NewsCryptoCounterfeit GIWA Network Drains 766 ETH After Users Bridge Funds to Fake Layer 2

Counterfeit GIWA Network Drains 766 ETH After Users Bridge Funds to Fake Layer 2

Author: Crypto Adventure·

Key Takeaways

  • •A counterfeit network impersonating GIWA collected approximately 767.65 ETH, nearly $2 million, from 1,335 addresses through an unofficial RPC endpoint and bridge.
  • •The fake network operated with chain ID 9134, one digit shorter than the 91342 configuration of GIWA's legitimate Sepolia testnet, and began running after its deployment on September 27.
  • •GIWA warned on X on September 27 that its mainnet was not running and that posts claiming to possess leaked mainnet RPC information were false.
  • •DYORSWAP has distributed more than 200 ETH from its own funds to affected users while the investigation is ongoing.
  • •Tracing efforts now cover the bridge deployer, early test wallets, batcher infrastructure, and the destinations that received the 766.25 ETH removed from the bridge.
Counterfeit GIWA Network Drains 766 ETH After Users Bridge Funds to Fake Layer 2

A counterfeit network impersonating GIWA, the Upbit-backed Layer 2 project, collected nearly $2 million in ETH after users were directed to an unofficial RPC endpoint and bridge for a mainnet that has not launched.

A total of 1,335 addresses bridged roughly 767.65 ETH into the fake network before approximately 766.25 ETH was transferred out. The fraudulent environment, which included an OP Stack-like bridge and batcher, began operating after its deployment on September 27.

GIWA's mainnet remains under development. The only publicly available GIWA network is GIWA Sepolia, an Ethereum testnet Layer 2 that uses chain ID 91342, test ETH, and the official sepolia-rpc.giwa.io endpoint, according to GIWA's official documentation.

Fake Network Used a Different Chain ID

The fraudulent network operated with chain ID 9134, one digit shorter than the 91342 configuration used by GIWA Sepolia.

Chain IDs are the identifiers wallets and applications use to tell EVM networks apart, so that single-digit difference was the verifiable technical marker separating the counterfeit setup from the configuration GIWA lists in its own documentation.

DYORSWAP had added a GIWA environment using chain ID 9134 alongside its deployments on other EVM networks, per its public documentation. As a result, the counterfeit chain appeared inside infrastructure that users could interpret as a live GIWA ecosystem deployment, even though no production GIWA network existed.

The fake Layer 2 went beyond a cloned website. It processed transactions, operated a bridge and batcher, and posted transaction batches to Ethereum, giving users an environment that behaved like a functioning Layer 2 before the funds were removed. That level of functionality shows how impersonation campaigns now operate at the infrastructure layer rather than only at the interface: a fake network can run its own bridge, batching, and Ethereum settlement while the project it copies has published only testnet documentation.

Three early deposits totaling 0.4 ETH entered only 39 blocks after the bridge became active. Two came from wallets making their first outbound transaction, and those addresses are now among the activity being investigated as possible test wallets connected to the deployment.

GIWA Warned That Mainnet Was Not Live

GIWA responded as claims of an unannounced mainnet and a leaked RPC spread across social channels.

"We DO NOT have our mainnet running currently," GIWA warned on X on September 27, adding that posts claiming to possess GIWA mainnet RPC information were false and urging users to inspect contracts before interacting with them.

An earlierWA warning was equally direct: "we haven't launched our mainnet yet," which made an alleged mainnet RPC leak impossible.

GIWA Sepolia uses test assets with no economic value and is separate from Upbit's exchange services. GIWA also does not currently plan to issue a separate native token, with ETH designated as the Layer 2's base asset.

Crypto impersonation campaigns have increasingly copied legitimate infrastructure and branding, including a recent Trezor and BitBox phishing campaign that used fabricated security warnings to direct wallet users toward malicious pages.

DYORSWAP Starts Reimbursing Victims

More than 200 ETH has already been distributed to affected users using DYORSWAP's own funds while the investigation continues, according to the project's statement on X.

The tracing now covers the bridge deployer, its initial funding, early test wallets, batcher infrastructure, and the destinations that received the 766.25 ETH removed from the bridge. Whether DYORSWAP's reimbursement grows further, and what the ongoing tracing of the removed 766.25 ETH uncovers, are the developments to watch as the investigation continues.

The incident did not involve an exploit of GIWA's active Sepolia testnet. Users instead transferred real ETH into infrastructure impersonating an unreleased network, while GIWA's legitimate bridge remains a Sepolia testnet bridge handling test assets.

This article originally appeared on Crypto Adventure.