Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
- Sequence
- #1
- Score
- →
- Cluster
- mainnet-beta
- Slot
- 452285717
- Off-chain at
- 2026-10-01T12:19:27.306Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- 3yYLHgiuQfAL2mX28Y869HjXF5bsRwPzbw4AHThoPJCZ
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (21774 chars)
{"actor":"system:backfill","investigation_id":"01494b56-984e-47cb-ab96-8de03af4c51c","kind":"publish","page_slug":"fake-giwa-mainnet-bridge-scam-impersonation-of-giwa-l2-listed-by-dyorswap","published_at":"2026-10-01T12:19:27.203Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Fake GIWA Mainnet / Bridge Scam (impersonation of GIWA L2, listed by DYORSWAP)","sections":[{"content":"GIWA is an Ethereum Layer 2 network under development by Dunamu, the South Korean company that operates the Upbit cryptocurrency exchange. GIWA is built on Optimism's OP Stack and was positioned as the first 'Self-Managed OP Enterprise chain.' A Sepolia testnet (chain ID 91342) launched in September 2025, but as of the time of the attack in September 2026, GIWA's production mainnet had not gone live. In April 2026, Dunamu announced a partnership with Hana Financial and POSCO International to pilot a GIWA Chain-based cross-border remittance system. The project had publicly reserved chain ID 9134 for its forthcoming mainnet — a fact that the attackers exploited.","heading":"Background: The Real GIWA Project","severity":"low","sources":[{"credibility":2,"name":"Scammers steal over $2M by creating fake GIWA blockchain — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/scammers-steal-2m-fake-giwa-blockchain/"},{"credibility":2,"name":"Fake GIWA Chain Drained 766 ETH After Running as a Real Layer 2 — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/28/fake-giwa-chain-drained-766-eth-after-1335-addresses-bridged-into-it/"},{"credibility":2,"name":"Scammers Steal $2M in ETH as Fake GIWA Network Fools DYORSWAP — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/fake-giwa-blockchain-scam-drains-2m-eth"}]},{"content":"The attack exploited a gap in the EVM ecosystem: any operator can deploy an EVM-compatible network and set its chain ID to any value, including one that a legitimate project has publicly announced but not yet launched. The attackers registered chain ID 9134 — GIWA's publicly known forthcoming mainnet identifier — and used it to stand up a working Layer 2 network using the OP Stack architecture. The fake network included a functional cross-chain bridge accepting real ETH deposits from Ethereum mainnet, an OP Stack compatibility layer, and a transaction batcher. This infrastructure was sophisticated enough to pass initial inspection, distinguishing this incident from simpler website spoofs or phishing pages. The attackers modified the bridge's portal contract code after accumulating deposits, then drained the locked ETH in a single transaction. DYORSWAP's smart contracts were not compromised; the fraud operated entirely at the network infrastructure level.","heading":"Attack Mechanism: Chain ID Pre-Registration Exploit","severity":"critical","sources":[{"credibility":2,"name":"Crypto scammers built an entire fake blockchain to steal over $2 million — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/crypto-scammers-built-an-entire-fake-blockchain-to-steal-over-2-million/"},{"credibility":2,"name":"Fake GIWA Chain Drained 766 ETH After Running as a Real Layer 2 — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/28/fake-giwa-chain-drained-766-eth-after-1335-addresses-bridged-into-it/"},{"credibility":2,"name":"DYORSWAP users tricked into sending 767 ETH to fake bridge contract — Protos","type":"news_article","url":"https://protos.com/dyorswap-users-tricked-into-sending-767-eth-to-fake-bridge-contract/"}]},{"content":"According to on-chain data reported by CryptoTimes, the deployer received an initial funding of approximately 0.045 ETH from an address associated with the ChangeHero instant exchange service roughly 8.5 hours before bridge deployment. Two test wallets linked to the operation were reportedly traced to funding from Binance and Gate.io accounts approximately 25 days before the attack, then left dormant. The fake bridge was deployed at approximately 02:10:59 UTC+8 on September 27, 2026, corresponding to Ethereum block 26063331. Three verification