Attackers drain 766 ETH from counterfeit GIWA blockchain targeting 1,333 wallets
Scammers built a fully functional counterfeit GIWA blockchain using GIWA’s expected Chain ID to deceive 1,333 wallets into depositing 767 ETH, worth approximately $2 million, before draining 766 ETH in a single transaction. The incident exposes a critical vulnerability in how Ethereum Virtual Machine networks are identified and trusted, with serious implications for institutional users managing large positions across multiple chains.
- Attackers deposited 767 ETH across 1,333 wallets on a fake GIWA network using the legitimate Chain ID 9134 before draining 766 ETH in one transaction.
- 177 ETH was routed through Tornado Cash to obscure its trail, while 589 ETH remained spread across four wallets.
- DYORSWAP is offering 40% compensation only to victims who deposited less than 5 ETH, leaving most users with substantial unrecovered losses.
- $2 million Total value of ETH stolen through the fake GIWA blockchain operation.
- 767 ETH Total deposits across 1,333 wallets before attackers changed the bridge’s portal code.
- 40% Compensation rate offered by DYORSWAP to victims depositing under 5 ETH.
Scammers constructed a fully operational replica of GIWA, South Korea’s Upbit exchange’s planned Ethereum Layer 2 network, according to first reporting by CryptoSlate. The fake network included a complete RPC endpoint, cross-chain bridge, and, critically, Chain ID 9134, the identifier associated with GIWA’s planned mainnet launch. The deception appeared legitimate because it mimicked legitimate technical markers, but GIWA stated on X that no production mainnet RPC had ever been released, and its documentation lists only GIWA Sepolia testnet, which uses Chain ID 91342.
Attackers Waited 11 Hours Before Draining the Bridge
On-chain analysis by pseudonymous blockchain researcher Stablemark shows the attackers methodically staged the operation. On September 26, wallets tied to the scheme were funded through ChangeHero. About 11 hours later, the Safe wallet controlling the scheme and its fake bridge went live. Over the next 13 hours, 1,333 wallets deposited a combined 767 ETH.
The operators then changed the bridge’s portal code and drained 766 ETH in a single transaction, according to Stablemark.
The sequence reveals a deliberate strategy: the bridge remained operational long enough to accumulate deposits before the operators replaced its controlling code and removed funds.
The attack succeeded because EVM networks are identified by Chain ID, a marker that tells a wallet which network it is connected to, but a Chain ID does not verify who controls the RPC endpoint or bridge infrastructure behind that network.
By using GIWA’s expected Chain ID 9134, the operators made the environment appear consistent with the anticipated mainnet while retaining full control of the infrastructure receiving user funds.
Chain ID Weakness Exposes Institutional Users to Infrastructure Impersonation
The vulnerability at the heart of this attack is structural, not incidental. A Chain ID is a purely functional identifier used by wallets to route transactions to the correct network, but it carries no cryptographic proof of network ownership or operator identity. DYORSWAP, whose community initially interacted with the purported network, later said the chain was fraudulent and warned users against unofficial RPC endpoints, bridges and contracts, noting that “the fake network used the correct GIWA Chain ID (9134), which made it appear legitimate during our initial verification.”
For institutional investors and treasury managers moving assets across Layer 2 networks, this means that standard wallet-level network verification offers no protection against sophisticated infrastructure spoofing. A user connecting to the correct Chain ID cannot distinguish between a legitimate RPC endpoint and a fraudulent one without additional out-of-band verification, such as checking against official documentation or using whitelisted endpoints. As more major exchanges, including Upbit with GIWA through its partnership with Optimism announced in May, launch their own proprietary Layer 2 networks, the attack surface for such impersonation grows. Institutional users must now treat RPC endpoint verification as a critical risk control, not a routine configuration step.
Stolen Funds Begin Mixing as Recovery Window Narrows
Of the 766 ETH stolen, 177 ETH has already been routed through Tornado Cash, complicating forensic tracing.
Another 589 ETH remains spread across four wallets and remains visible on-chain as of Stablemark’s update. The timing is critical: assets moved to coin mixers become difficult or impossible to trace, while those remaining in visible wallets can theoretically be frozen by exchanges or recovered through law enforcement cooperation.
The longer funds remain unmixed, the higher the recovery likelihood, but each passing hour increases the probability of further transfers to privacy services or dark pool exchanges.
DYORSWAP has announced a limited compensation plan. Wallets that bridged less than 5 ETH will receive compensation equal to 40% of their cross-chain amount, leaving smaller victims with losses of 60% or more.
Claims involving more than 5 ETH will be handled separately and require identity and address verification, because DYORSWAP said some larger wallets could be linked to phishing or other fraudulent activity.
The project has published an official compensation address but warned victims to verify it through official channels, citing the risk that scammers could exploit the incident again using fake reimbursement requests.
The CCS read. We see the fraud as a pressure test on GIWA’s actual launch readiness. Upbit, as a Self-Managed OP Enterprise operator, will control its own sequencer, meaning institutional users moving material positions will be entirely reliant on Dunamu’s infrastructure security and authentication practices, not on Optimism Foundation oversight. The fake chain incident signals that official documentation and public announcements are now mandatory due diligence, not optional reading.
The open question is whether this fraud will accelerate or delay GIWA’s mainnet launch. Dunamu has not disclosed a revised timeline, and the Optimism Foundation’s partnership announcement made no public commitment to a specific go-live date. Institutional investors and compliance officers at major exchanges will be watching how Upbit responds, both in hardening GIWA’s onboarding and authentication flow, and in any contribution to victim recovery, before deciding whether to route significant volume through a newly launched exchange chain.