Scammers constructed a counterfeit model of Upbit-backed GIWA blockchain and lured 1,333 wallets into depositing 767 ETH, price about $2 million, earlier than draining virtually all of it.
The pretend community seemed to be GIWA’s anticipated Ethereum Layer 2 mainnet, full with an RPC endpoint, cross-chain bridge, and Chain ID 9134, the identifier related to the deliberate launch.
However GIWA’s mainnet was not dwell.
In an X publish, GIWA mentioned claims that its manufacturing RPC had leaked have been false as a result of no mainnet RPC exists. Its documentation lists solely GIWA Sepolia, which makes use of Chain ID 91342, whereas the manufacturing community stays beneath improvement.
DYORSWAP, whose neighborhood initially interacted with the purported community, later mentioned the chain was fraudulent and warned customers in opposition to unofficial RPC endpoints, bridges and contracts. It acknowledged:
“The pretend community used the proper GIWA Chain ID (9134), which made it seem legit throughout our preliminary verification. Now we have additionally recognized particular suspicious messages and people within the associated neighborhood which may be linked to this incident.”
Dunamu, operator of South Korea’s largest crypto alternate, Upbit, is creating GIWA utilizing Optimism’s OP Stack.
Dunamu and the Optimism Basis introduced in Might that GIWA is deliberate as the primary Self-Managed OP Enterprise chain, permitting Upbit to retain operational management whereas Optimism gives backup infrastructure and help.
Attackers waited for deposits earlier than altering the bridge
On-chain information suggests the attackers spent hours getting ready the infrastructure earlier than the primary important deposits arrived.
Pseudonymous blockchain analyst Stablemark mentioned wallets tied to the operation have been funded by means of ChangeHero on Sept. 26. About 11 hours later, the Protected pockets controlling the scheme and the pretend bridge went dwell.
Over the following 13 hours, 1,333 wallets deposited a mixed 767 ETH.

The operators then modified the bridge’s portal code and drained 766 ETH in a single transaction, in response to Stablemark.
The sequence suggests the bridge remained operational lengthy sufficient to build up deposits earlier than the operators changed its controlling code and eliminated the funds.
The assault relied partially on how EVM networks are recognized. A Chain ID can inform a pockets which community it’s linked to, but it surely doesn’t confirm who controls the RPC endpoint or bridge behind that community.
By utilizing GIWA’s anticipated Chain ID 9134, the operators may make the atmosphere seem in line with the anticipated mainnet whereas retaining management of the infrastructure receiving consumer funds.
The stolen ETH has since begun to maneuver.
Stablemark mentioned 177 ETH was routed by means of Twister Money, complicating efforts to hint its subsequent vacation spot, whereas one other 589 ETH remained unfold throughout 4 wallets on the time of his replace.
That leaves many of the stolen funds seen on-chain for now, although additional transfers to mixers, exchanges, or different providers may slender the window for investigators to freeze or get well them.
DYORSWAP gives 40% compensation to smaller victims
DYORSWAP has moved to compensate some customers caught within the pretend blockchain scheme after reviewing affected addresses.
The mission mentioned wallets that bridged lower than 5 ETH would obtain compensation equal to 40% of their cross-chain quantity.
Claims involving greater than 5 ETH will probably be dealt with individually and require identification and handle verification, as a result of DYORSWAP mentioned some bigger wallets might be linked to phishing or different fraudulent exercise.
It additionally printed an handle for compensation distributions and warned victims to confirm it by means of official channels, citing the chance that scammers may exploit the incident once more utilizing pretend reimbursement requests.
The compensation plan leaves substantial losses with customers even the place claims are authorised. Smaller victims would get well lower than half of what they deposited beneath the introduced phrases, whereas outcomes for bigger wallets stay topic to particular person assessment.
DYORSWAP has mentioned it’s preserving RPC information, bridge addresses, transaction information and neighborhood communications as investigators reconstruct how the fraudulent community unfold.