deposits totaling 0.4 ETH arrived 39 blocks after launch (approximately 02:18:47 UTC+8). Over the following approximately 12-13 hours, 1,335 wallet addresses deposited a combined 767.65 ETH. The drain was executed at Ethereum block 26067309, removing approximately 766.25 ETH. GIWA issued a public warning minutes before the bridge was emptied. Post-drain, on-chain records showed 177 ETH was routed through Tornado Cash and 589 ETH spread across four wallets. DYORSWAP published an on-chain message requesting the attackers return stolen funds.","heading":"Timeline of the Attack","severity":"critical","sources":[{"credibility":2,"name":"Fake GIWA Chain Drained 766 ETH After Running as a Real Layer 2 — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/28/fake-giwa-chain-drained-766-eth-after-1335-addresses-bridged-into-it/"},{"credibility":2,"name":"Crypto scammers built an entire fake blockchain to steal over $2 million — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/crypto-scammers-built-an-entire-fake-blockchain-to-steal-over-2-million/"},{"credibility":2,"name":"DYORSWAP users tricked into sending 767 ETH to fake bridge contract — Protos","type":"news_article","url":"https://protos.com/dyorswap-users-tricked-into-sending-767-eth-to-fake-bridge-contract/"}]},{"content":"DYORSWAP, a decentralized exchange, integrated the fraudulent GIWA Chain 9134 after the attackers' infrastructure appeared to match the publicly announced GIWA mainnet parameters. DYORSWAP subsequently confirmed the incident was 'not due to an attack on the DYOR contract, but rather because its application was affected by the fraudulent network GIWA Chain 9134.' The platform recorded 1,479 operations on the fake chain, involving 298 wallets and 104 pools, with 1,148 successful transactions. DYORSWAP stated it was tracing the bridge deployer, funding sources, suspected test wallets, and recipient addresses, including coordination with centralized exchanges (Binance and Gate.io) where early funding wallets were reportedly sourced. The platform paid over 200 ETH — approximately 26% of stolen funds — in compensation from its own treasury before investigation completion. For addresses that bridged less than 5 ETH, DYORSWAP offered 40% reimbursement. Addresses exceeding 5 ETH were evaluated individually; DYORSWAP noted some large-deposit addresses were suspected of involvement in related phishing or fraudulent bridge operations. The official compensation distribution address published by DYORSWAP was 0xdf25f88aa6cde9937fdcfcf10fa349528c79dbf9. DYORSWAP stated it would not ask users to transfer funds or pay fees as part of compensation.","heading":"DYORSWAP's Role and Response","severity":"high","sources":[{"credibility":2,"name":"DYORSWAP Clarifies Incident Not a Contract Hack, Compensates Users with Over 200 ETH — KuCoin News","type":"news_article","url":"https://www.kucoin.com/news/flash/dyorswap-clarifies-incident-not-a-contract-hack-compensates-users-with-over-200-eth"},{"credibility":2,"name":"DYORSWAP Compensates Over 200 ETH to Users Affected by the Fake GIWA Mainnet Incident — KuCoin News","type":"news_article","url":"https://www.kucoin.com/news/flash/dyorswap-compensates-over-200-eth-to-users-affected-by-fake-giwa-mainnet-incident"},{"credibility":2,"name":"DYORSWAP Fake Bridge Scam Drains $2M in ETH — Compensation Plan Details (PANews)","type":"news_article","url":"https://panews.io/articles/01a0e2ef-1611-77db-b498-a5f213cdc923"},{"credibility":2,"name":"Fake GIWA Bridge Drains 766 ETH From 1,335 Users; DYORSWAP Pays 200 ETH Compensation — Gokhshtein","type":"news_article","url":"https://gokhshtein.com/news/2026-09-28-fake-giwa-bridge-drains-766-eth-from-1335-users-dyorswap"}]},{"content":"GIWA's development team confirmed the fraudulent nature of the circulating mainnet infrastructure, stating: 'The so-called GIWA Mainnet previously circulated is a fraudulent chain set up by scammers' and 'We do not have our mainnet running currently.' GIWA advised users against connecting to non-official RPCs, bridges, or contracts, and noted that projects using the OP Stack should verify Ethereum-side Rollup contracts and confirm RPC origins from official sources or trusted partners. GIWA also stated it had engaged a security team to track funds and preserve evidence including chat logs, RPC information, bridge