NewsCryptoFake GIWA Layer 2 Network Drains 766 ETH From 1,335 Wallets

Fake GIWA Layer 2 Network Drains 766 ETH From 1,335 Wallets

Author: CoinTrust·

Key Takeaways

  • •A fraudulent Layer 2 network impersonating GIWA's unreleased mainnet drained approximately 766 ETH from 1,335 wallets, with community estimates placing losses near $2 million.
  • •The fake chain went live on Sept. 26 using chain ID 9134, the identifier reserved for the genuine GIWA network, and operated a working bridge with OP Stack compatibility.
  • •DYORSWAP mistakenly listed the counterfeit network as the real GIWA mainnet, which lent credibility to the scheme and accelerated user deposits.
  • •GIWA stated on Sept. 27 that its mainnet had not launched, that the reported RPC endpoints were fabricated, and that the project has no separate native token.
  • •DYORSWAP has begun compensating victims from its treasury, allocating over 200 ETH for larger losses and applying a 40% flat rate for smaller ones.
Fake GIWA Layer 2 Network Drains 766 ETH From 1,335 Wallets

A fraudulent Ethereum Layer 2 network impersonating the unreleased mainnet of GIWA drained approximately 766 ETH from 1,335 wallets before the scheme was identified, according to reports. The attackers built a fully functioning counterfeit blockchain, complete with a cross-chain bridge, a transaction batcher, and compatibility with the OP Stack, the open-source toolkit widely used to launch Ethereum Layer 2 networks. Community estimates placed the total losses at close to $2 million, although the exact value may vary with cryptocurrency prices.

GIWA is a Layer 2 network under development by Dunamu, the South Korean company behind Upbit, one of South Korea's largest cryptocurrency exchanges (official site: giwa.io). Layer 2 networks run on top of Ethereum and settle their transactions back to the main chain, a design intended to reduce fees for users. Because GIWA's official mainnet had not launched when the fraudulent network appeared, the attackers were able to present the counterfeit infrastructure as an early version of the legitimate project. A pre-launch project has no official documentation or verified endpoints for users to check a claimed deployment against, which is precisely the gap a counterfeit can occupy.

Counterfeit Network Went Live With GIWA's Reserved Chain ID

The counterfeit network went live on Sept. 26 using chain ID 9134, the identifier reserved for the genuine GIWA network. Chain IDs are intended to distinguish blockchain networks from one another and to help prevent transactions from being replayed across incompatible chains. In a typical Layer 2 launch, the chain ID is published alongside official documentation and verified RPC endpoints so that wallets and block explorers can confirm they are communicating with the correct network.

By adopting GIWA's reserved identifier, the attackers made a fully operational fake Layer 2 appear connected to the legitimate project, turning a technical identifier into a key component of the fraud.

The scheme was not limited to a static website or fabricated documentation. The fake network ran infrastructure capable of processing real transactions and operated a bridge that accepted ETH deposits directly from Ethereum mainnet. Its OP Stack compatibility further reinforced the appearance of an authentic Layer 2 deployment. Because the OP Stack is open source, the same components that let teams launch legitimate networks quickly are available to anyone, so a technically convincing deployment does not by itself establish who is operating a chain.

The operation gained additional credibility after DYORSWAP, a decentralized exchange (dyorswap.finance), mistakenly listed the counterfeit network as the genuine GIWA mainnet. The listing gave users another reason to trust the network and helped accelerate deposits.

Approximately 767.65 ETH was transferred through the fraudulent bridge before the attackers began draining funds. About 766.25 ETH was ultimately taken from affected wallets, according to the reported figures.

GIWA Confirms Its Mainnet Has Not Launched

GIWA publicly clarified on Sept. 27 that its official mainnet was still unavailable and that infrastructure associated with the counterfeit deployment, including claimed RPC endpoints, was fabricated. RPC endpoints are the connection interfaces that wallets and applications use to interact with a blockchain. The project also emphasized that GIWA does not have a separate native token: the network is designed to use ETH for transaction fees, meaning users should not treat an alleged "GIWA token" as an official asset associated with the network.

FYI, we haven't launched our mainnet yet
No possibility of RPC leakage as well since we've never launched it
"DYOR" and stay safe from FUDs and scams

— GIWA (@GIWA_by_Upbit) September 27, 2026

The incident demonstrated how infrastructure that appears technically authentic can create substantial risks when users rely on identifiers or third-party listings without independently verifying the source. DYORSWAP acknowledged that it had inadvertently contributed to the incident, attributing the initial failure to the counterfeit network's use of the reserved chain ID, which allowed the fraudulent deployment to pass preliminary verification checks.

DYORSWAP Begins Compensating Affected Users

Following the discovery, DYORSWAP began compensating affected users from its treasury. More than 200 ETH had reportedly been allocated as reparations to users who suffered larger losses. For smaller losses, the platform adopted a flat compensation rate of 40%, according to the information provided. The compensation effort does not eliminate the underlying security issue, but it represents an attempt to address losses associated with the mistaken network listing.

I don't know how I could emphasize this further : We DO NOT have our mainnet running currently. Any of those posts claiming that they have GIWA mainnet RPC information are NOT TRUE. Please, please check the contracts that you interact with and PLEASE STAY SAFE

— GIWA (@GIWA_by_Upbit) September 27, 2026

Community members also identified unusual trading activity involving a meme token known as $FAKER during the period surrounding the incident. The reported activity has added another area of interest as efforts continue to reconstruct the sequence of events.

Chain ID Verification Emerges as a Security Concern

The attack highlights a potential weakness in relying on chain IDs as proof of network authenticity. Although these identifiers are designed to distinguish blockchain networks, a reserved identifier can potentially be misused before an official network launch if verification procedures do not account for deployment status.

Compensation progress update: We have completed the review of all affected addresses. For addresses that bridged less than 5 ETH, we will compensate 40% of the bridged amount, regardless of whether the funds were used for trading. The same compensation rate will apply to all…

— DYORSWAP (@DYORSWAPDEX) September 27, 2026

The incident shows that a chain ID alone is insufficient to establish that an unreleased blockchain network is authentic, particularly when supporting infrastructure and third-party listings can also be fabricated or misconfigured.

— DYORSWAP (@DYORSWAPDEX) September 27, 2026

GIWA and DYORSWAP have urged users to avoid unofficial RPC endpoints, contracts, and other infrastructure associated with the counterfeit network. Investigators and community members are continuing efforts to trace the stolen ETH and identify those responsible. For users tracking GIWA's eventual genuine launch, the officially published chain ID, documentation, and verified RPC endpoints are the details to rely on when confirming the real network.

The incident adds another example of how attackers can combine legitimate blockchain technology with misleading identity signals to create convincing fraud. It also underscores the need for wallets, decentralized applications, and infrastructure providers to verify network provenance through multiple independent sources before directing users or funds to a newly deployed chain.

Source: CoinTrust