A fraudulent Ethereum Layer 2 network impersonating GIWA drained about 766.25 ETH, worth roughly $2 million, after 1,335 addresses transferred about 767.65 ETH through a fake bridge.
The fake network was presented as the GIWA mainnet even though GIWA had not launched its mainnet. The attackers used chain ID 9134, which was associated with GIWA, and built a functioning Layer 2 environment with bridge and batcher infrastructure that made the network appear legitimate.
According to the exchange, the incident was not caused by a vulnerability in DYORSWAP’s contracts. Instead, users and the platform interacted with fraudulent infrastructure that was impersonating GIWA. DYORSWAP has since distributed more than 200 ETH in compensation from its own funds while investigating the attackers and tracing the stolen assets.
Fake GIWA Mainnet Used a Known Chain ID
The attackers did more than create a fake website or social media account.
The fraudulent network operated as a functioning Layer 2 and used chain ID 9134, allowing it to appear as the GIWA network in some infrastructure. GIWA’s legitimate Sepolia testnet uses a different chain ID, 91342.
The fake network also included an Ethereum bridge and batcher similar to infrastructure used by OP Stack-based Layer 2 networks. It processed transactions and posted transaction batches to Ethereum, giving users an environment that behaved like a working blockchain.
This made the scam harder to identify than a simple phishing website because users could interact with a functioning network and see transactions being processed.
1,335 Addresses Bridged More Than 767 ETH
According to DYORSWAP’s reconstruction of the incident, 1,335 addresses deposited approximately 767.65 ETH into the fraudulent bridge.
About 766.25 ETH was later removed from the bridge. The difference between the amount deposited and the amount drained reflects the ETH that remained in the system when the funds were removed.
The fraudulent network was deployed on September 27, according to DYORSWAP’s investigation. The team said the bridge began receiving deposits shortly after it went live, with three early deposits totaling 0.4 ETH arriving within the same second.
DYORSWAP said it is continuing to investigate the deployer, funding sources, early test wallets, batcher infrastructure, and the addresses that received the drained ETH.
| Detail | Reported Information |
| Fake network | GIWA Chain 9134 |
| Legitimate GIWA status | Mainnet has not launched |
| ETH deposited | About 767.65 ETH |
| ETH removed | About 766.25 ETH |
| Addresses affected | 1,335 |
| Network type | Fraudulent Ethereum Layer 2 |
| Main infrastructure | Bridge and batcher |
Table 1. Key details of the fake GIWA network incident.
DYORSWAP Starts Compensating Affected Users
DYORSWAP said it has already distributed more than 200 ETH to affected users using its own funds. The exchange said the compensation was initiated while the investigation continues and that it is working to distinguish affected users from addresses that may have been involved in the fraudulent operation.
The compensation does not mean the full amount lost has been recovered. Around 766 ETH was removed from the fraudulent bridge, while more than 200 ETH has so far been returned through DYORSWAP’s compensation process. The investigation is also tracking where the drained ETH moved after leaving the bridge.
Why the Chain ID Created Confusion
Chain IDs are used by EVM-compatible networks to distinguish one blockchain from another. The problem here was that the fraudulent network used 9134, a chain ID associated with GIWA.
Because the identifier was known before the real mainnet launched, another network could use the same number and appear legitimate to infrastructure that relied on the chain ID for verification.
The incident shows why checking a chain ID alone is not enough when interacting with a newly announced blockchain. Users also need to verify the official RPC endpoint, bridge contracts, and other network information through the project’s official channels.
What Comes Next
The investigation will focus on identifying the operators of the fraudulent network, tracing the drained ETH and determining how the fake chain was presented to users as GIWA’s mainnet.
DYORSWAP is continuing its compensation process and on-chain investigation, while GIWA has warned users to avoid unofficial network infrastructure until the situation is resolved.
What This Means for You: Do not connect wallets or bridge funds to an unreleased blockchain unless the network details come directly from the project’s official channels. A familiar name or chain ID is not enough to verify a network. Users who interacted with the fake GIWA bridge should follow official updates and avoid anyone requesting additional funds to recover their assets.

