0x0fde5cc10fde…0fde5cbe
Fake 'GIWA' Ethereum L2 Bridge Drains 766.25 ETH From 1,335 Users
A fraudulent GIWA-branded Ethereum L2 network drained 766.25 ETH from 1,335 users through a fake bridge. DYORSWAP has reimbursed over 200 ETH and is tracing fund movements and operators.
Outputs
766.25 ETH extracted from 1,335 users via a fake GIWA L2 bridge
Fake network launched September 26, 2026; GIWA confirms no official mainnet exists
Total deposits reached approximately 767.65 ETH
DYORSWAP has reimbursed more than 200 ETH and tracing operators
Roughly 566 ETH remains unaccounted for across affected wallets
A fraudulent layer-2 network branded as "GIWA" extracted 766.25 ETH from 1,335 victims through a counterfeit bridge contract, according to incident data published by the project and its affiliated platform DYORSWAP.
The bogus chain launched on September 26, 2026, and mimicked legitimate Ethereum rollup infrastructure. GIWA has confirmed that no official mainnet exists; the real network remains under development. Deposits flowed into a bridge front-end resembling standard L2 architecture, which then routed funds to addresses under the operators' control.
DYORSWAP, an exchange operating within the GIWA ecosystem, has reimbursed more than 200 ETH to affected users. The platform now traces on-chain fund movements and works to identify the deployment operators.
How did the fraud unfold?
The counterfeit GIWA network advertised itself as a launched mainnet through channels that DYORSWAP and the GIWA team have not yet publicly disclosed. Users deposited ETH into a bridge contract expecting wrapped or canonical L2 representations of their assets. Instead, the contract forwarded deposits to externally owned wallets. The 1.4 ETH gap between total deposits (767.65 ETH) and total losses (766.25 ETH) likely reflects residual contract balances or partial manual withdrawals before the operators abandoned the contract.
How is DYORSWAP responding?
DYORSWAP's reimbursement covers a fraction of the damage. Roughly 566 ETH — the difference between 766.25 ETH lost and 200 ETH returned — remains unaccounted for across the 1,335 affected wallets. DYORSWAP has indicated its tracing effort will identify downstream wallets, mixers, and any centralized exchange deposit addresses that received the stolen funds. Recovery beyond the voluntary reimbursement depends on cooperation from venue compliance teams and on the attackers' use of privacy tools such as Tornado Cash-style mixers.
What should users verify before bridging?
Three checks can confirm a legitimate layer-2 deployment:
- Bridge contract address verified against the project's official documentation and block-explorer records
- Audit reports from named firms published prior to any mainnet claim
- Cross-channel announcement consistency across developer forums, official domains, and verified social accounts
GIWA's official statement notes that users who interacted only with verified contract addresses remain outside the incident scope. The project has not announced a timeline for its actual mainnet launch, leaving an enforcement question for the broader Ethereum L2 ecosystem: how brand impersonation during pre-mainnet phases should be policed when no canonical contract address yet exists. DYORSWAP's tracing effort, and any subsequent law-enforcement referral, will shape the recovery outlook for the more than 566 ETH still outstanding as the October compliance review window opens.
via image-cdn.pluang.com (Original)