Key Takeaways
- A fake GIWA Ethereum L2 chain drained 766 ETH (over $2M) from 1,335 users who bridged funds.
- Scammers deployed a complex fake chain with functioning bridges, initially deceiving DYORSWAP.
- DYORSWAP is investigating the scam and refunding users, but faces backlash for enabling it.
Fake Giwa L2 Chain Deployment Scheme Causes Over 760 ETH in Losses
A new sophisticated scheme involving the launch of a fake Ethereum L2 solution has been reported for the first time, affecting over a thousand users who bridged their funds to the chain.
The chain, which used 9134 as its Chain ID number, was identified by DYORSWAP, a multi-chain decentralized exchange (DEX), as the mainnet for GIWA, an Upbit-backed project at first, taking early adopters to quickly bridge funds to the chain to take advantage of the financial opportunities next.
Initially, some claimed the scam only involved taking a normal ETH address and posting it as an L2 chain. Nonetheless, in its official report, DYORSWAP stressed this was not the case, as the chain deployment included an OP stack-style infrastructure, a bridge, and a batcher, indicating a larger degree of sophistication.
The theft was executed after over 1,335 addresses bridged funds to the contract, with approximately 766.25 ETH drained from these users, valued at over $2 million at the time of writing.
Before the funds were drained, DYORSWAP identified real movement in the impersonating chain, with user transactions including buys, sells, and token launches happening in real time.
“Until further notice, DO NOT use any unofficial GIWA Mainnet RPC, bridge, or contract, and DO NOT send funds to any related addresses,” DYORSWAP declared after detecting that user funds were drained.
Nonetheless, as the incident happened, the real Giwa project clarified that it had not stealth-launched its mainnet. “We DO NOT have our mainnet running currently. Any of those posts claiming that they have GIWA mainnet RPC information are NOT TRUE,” Giwa explained on social media.
While it denied direct responsibility in the attack, saying the funds were drained from the fake chain, DYORSWAP started a reimbursement process for affected users, claiming it had already distributed over 200 ETH from its own funds.
DYORSWAP stressed that it will continue to investigate and reconstruct the whole fake chain transaction history to identify and trace the attacker’s addresses.
Even so, users criticized DYORSWAP’s approach, arguing that without their involvement, none would have noticed the chain launch or bridged funds onto it, labeling it a social engineering scam.
The fake Giwa mainnet launch scheme follows a series of security incidents targeting both decentralized and centralized platforms, which are keeping crypto holders on constant alert.


