers used the same chain ID (9134) as the legitimate GIWA network to appear valid during verification.
- The fake bridge was deployed on Saturday after 6 PM UTC and drained just over 12 hours later.
- Funds were funneled into Tornado Cash, a privacy protocol often used to obscure transaction trails.
- Suspicious messages may have planted false information within the DYORSWAP community prior to the attack.
Official response and confirmation
DYORSWAP admitted that the "GIWA Mainnet" they had identified was actually a fake chain set up by criminals. The platform noted that the impersonation was successful because it used the correct technical identifiers.
The official GIWA project, powered by South Korean exchange UPbit, also issued a statement debunking the existence of its mainnet. However, this warning came minutes after the fake bridge contract had already been emptied.
Compensation and ongoing efforts
DYORSWAP offered a 40% refund to users who bridged less than five ETH. Addresses with larger amounts will be reviewed on a case-by-case basis. The exchange stated it has distributed over 200 ETH in compensation so far.
The platform claims to have identified specific addresses involved in the scam, noting they were funded from Binance and Gate exchanges. An address linked to the DYORSWAP team has also reached out on-chain to request the return of stolen funds.
Why this matters for security
This event highlights the risks of social engineering in the crypto space. Despite DYORSWAP's name standing for "do your own research," the sophisticated nature of the fake chain setup bypassed initial checks. One observer described the heist as social engineering at the highest level.
Next steps for affected users
Users who lost funds are waiting to see if the remaining compensation will be processed. DYORSWAP continues to investigate the specific actors behind the attack based on timing and behavior patterns.