addresses, and transaction records. As of reporting, GIWA had not announced its own compensation plan, noting that details would follow the completion of its investigation.","heading":"GIWA (Dunamu) Official Position","severity":"medium","sources":[{"credibility":2,"name":"GIWA Confirms Fake Mainnet and Bridge Scam, Over 766 ETH Stolen — KuCoin News","type":"news_article","url":"https://www.kucoin.com/news/flash/giwa-confirms-fake-mainnet-and-bridge-scam-over-766-eth-stolen"},{"credibility":2,"name":"Scammers Steal $2M in ETH as Fake GIWA Network Fools DYORSWAP — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/fake-giwa-blockchain-scam-drains-2m-eth"}]},{"content":"Approximately 1,335 wallet addresses deposited a combined 767.65 ETH into the fraudulent bridge. Of this, 766.25 ETH was drained — approximately $2 million at prevailing ETH prices near the time of the attack. DYORSWAP reported having distributed over 200 ETH in compensation from its own treasury, covering roughly 26% of the total stolen amount. Post-drain on-chain tracking indicated 177 ETH was routed through Tornado Cash, rendering those funds substantially more difficult to recover. The remaining approximately 589 ETH was reported spread across four wallets, making it theoretically traceable and potentially recoverable through coordination with centralized exchanges. No law enforcement action or court proceedings had been publicly announced as of the time of reporting.","heading":"Financial Impact","severity":"critical","sources":[{"credibility":2,"name":"Fake GIWA Bridge Scam Drains About $2 Million in Ether From 1,335 Wallets — FinanceFeeds","type":"news_article","url":"https://financefeeds.com/fake-giwa-bridge-scam-drains-about-2-million-in-ether-from-1335-wallets/"},{"credibility":2,"name":"Crypto scammers built an entire fake blockchain to steal over $2 million — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/crypto-scammers-built-an-entire-fake-blockchain-to-steal-over-2-million/"},{"credibility":2,"name":"DYORSWAP users tricked into sending 767 ETH to fake bridge contract — Protos","type":"news_article","url":"https://protos.com/dyorswap-users-tricked-into-sending-767-eth-to-fake-bridge-contract/"}]},{"content":"Security analysts and reporters covering the incident noted that the attack represents a novel and potentially repeatable pattern. Because the EVM specification does not prevent any operator from deploying a network with a chain ID that another project has publicly announced but not yet used in production, any project that reserves a chain ID before mainnet launch faces an analogous impersonation window. The attackers did not need to compromise any existing infrastructure; they simply built a convincing parallel infrastructure that matched the published parameters of an anticipated launch. DYORSWAP's integration of the fraudulent chain without sufficient verification of its provenance was the proximate mechanism by which user funds were put at risk. As CryptoSlate reported, the incident 'highlights that chain verification can become a security risk before users interact with any DeFi application.' The attack pattern is distinct from traditional smart contract exploits, phishing sites, or private key theft, and may require new verification protocols in DEX listing processes and wallet software chain-ID validation.","heading":"Novel Attack Pattern and Systemic Risk","severity":"high","sources":[{"credibility":2,"name":"Crypto scammers built an entire fake blockchain to steal over $2 million — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/crypto-scammers-built-an-entire-fake-blockchain-to-steal-over-2-million/"},{"credibility":2,"name":"Fake GIWA L2 Drains 766 ETH From 1,300 Wallets in $2M Chain ID Exploit — Gokhshtein Media","type":"news_article","url":"https://gokhshtein.com/news/2026-09-28-fake-giwa-l2-drains-766-eth-from-1300-wallets-in-2m-chain"},{"credibility":2,"name":"Fake GIWA Network Drains 766 ETH in Layer 2 Scam — UseTheBitcoin","type":"news_article","url":"https://usethebitcoin.com/eth/fake-giwa-layer2-scam/"}]},{"content":"The identities of the attackers remain unknown as of the most recent reporting. On-chain forensics reported by CryptoTimes traced the initial deployer funding to an address associated with ChangeHero. Two preparatory test wallets were allegedly