Fake GIWA Bridge Drains 766 ETH After DYORSWAP Mistakes Scam for Real Network
Fraudulent bridge loses $2 million in ETH
A fake Layer 2 network pretending to be the Upbit-backed GIWA project had 766.25 ETH, worth roughly $2 million, stolen from its Ethereum bridge on September 27. The loss occurred after the decentralized exchange DYORSWAP mistakenly believed the fake network was real and allowed users to deposit funds.
The scam network used a specific chain ID (9134) that matched GIWA's expected identifier, tricking the exchange into deploying its platform there. Users were able to trade and launch tokens on this fraudulent chain before the funds were drained.
How the theft unfolded
- Total deposits into the fake bridge reached approximately 767.65 ETH from 1,335 different addresses.
- Etherscan records show the stolen ETH was moved to a receiving wallet and then repeatedly sent to Tornado Cash, a privacy mixer.
- The attack involved a malicious contract upgrade signed by the bridge controllers within a single transaction.
- DYORSWAP confirmed the loss happened in the bridge infrastructure, not through a flaw in its own trading code.
GIWA confirms the network is fake
The actual GIWA project issued a warning on September 27 stating that their mainnet is not yet running. They clarified that any connection details or RPC information circulating for a live mainnet were false. This confirmation helped distinguish the legitimate project from the impersonator.
DYORSWAP offers partial refunds
In response to the incident, DYORSWAP announced a compensation plan. The exchange promised to reimburse 40% of the bridged amount to eligible users who deposited less than 5 ETH. For accounts that bridged more than 5 ETH, separate verification steps are required.
The exchange stated it would use its own treasury funds to cover these costs and had already distributed over 200 ETH. DYORSWAP noted that this repayment would not fully restore all lost funds and did not set a deadline for completing the process. Users will not need to pay fees or submit manual claims to receive their share.
What remains uncertain
While the exchange has committed to paying out 40% to smaller depositors, it has not confirmed if the remaining 60% of losses for these users or the full losses for larger depositors will ever be recovered. The identity of the attackers behind the malicious contract upgrade also remains unknown.
Why this matters for users
This event highlights the risks of interacting with new Layer 2 networks that lack official verification. Even established exchanges can be fooled by sophisticated scams that mimic legitimate project identifiers and infrastructure. It underscores the importance of verifying network status directly with official project channels before depositing funds.