Fake GIWA Mainnet / Bridge Scam (impersonation of GIWA L2, listed by DYORSWAP)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·4n2ZEP…oJz4Summary
In late September 2026, unidentified attackers deployed a fully functional counterfeit Ethereum Layer 2 network that impersonated the not-yet-launched GIWA Chain — a project developed by South Korean exchange operator Dunamu (parent of Upbit). By registering the legitimate project's publicly reserved chain ID (9134) before the real mainnet went live, and by operating a working OP Stack-compatible bridge, the attackers deceived the decentralized exchange DYORSWAP into listing the fake chain as genuine. Approximately 1,335 wallet addresses deposited 767.65 ETH (~$2 million) into the fraudulent bridge; 766.25 ETH was subsequently drained. DYORSWAP later paid over 200 ETH in partial compensation from its own treasury.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(8 events)
September 2025
GIWA launches Sepolia testnet (chain ID 91342). Production mainnet not yet live. Chain ID 9134 publicly reserved for the forthcoming mainnet.
CryptoSlateApril 2026
Dunamu announces partnership with Hana Financial and POSCO International for a GIWA Chain-based cross-border remittance pilot, raising public awareness of the forthcoming GIWA mainnet.
CoinTelegraph2 September 2026
Approximately 25 days before the attack, two test wallets linked to the attackers were allegedly funded via Binance and Gate.io accounts, then left dormant.
CryptoTimes26 September 2026
Attacker deployer wallet receives approximately 0.045 ETH funding via ChangeHero, approximately 8.5 hours before the fake bridge is deployed. Fake GIWA mainnet infrastructure reportedly launched approximately 11 hours after this funding.
CryptoSlate / CryptoTimes27 September 2026
Fake bridge deployed at approximately 02:10:59 UTC+8 (Ethereum block 26063331). Three verification deposits of 0.4 ETH total arrive 39 blocks later. DYORSWAP integrates the fraudulent chain. Over the following 12-13 hours, 1,335 wallet addresses deposit 767.65 ETH. GIWA issues a public warning. The drain is executed at block 26067309, removing 766.25 ETH (~$2 million). 177 ETH is routed through Tornado Cash; ~589 ETH spread across four wallets.
CryptoTimes / Protos / KuCoin News27 September 2026
GIWA publicly confirms the fake mainnet, stating 'The so-called GIWA Mainnet previously circulated is a fraudulent chain set up by scammers' and that its official mainnet is not live.
KuCoin News (GIWA statement)28 September 2026
DYORSWAP confirms the fake chain incident, clarifies its own smart contracts were not compromised, announces compensation plan: 40% refund for deposits under 5 ETH, case-by-case review for larger amounts. DYORSWAP publishes compensation address 0xdf25f88aa6cde9937fdcfcf10fa349528c79dbf9.
KuCoin News (DYORSWAP statements) / PANews28 September 2026
DYORSWAP reports having distributed over 200 ETH (~26% of stolen funds) in compensation from its own treasury. Investigation of attacker identities ongoing via on-chain tracing and potential cooperation with Binance and Gate.io.
KuCoin News / Protos / FinanceFeedsDecision Log
- hash: 3yYLHgiuQfAL2mX28Y869HjXF5bsRwPzbw4AHThoPJCZ
This investigation is cryptographically anchored to the Solana blockchain (1 event). 13 of 15 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 10/1/2026, 12:19:15 PM
last updated: 10/2/2026, 3:30:05 AM
avoid.net — verified advice for a post-truth world