funded through Binance and Gate.io accounts approximately 25 days before the attack. DYORSWAP stated it was cooperating with security teams and tracing these funding sources, suggesting potential coordination with the named centralized exchanges for account-level identification. No arrests, indictments, or formal regulatory referrals had been publicly announced at the time of reporting. Approximately 177 ETH was routed through Tornado Cash, reducing the likelihood of tracing those funds. The remaining approximately 589 ETH was reported spread across multiple wallets and had not been confirmed as frozen or recovered.","heading":"Attacker Identity and Investigation Status","severity":"high","sources":[{"credibility":2,"name":"Fake GIWA Chain Drained 766 ETH After Running as a Real Layer 2 — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/28/fake-giwa-chain-drained-766-eth-after-1335-addresses-bridged-into-it/"},{"credibility":2,"name":"DYORSWAP Responds to Fake GIWA Chain Incident, Reports Over 200 ETH in Compensation — KuCoin News","type":"news_article","url":"https://www.kucoin.com/news/flash/dyorswap-responds-to-fake-giwa-chain-incident-reports-over-200-eth-in-compensation"}]}],"sources_used":[{"credibility":2,"name":"GIWA Confirms Fake Mainnet and Bridge Scam, Over 766 ETH Stolen — KuCoin News","type":"news_article","url":"https://www.kucoin.com/news/flash/giwa-confirms-fake-mainnet-and-bridge-scam-over-766-eth-stolen"},{"credibility":2,"name":"Crypto scammers built an entire fake blockchain to steal over $2 million — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/crypto-scammers-built-an-entire-fake-blockchain-to-steal-over-2-million/"},{"credibility":2,"name":"DYORSWAP Confirms GIWA Mainnet Is a Fake Chain, Plans to Compensate Affected Users — KuCoin News","type":"news_article","url":"https://www.kucoin.com/news/flash/dyorswap-confirms-giwa-mainnet-is-a-fake-chain-plans-to-compensate-affected-users"},{"credibility":2,"name":"DYORSWAP users tricked into sending 767 ETH to fake bridge contract — Protos","type":"news_article","url":"https://protos.com/dyorswap-users-tricked-into-sending-767-eth-to-fake-bridge-contract/"},{"credibility":2,"name":"Fake GIWA Bridge Scam Drains About $2 Million in Ether From 1,335 Wallets — FinanceFeeds","type":"news_article","url":"https://financefeeds.com/fake-giwa-bridge-scam-drains-about-2-million-in-ether-from-1335-wallets/"},{"credibility":2,"name":"Fake GIWA Mainnet Compensation Plan — PANews","type":"news_article","url":"https://panews.io/articles/01a0e2ef-1611-77db-b498-a5f213cdc923"},{"credibility":2,"name":"Scammers Steal $2M in ETH as Fake GIWA Network Fools DYORSWAP — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/fake-giwa-blockchain-scam-drains-2m-eth"},{"credibility":2,"name":"Fake GIWA Chain Drained 766 ETH After Running as a Real Layer 2, With 1,335 Wallets Bridging In — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/28/fake-giwa-chain-drained-766-eth-after-1335-addresses-bridged-into-it/"},{"credibility":2,"name":"DYORSWAP Clarifies Incident Not a Contract Hack, Compensates Users with Over 200 ETH — KuCoin News","type":"news_article","url":"https://www.kucoin.com/news/flash/dyorswap-clarifies-incident-not-a-contract-hack-compensates-users-with-over-200-eth"},{"credibility":2,"name":"DYORSWAP Compensates Over 200 ETH to Users Affected by the Fake GIWA Mainnet Incident — KuCoin News","type":"news_article","url":"https://www.kucoin.com/news/flash/dyorswap-compensates-over-200-eth-to-users-affected-by-fake-giwa-mainnet-incident"},{"credibility":2,"name":"DYORSWAP Responds to Fake GIWA Chain Incident, Reports Over 200 ETH in Compensation — KuCoin News","type":"news_article","url":"https://www.kucoin.com/news/flash/dyorswap-responds-to-fake-giwa-chain-incident-reports-over-200-eth-in-compensation"},{"credibility":2,"name":"Fake GIWA Ethereum Layer 2 Drains 766 ETH From Crypto Traders — TokenPost","type":"news_article","url":"https://www.tokenpost.com/news/technology/24755"},{"credibility":2,"name":"Fake GIWA L2 Drains 766 ETH From 1,300 Wallets in $2M Chain ID Exploit — Gokhshtein Media","type":"news_article","url":"https://gokhshtein.com/news/2026-09-28-fake-giwa-l2-drains-766-eth-from-1300-wallets-in-2m-chain"},{"credibility":2,"name":"Fake GIWA Network Drains 766 ETH in Layer 2 Scam — UseTheBitcoin","type":"news_article","url":"https://usethebitcoin.com/eth/fake-giwa-layer2-scam/"},{"credibility":2,"name":"Scammers steal over $2M by creating fake GIWA blockchain — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/scammers-steal-2m-fake-giwa-blockchain/"}],"summary":"In late September 2026, unidentified attackers deployed a fully functional counterfeit Ethereum Layer 2 network that impersonated the not-yet-launched GIWA Chain — a project developed by South Korean exchange operator Dunamu (parent of Upbit). By registering the legitimate project's publicly reserved chain ID (9134) before the real mainnet went live, and by operating a working OP Stack-compatible bridge, the attackers deceived the decentralized exchange DYORSWAP into listing the fake chain as genuine. Approximately 1,335 wallet addresses deposited 767.65 ETH (~$2 million) into the fraudulent bridge; 766.25 ETH was subsequently drained. DYORSWAP later paid over 200 ETH in partial compensation from its own treasury.","timeline":[{"date":"2025-09","event":"GIWA launches Sepolia testnet (chain ID 91342). Production mainnet not yet live. Chain ID 9134 publicly reserved for the forthcoming mainnet.","source":"CryptoSlate","source_url":"https://cryptoslate.com/crypto-scammers-built-an-entire-fake-blockchain-to-steal-over-2-million/"},{"date":"2026-04","event":"Dunamu announces partnership with Hana Financial and POSCO International for a GIWA Chain-based cross-border remittance pilot, raising public awareness of the forthcoming GIWA mainnet.","source":"CoinTelegraph","source_url":"https://cointelegraph.com/news/fake-giwa-blockchain-scam-drains-2m-eth"},{"date":"2026-09-02","event":"Approximately 25 days before the attack, two test wallets linked to the attackers were allegedly funded via Binance and Gate.io accounts, then left dormant.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/09/28/fake-giwa-chain-drained-766-eth-after-1335-addresses-bridged-into-it/"},{"date":"2026-09-26","event":"Attacker deployer wallet receives approximately 0.045 ETH funding via ChangeHero, approximately 8.5 hours before the fake bridge is deployed. Fake GIWA mainnet infrastructure reportedly launched approximately 11 hours after this funding.","source":"CryptoSlate / CryptoTimes","source_url":"https://www.cryptotimes.io/2026/09/28/fake-giwa-chain-drained-766-eth-after-1335-addresses-bridged-into-it/"},{"date":"2026-09-27","event":"Fake bridge deployed at approximately 02:10:59 UTC+8 (Ethereum block 26063331). Three verification deposits of 0.4 ETH total arrive 39 blocks later. DYORSWAP integrates the fraudulent chain. Over the following 12-13 hours, 1,335 wallet addresses deposit 767.65 ETH. GIWA issues a public warning. The drain is executed at block 26067309, removing 766.25 ETH (~$2 million). 177 ETH is routed through Tornado Cash; ~589 ETH spread across four wallets.","source":"CryptoTimes / Protos / KuCoin News","source_url":"https://www.cryptotimes.io/2026/09/28/fake-giwa-chain-drained-766-eth-after-1335-addresses-bridged-into-it/"},{"date":"2026-09-27","event":"GIWA publicly confirms the fake mainnet, stating 'The so-called GIWA Mainnet previously circulated is a fraudulent chain set up by scammers' and that its official mainnet is not live.","source":"KuCoin News (GIWA statement)","source_url":"https://www.kucoin.com/news/flash/giwa-confirms-fake-mainnet-and-bridge-scam-over-766-eth-stolen"},{"date":"2026-09-28","event":"DYORSWAP confirms the fake chain incident, clarifies its own smart contracts were not compromised, announces compensation plan: 40% refund for deposits under 5 ETH, case-by-case review for larger amounts. DYORSWAP publishes compensation address 0xdf25f88aa6cde9937fdcfcf10fa349528c79dbf9.","source":"KuCoin News (DYORSWAP statements) / PANews","source_url":"https://www.kucoin.com/news/flash/dyorswap-confirms-giwa-mainnet-is-a-fake-chain-plans-to-compensate-affected-users"},{"date":"2026-09-28","event":"DYORSWAP reports having distributed over 200 ETH (~26% of stolen funds) in compensation from its own treasury. Investigation of attacker identities ongoing via on-chain tracing and potential cooperation with Binance and Gate.io.","source":"KuCoin News / Protos / FinanceFeeds","source_url":"https://www.kucoin.com/news/flash/dyorswap-compensates-over-200-eth-to-users-affected-by-fake-giwa-mainnet-incident"}]},"v":1}