A fake GIWA mainnet tricked 1,333 wallets into sending $2 million in ETH, then drained nearly all the funds. The scam shows how easy it is to fool users with lookalike networks and weak verification.
Scammers built a fake version of the GIWA blockchain and stole nearly $2 million in ETH. They took advantage of gaps in how users check networks and bridges. The fake network looked like GIWA's upcoming Ethereum Layer 2 mainnet. It used a misleading Chain ID and copied infrastructure details. In the end, 1,333 wallets sent 767 ETH to the scam. Almost all of it was drained in one move.
How the scam worked
The attackers set up a copycat blockchain that matched GIWA's planned mainnet. They used a fake Chain ID (9134), a lookalike RPC endpoint, and a bridge under their control. This made the network seem real to users and even some community projects. DYORSWAP, in an official update, said the attack came from a fake network pretending to be GIWA Chain 9134. It was not a hack of DYORSWAP's contracts, but a case of malicious infrastructure. The bridge was run by the attackers. GIWA's team confirmed their mainnet had not launched. They said any talk of a leaked production RPC was false. Users were told not to use unofficial RPCs, bridges, or contracts. The only real testnet, GIWA Sepolia, uses Chain ID 91342. That is different from the fake network's ID.
Over 1,333 wallets interacted with the fake GIWA network before 766 ETH was drained via a malicious bridge in a single transaction.
On-chain data shows the scammers spent hours getting ready before the first big deposits. Wallets tied to the scam were funded through ChangeHero on September 26. About 11 hours later, the Safe wallet that controlled the bridge went live. Over the next 13 hours, 1,333 wallets sent a total of 767 ETH. The attackers then swapped out the bridge's code and drained 766 ETH in one transaction. Almost nothing was left for depositors. Independent reports confirm about 766 ETH was pulled out through the fake bridge, with more than 1,333 wallets caught up before the theft.
Technical vulnerabilities exposed
This scam worked because of a basic flaw in how Ethereum-compatible networks are checked. A Chain ID tells a wallet which network it is on, but does not prove who controls the RPC endpoint or bridge. By copying GIWA's expected Chain ID, the scammers made the fake network look real to both users and automated tools. But they kept full control over the infrastructure and the funds. This let them collect deposits and then steal them. GIWA's official docs only mention the testnet GIWA Sepolia (Chain ID 91342). This shows why users need to check network details with official sources.
After the theft, 177 ETH was sent through Tornado Cash, a privacy mixer that makes tracking harder. Another 589 ETH was still spread across four wallets at the time of the last update from Stablemark. Moving funds through mixers and many wallets makes it tough for investigators to freeze or get assets back.
GIWA's mainnet had not launched at the time of the incident, and the only legitimate testnet was GIWA Sepolia with Chain ID 91342. The fraudulent network used a different Chain ID (9134), which was not documented in official project materials.
DYORSWAP, which had users hit by the scam, announced a partial compensation plan. The project said it started emergency steps, including hiring on-chain tracking experts, saving logs and addresses, and looking at ways to pay back users from its treasury. Wallets that bridged less than 5 ETH would get 40% of their lost funds. Bigger claims would need identity and address checks because of worries about phishing or other scams. DYORSWAP published a compensation address and told users to check it through official channels. They warned that scammers might try to trick people with fake reimbursement offers. Even with this plan, most users will get back less than half of what they lost. Larger claims are still under review.
GIWA is being built by Dunamu, the company behind Upbit, South Korea's biggest crypto exchange. It uses Optimism's OP Stack. The mainnet is planned as the first Self-Managed OP Enterprise chain, but it had not launched at the time of the scam. This case shows the risks users face when using unofficial infrastructure, especially when a new network is expected or during migration. Similar problems have happened before, like the Bitget hack that led to a major theft of user funds.
Market and security context
On-chain records show 767 ETH, worth about $2 million at the time, was sent to the fake GIWA network by 1,333 wallets. Of that, 766 ETH was drained in one transaction after the attackers changed the bridge's code. Only 1 ETH was left. As of the last update, 177 ETH had gone through Tornado Cash, and 589 ETH was still traceable in four wallets. The size of the loss and the use of privacy mixers make recovery harder and show how tough blockchain security and user checks can be.
Ethereum and its Layer 2 networks still see heavy use and lots of transactions. But this incident proves that technical know-how alone does not keep users safe. Both users and developers need to double-check network details, especially when a mainnet launch or migration is coming up but not finished.
Chain IDs help Ethereum-compatible networks tell themselves apart, but they are not a security tool. A Chain ID just tells a wallet which network it is talking to. It does not prove who runs the RPC endpoints, bridges, or contracts. This lets attackers set up convincing fakes, especially when a new network is expected but not live yet. Users should always check network details in official docs and channels, and avoid using infrastructure that is not clearly approved by the project or its developers.