0x7460d6337460…7460d636

ConfirmedSecurity575 vB145 sat/vB3 min decode

Scammers Drain ~$2M in ETH Through Fake GIWA Bridge, DYORSWAP Says

Scammers stole roughly $2 million in Ether from a fake GIWA blockchain bridge, draining 766.25 ETH from 1,335 addresses. DYORSWAP paid over 200 ETH in compensation while GIWA confirmed its mainnet had not launched.

Scammers steal $2M in ETH as fake GIWA network fools DYORSWAP
WitnessScammers steal $2M in ETH as fake GIWA network fools DYORSWAPAI-generated

Outputs

  1. Scammers drained 766.25 ETH of 767.65 ETH deposited by 1,335 addresses, valued at approximately $2 million.

  2. GIWA stated on Sunday: "We do not have our mainnet running currently."

  3. DYORSWAP paid more than 200 ETH to affected users from its own funds.

  4. Dunamu launched GIWA's Sepolia testnet in September 2025 using Optimism's OP Stack.

  5. In April, Dunamu, Hana Financial and POSCO International agreed to test a GIWA Chain-based cross-border remittance system.

Scammers extracted roughly $2 million in Ether from a bridge impersonating the GIWA layer-2 network, siphoning 766.25 ETH from the 767.65 ETH deposited by 1,335 user wallets, according to a Monday reconstruction published by the decentralized exchange DYORSWAP.

What happened?

DYORSWAP disclosed on Monday that a counterfeit bridge posed as the official GIWA mainnet, a network that, per its operating team, does not yet exist. "We do not have our mainnet running currently," GIWA stated on Sunday, warning that mainnet connection details circulating online were false.

The exchange acknowledged that it initially routed user deposits through the fraudulent contract after mistaking it for GIWA's production deployment. The fraudulent bridge accumulated 767.65 ETH from 1,335 addresses before operators drained 766.25 ETH.

Who is GIWA?

GIWA is an Ethereum layer-2 network developed by Dunamu, the operator of South Korea's largest crypto exchange Upbit. Dunamu launched GIWA's Sepolia testnet in September 2025 using Optimism's OP Stack. In April, Dunamu signed an agreement with Hana Financial and POSCO International to test a GIWA Chain-based cross-border remittance system anchored to actual trade flows, a deployment channel that lends the project institutional credibility in Korea.

How did DYORSWAP respond?

DYORSWAP stated that its smart contracts were not compromised and that the loss stemmed from a misidentified bridge endpoint. The exchange paid more than 200 ETH to affected users from its own treasury and said it is tracing the bridge deployer, funding wallets, and suspected downstream recipients.

The incident illustrates an operational blind spot at the bridge and DEX integration layer: legitimate projects running testnets can be mimicked at the contract-address level, and aggregators or DEXs that copy mainnet configurations from public channels inherit the impersonation.

Why does this matter for market integrity?

The exploit bears the structural hallmarks of an address-poisoning or fake-endpoint scheme rather than a code-level hack: the smart-contract layer held, but the human and metadata layer failed. DYORSWAP's own post-mortem frames the issue as a configuration error rather than a protocol compromise, a distinction with legal and disclosure implications as regulators sharpen scrutiny of DeFi front-ends.

For GIWA, the episode carries reputational cost ahead of any mainnet launch. The project now shares public discourse with a $2 million theft, even though its team's Sunday statement explicitly disclaimed any live network. Cross-border partners such as Hana Financial and POSCO International will monitor how the team handles bridge impersonation tooling and address-verification standards before any production remittance pilot goes live.

What is the enforcement path forward?

DYORSWAP did not announce law enforcement referral in its Monday statement, but the exchange said it is tracing on-chain funding paths. Chain-analysis firms typically require a named victim filing to coordinate with exchange compliance teams for freezes. The 200 ETH compensation DYORSWAP distributed from its own balance sheet sets a precedent for centralized front-ends covering user losses stemming from third-party bridge address confusion, a posture that may invite closer regulatory review of liability allocation between aggregators and the bridges they list.

The episode arrives as South Korean authorities expand oversight of layer-2 deployments and token listings on regulated venues such as Upbit. The market-structure question is now sharpened: who verifies that a listed bridge endpoint corresponds to an active mainnet rather than a cloned testnet, and who bears loss when that verification fails.

via x.com (Original)

More from Nathan Brooks

Nathan Brooks

Show full bio

Market editor covering business strategy at Mempool Brief.

451 articles