Fake GIWA Network Drains 766 ETH After Users Bridge Funds to Counterfeit L2

fiverr



A counterfeit network impersonating Upbit-backed GIWA collected nearly $2 million in ETH after users were directed to an unofficial RPC and bridge for a mainnet that has not launched.

A total of 1,335 addresses bridged about 767.65 ETH into the fake network before approximately 766.25 ETH was transferred out. The fraudulent environment included an OP Stack-like bridge and batcher and began operating after its deployment on September 27.

GIWA Mainnet remains under development. The only publicly available GIWA network is GIWA Sepolia, an Ethereum testnet Layer 2 using chain ID 91342, test ETH and the official sepolia-rpc.giwa.io endpoint.

Fake Network Used Different Chain ID

The fraudulent network operated with chain ID 9134, one digit shorter than GIWA Sepolia’s 91342 configuration.

DYORSWAP had added a GIWA environment using chain ID 9134 alongside its deployments on other EVM networks. The counterfeit chain therefore appeared inside infrastructure users could interpret as a live GIWA ecosystem deployment even though no production GIWA network existed.

The fake L2 went beyond a cloned website. It processed transactions, operated a bridge and batcher, and posted transaction batches to Ethereum, giving users an environment that behaved like an operating Layer 2 before the funds were removed.

Three early deposits totaling 0.4 ETH entered only 39 blocks after the bridge became active. Two came from wallets making their first outbound transaction, and those addresses are now among the activity being investigated as possible test wallets connected to the deployment.

GIWA Warned Mainnet Was Not Live

GIWA responded as claims of an unannounced mainnet and leaked RPC spread across social channels.

“We DO NOT have our mainnet running currently,” GIWA warned on September 27, adding that posts claiming to possess GIWA mainnet RPC information were false and urging users to inspect contracts before interacting with them.

An earlier GIWA warning was equally direct: “we haven’t launched our mainnet yet,” making an alleged mainnet RPC leak impossible.

GIWA Sepolia uses test assets with no economic value and is separate from Upbit’s exchange services. GIWA also does not currently plan to issue a separate native token, with ETH designated as the Layer 2’s base asset.

Crypto impersonation campaigns have increasingly copied legitimate infrastructure and branding, including a recent Trezor and BitBox phishing campaign that used fabricated security warnings to direct wallet users toward malicious pages.

DYORSWAP Starts Reimbursing Victims

More than 200 ETH has already been distributed to affected users using DYORSWAP’s own funds while the investigation continues.

The tracing now covers the bridge deployer, its initial funding, early test wallets, batcher infrastructure and the destinations that received the 766.25 ETH removed from the bridge.

The incident did not involve an exploit of GIWA’s active Sepolia testnet. Users instead transferred real ETH into infrastructure impersonating an unreleased network, while GIWA’s legitimate bridge remains a Sepolia testnet bridge using test assets.



Source link

Coinbase

Be the first to comment

Leave a Reply

Your email address will not be published.


*