0x771403787714…7714037b
Fake GIWA Layer 2 Bridge Loses 766 ETH in Impersonation Exploit
DYORSWAP integrated a fake L2 impersonating Upbit-backed GIWA, draining 766.25 ETH (~$2M) from its bridge on Sept. 27. The exchange is repaying 40% to wallets that bridged under 5 ETH, with no completion deadline.
Outputs
766.25 ETH (~$2M) drained from a fake GIWA Layer 2 bridge on Sept. 27
DYORSWAP integrated the chain after verifying chain ID 9134 as GIWA's identifier
Aggregate user deposits totaled approximately 767.65 ETH from 1,335 addresses
DYORSWAP pledged 40% reimbursement to wallets that bridged less than 5 ETH, with over 200 ETH distributed
Stolen ETH was routed through Tornado Cash's router in repeated 10 ETH deposits
A bridge fronting a fraudulent Layer 2 network impersonating Upbit-backed GIWA lost 766.25 ETH — roughly $2 million — on Sept. 27 after the decentralized exchange DYORSWAP integrated the chain as if it were the legitimate project.
An Ethereum transaction recorded the outflow from the bridge at 0xbA9938…435ab2 to a recipient address at 0x04a9c8…Fc4134. The receiving wallet subsequently made repeated 10 ETH deposits to the address Etherscan labels as Tornado Cash's router, an obfuscation step consistent with laundering proceeds through a sanctioned mixer.
DYORSWAP's reconstruction put aggregate user deposits into the bridge at approximately 767.65 ETH from 1,335 addresses. The exchange said the loss occurred in bridge infrastructure, not through a flaw in its own trading contracts.
How did the impersonation work?
The genuine GIWA project warned on Sept. 27 that any purported mainnet RPC information circulating online was false. "We DO NOT have our mainnet running currently," it posted on X the same day the drain occurred.
The fake network adopted chain ID 9134, which DYORSWAP confirmed it had identified as GIWA's correct identifier during pre-deployment checks. That match allowed the fraudulent chain to pass initial verification. DYORSWAP then operated an exchange on top of it, letting users who had bridged ETH buy, sell and launch tokens.
The ruse extended past a spoofed website. DYORSWAP's report said the impostor network ran OP Stack-style infrastructure and posted transaction batches to Ethereum. Removing the ETH from the bridge stripped every balance and liquidity pool on the fake chain of its underlying redemption backing, effectively wiping user funds.
Wallet developer apoorv.gwei traced the mechanics in an on-chain review. His analysis described how the bridge's controllers signed an upgrade to a "malicious contract," withdrew the ETH and restored the original implementation within a single transaction. The Ethereum receipt for the drain records two contract-upgrade events alongside the transfer.
What does DYORSWAP's compensation plan cover?
DYORSWAP announced it would repay 40% of the bridged amount to eligible addresses that deposited less than 5 ETH, "regardless of whether the funds were used for trading." Addresses that bridged more than 5 ETH face separate verification under terms the exchange published on X.
The exchange initially committed treasury funds and later said it had distributed more than 200 ETH using its own resources. DYORSWAP acknowledged that the payments would not make every affected user whole and gave no completion deadline.
DYORSWAP said it would reconstruct losses from on-chain deposits rather than require users to file claims or pay a fee. The exchange's compensation notice stipulated that no user would be asked to send funds to receive reimbursement — a step it framed as protection against secondary scams targeting victims of the first.
What regulatory and operational questions remain?
The drain routed into Tornado Cash, a mixer sanctioned by the U.S. Office of Foreign Assets Control in August 2022. Receiving wallets tied to that service create compliance exposure for downstream custodians that handle the proceeds, including potential tripwires at centralized exchanges screening deposits.
Operationally, the incident illustrates the limits of chain ID matching as an authentication signal. A shared identifier between a genuine project still in testnet and a live impostor left DYORSWAP unable to distinguish the two during integration. The genuine GIWA team has not stated a revised mainnet timeline, leaving chain ID 9134 a contested identifier until either party publishes a definitive testnet or mainnet claim.
For affected users, the immediate recourse remains DYORSWAP's partial reimbursement track. The exchange's broader obligations to depositors above the 5 ETH threshold are still being defined, and the published terms leave open whether additional treasury allocations or external recoveries will materialize before any hard deadline.
via etherscan.io (Original)