CoinTrust

Fake GIWA Layer 2 Network Drains 766 ETH From Wallets

giwa

A fraudulent Ethereum Layer 2 network impersonating the unreleased GIWA mainnet drained about 766 ETH from 1,335 wallets before the scheme was identified, according to reports.

The attackers created a functioning counterfeit blockchain that included a cross-chain bridge, a transaction batcher, and compatibility with the OP Stack. Community estimates placed the total losses at close to $2 million, although the exact value may vary with cryptocurrency prices.

GIWA is a Layer 2 network being developed by Dunamu, the South Korean company behind Upbit. Its official mainnet had not launched when the fraudulent network appeared, allowing the attackers to present the counterfeit infrastructure as an early version of the legitimate project.

Fraudulent Network Used Reserved Chain ID

The counterfeit network went live on Sept. 26 using chain ID 9134, the identifier reserved for the genuine GIWA network. Chain IDs are intended to distinguish blockchain networks and help prevent transactions from being replayed across incompatible chains.

The attackers used GIWA’s reserved chain ID to make a fully operational fake Layer 2 appear connected to the legitimate project, turning a technical identifier into a key part of the fraud.

The fake network was not limited to a static website or fabricated documentation. It included infrastructure capable of processing transactions and a bridge that accepted ETH deposits from Ethereum mainnet. Its OP Stack compatibility further contributed to the appearance of an authentic Layer 2 deployment.

The operation gained additional credibility after DYORSWAP, a decentralized exchange, mistakenly listed the counterfeit network as the genuine GIWA mainnet. The listing gave users an additional reason to trust the network and helped accelerate deposits.

Approximately 767.65 ETH was transferred through the fraudulent bridge before the attackers began draining funds. About 766.25 ETH was ultimately taken from affected wallets, according to the reported figures.

GIWA Confirms Mainnet Had Not Launched

GIWA publicly clarified on Sept. 27 that its official mainnet was still unavailable and that infrastructure associated with the counterfeit deployment, including claimed RPC endpoints, was fabricated.

The project also clarified that GIWA does not have a separate native token. The network is designed to use ETH for transaction fees, meaning users should not treat an alleged GIWA token as an official asset associated with the network.


The incident demonstrated how infrastructure that appears technically authentic can create substantial risks when users rely on identifiers or third-party listings without independently verifying the source.

DYORSWAP acknowledged that it had inadvertently contributed to the incident. The exchange attributed the initial failure to the counterfeit network’s use of the reserved chain ID, which allowed the fraudulent deployment to pass preliminary verification checks.

DYORSWAP Begins User Compensation

Following the discovery, DYORSWAP began compensating affected users from its treasury. More than 200 ETH had reportedly been allocated as reparations to users who suffered larger losses.

For smaller losses, the platform adopted a flat compensation rate of 40%, according to the information provided. The compensation effort does not eliminate the underlying security issue but represents an attempt to address losses associated with the mistaken network listing.


Community members also identified unusual trading activity involving a meme token known as $FAKER during the period surrounding the incident. The reported activity has added another area of interest as efforts continue to reconstruct the sequence of events.

Chain ID Verification Emerges as Security Concern

The attack highlights a potential weakness in relying on chain IDs as proof of network authenticity. Although these identifiers are designed to distinguish blockchain networks, a reserved identifier can potentially be misused before an official network launch if verification procedures do not account for deployment status.


The incident shows that verifying a chain ID alone is insufficient to establish that an unreleased blockchain network is authentic, particularly when supporting infrastructure and third-party listings can also be fabricated or misconfigured.


GIWA and DYORSWAP have urged users to avoid unofficial RPC endpoints, contracts, and other infrastructure associated with the counterfeit network. Investigators and community members are continuing efforts to trace the stolen ETH and identify those responsible.

The incident adds another example of how attackers can combine legitimate blockchain technology with misleading identity signals to create convincing fraud. It also underscores the need for wallets, decentralized applications, and infrastructure providers to verify network provenance through multiple independent sources before directing users or funds to a newly deployed chain.

Exit mobile version