Threat actors deployed a fake Ethereum layer-2 blockchain impersonating Giwa, an Upbit-backed project, resulting in the theft of over 760 ETH from crypto traders who bridged their funds to the fraudulent chain.
The fake chain, identified by DYORSWAP, a multichain decentralized exchange, used chain ID 9134 and incorporated sophisticated infrastructure including an OP stack-style system, bridge, and batcher. Over 1,335 addresses bridged funds to the malicious contract, with approximately 766.25 ETH drained in total, valued at over $2 million at the time of the incident.
Before the funds were stolen, DYORSWAP observed active transaction activity on the fake chain, including token buys, sells, and launches occurring in real time. The exchange issued a warning after detecting the theft: "Until further notice, DO NOT use any unofficial GIWA Mainnet RPC, bridge, or contract, and DO NOT send funds to any related addresses."
The legitimate Giwa project denied involvement in the attack and clarified it had not launched its mainnet. "We DO NOT have our mainnet running currently," the project stated on social media. "Any of those posts claiming that they have GIWA mainnet RPC information are NOT TRUE."
DYORSWAP initiated a reimbursement process for affected users, stating it had already distributed over 200 ETH from its own funds. The exchange said it would continue investigating the fake chain's transaction history to identify the attacker's addresses.
Users criticized DYORSWAP's role in enabling the scam, arguing that the exchange's involvement in promoting the chain facilitated the social engineering attack.


