A fraudulent chain posing as Giwa’s Ethereum layer-2 network led to the loss of about 766.25 ETH from 1,335 addresses, according to details shared by DYORSWAP and the Giwa project. At the time cited in the report, the stolen funds were worth more than $2 million.

The incident appears to have gone beyond a simple wallet-address impersonation. DYORSWAP said the attackers deployed a more elaborate setup that resembled an OP Stack-style chain, complete with a bridge and batcher, which helped convince users that the network was legitimate.

How the fake network was presented

The chain used Chain ID 9134 and was identified by DYORSWAP, a multichain decentralized exchange, as Giwa’s mainnet. Giwa is described in the report as an Upbit-backed project, and the apparent mainnet launch prompted early users to bridge funds in anticipation of opportunities on the network.

DYORSWAP later said that activity on the impersonating chain looked real before the theft. According to the exchange, users were carrying out transactions including buys, sells, and token launches, adding to the impression that the chain was active and authentic.

Losses and warning after the drain

After users had moved funds onto the fake network, the assets were drained. The reported total reached roughly 766.25 ETH across 1,335 addresses.

Once the losses were detected, DYORSWAP warned users not to interact with any unofficial Giwa mainnet RPC endpoints, bridges, contracts, or related addresses until further notice. The exchange said the scam had involved a functioning chain environment rather than a basic address trick.

Giwa denial and DYORSWAP response

As the incident unfolded, Giwa stated on social media that it had not launched a mainnet and said posts claiming to provide Giwa mainnet RPC information were false. That statement became a key clarification, indicating that the network users had connected to was not operated by the real project.

DYORSWAP said the funds were drained from the fake chain and denied direct responsibility for the attack itself. Even so, it began compensating affected users and said it had already paid out more than 200 ETH from its own funds.

Backlash and the next step in the investigation

The reimbursement effort did not prevent criticism. Some users argued that without DYORSWAP’s identification of the chain as Giwa’s mainnet, many people would not have discovered the network or bridged assets to it, and they described the episode as a social-engineering scam.

DYORSWAP said it is continuing to investigate the incident and reconstruct the transaction history of the fake chain in an effort to identify and trace the attacker’s addresses. For now, the clearest confirmed next step is that the exchange is still processing reimbursements while the source of the fake network remains under investigation.

Source: news.bitcoin.com