Fake GIWA Blockchain Scam Drains $2 Million in ETH
Deceptive Bridge Steals Millions in Ether
Cybercriminals stole approximately $2 million worth of Ether (ETH) by tricking users into sending funds to a fake bridge for the GIWA blockchain. The decentralized exchange (DEX) known as DYORSWAP initially mistook the fraudulent setup for the official launch of the project's mainnet.
The incident highlights the risks associated with new blockchain networks that have not yet officially launched. Users sent funds believing they were interacting with the legitimate system, only for the scammers to drain the majority of the assets.
Key figures from the theft
- A total of 767.65 ETH was deposited into the fraudulent bridge by 1,335 different addresses.
- Attackers successfully withdrew 766.25 ETH from the bridge.
- DYORSWAP has committed more than 200 ETH from its own funds to compensate affected users.
Official warning from the real project
GIWA is an Ethereum layer-2 network being developed by Dunamu, the operator behind the South Korean exchange Upbit. On Sunday, the official GIWA account clarified that its mainnet had not launched yet.
The project explicitly stated that any connection details circulating online claiming to be for the mainnet were false. "We do not have our mainnet running currently," the project wrote in a public statement.
Investigation and background
DYORSWAP reported that its internal smart contracts were not hacked. Instead, the team is actively tracing the individual who deployed the fake bridge, the sources of funding used for the scam, and the wallets that received the stolen funds.
This event occurred despite legitimate progress by the real GIWA project. Dunamu launched the Sepolia testnet in September 2025 using technology from Optimism. Additionally, in April, Dunamu partnered with Hana Financial and POSCO International to test a cross-border payment system based on the GIWA Chain.
Current status of recovery
While DYORSWAP has begun reimbursing victims with its own capital, the identity of the scammers remains unknown. The exchange is continuing its investigation to locate the deployer of the fake bridge and the addresses holding the stolen funds.