BC.GAME promotional banner

Fake GIWA Network Drains 766 ETH After Users Bridge Funds to Fraudulent Layer 2

3–4 minutes
Fact Checked by Mazel Ventura

Last Updated:

September 28, 2026

GIWA logo with a warning sign and Ethereum coins flowing from a tunnel.

Fake GIWA Network Drains 766 ETH After Users Bridge Funds to Fraudulent Layer 2

GIWA logo with a warning sign and Ethereum coins flowing from a tunnel.

Fake GIWA Network Drains 766 ETH After Users Bridge Funds to Fraudulent Layer 2

A fraudulent Ethereum Layer 2 network impersonating GIWA drained about 766.25 ETH, worth roughly $2 million, after 1,335 addresses transferred about 767.65 ETH through a fake bridge.

The fake network was presented as the GIWA mainnet even though GIWA had not launched its mainnet. The attackers used chain ID 9134, which was associated with GIWA, and built a functioning Layer 2 environment with bridge and batcher infrastructure that made the network appear legitimate.

According to the exchange, the incident was not caused by a vulnerability in DYORSWAP’s contracts. Instead, users and the platform interacted with fraudulent infrastructure that was impersonating GIWA. DYORSWAP has since distributed more than 200 ETH in compensation from its own funds while investigating the attackers and tracing the stolen assets.

Fake GIWA Mainnet Used a Known Chain ID

The attackers did more than create a fake website or social media account.

The fraudulent network operated as a functioning Layer 2 and used chain ID 9134, allowing it to appear as the GIWA network in some infrastructure. GIWA’s legitimate Sepolia testnet uses a different chain ID, 91342.

The fake network also included an Ethereum bridge and batcher similar to infrastructure used by OP Stack-based Layer 2 networks. It processed transactions and posted transaction batches to Ethereum, giving users an environment that behaved like a working blockchain.

This made the scam harder to identify than a simple phishing website because users could interact with a functioning network and see transactions being processed.

1,335 Addresses Bridged More Than 767 ETH

According to DYORSWAP’s reconstruction of the incident, 1,335 addresses deposited approximately 767.65 ETH into the fraudulent bridge.

About 766.25 ETH was later removed from the bridge. The difference between the amount deposited and the amount drained reflects the ETH that remained in the system when the funds were removed.

The fraudulent network was deployed on September 27, according to DYORSWAP’s investigation. The team said the bridge began receiving deposits shortly after it went live, with three early deposits totaling 0.4 ETH arriving within the same second.

DYORSWAP said it is continuing to investigate the deployer, funding sources, early test wallets, batcher infrastructure, and the addresses that received the drained ETH.

Detail Reported Information 
Fake network GIWA Chain 9134 
Legitimate GIWA status Mainnet has not launched 
ETH deposited About 767.65 ETH 
ETH removed About 766.25 ETH 
Addresses affected 1,335 
Network type Fraudulent Ethereum Layer 2 
Main infrastructure Bridge and batcher 

Table 1. Key details of the fake GIWA network incident. 

DYORSWAP Starts Compensating Affected Users

DYORSWAP said it has already distributed more than 200 ETH to affected users using its own funds. The exchange said the compensation was initiated while the investigation continues and that it is working to distinguish affected users from addresses that may have been involved in the fraudulent operation.

The compensation does not mean the full amount lost has been recovered. Around 766 ETH was removed from the fraudulent bridge, while more than 200 ETH has so far been returned through DYORSWAP’s compensation process. The investigation is also tracking where the drained ETH moved after leaving the bridge.

Why the Chain ID Created Confusion

Chain IDs are used by EVM-compatible networks to distinguish one blockchain from another. The problem here was that the fraudulent network used 9134, a chain ID associated with GIWA. 

Because the identifier was known before the real mainnet launched, another network could use the same number and appear legitimate to infrastructure that relied on the chain ID for verification.

The incident shows why checking a chain ID alone is not enough when interacting with a newly announced blockchain. Users also need to verify the official RPC endpoint, bridge contracts, and other network information through the project’s official channels.

What Comes Next

The investigation will focus on identifying the operators of the fraudulent network, tracing the drained ETH and determining how the fake chain was presented to users as GIWA’s mainnet.

DYORSWAP is continuing its compensation process and on-chain investigation, while GIWA has warned users to avoid unofficial network infrastructure until the situation is resolved.

What This Means for You: Do not connect wallets or bridge funds to an unreleased blockchain unless the network details come directly from the project’s official channels. A familiar name or chain ID is not enough to verify a network. Users who interacted with the fake GIWA bridge should follow official updates and avoid anyone requesting additional funds to recover their assets.

Join our growing community

David Constantino

Author

David is a crypto enthusiast, airdrop farmer, and blog writer with a focus on discovering and analyzing new token launches and blockchain projects. He explores the latest trends, shares actionable insights, and guides readers through opportunities in the fast-paced world of digital assets.