Fake GIWA bridge drains $2m in ether from DYORSWAP users
Scammers posing as Dunamu's GIWA network took about 766 ETH through a fraudulent bridge, prompting DYORSWAP to refund more than 200 ETH from its own funds.
Key points
- DYORSWAP said the fake GIWA bridge received about 767.65 ETH from 1,335 addresses and scammers drained 766.25 ETH.
- GIWA, an Ethereum layer-2 built by Upbit operator Dunamu, said on Sunday its mainnet had not launched.
- Dunamu launched GIWA's Sepolia testnet in September 2025 using Optimism's OP Stack.
- DYORSWAP said its own contracts were not compromised and it is tracing the deployer, funding sources and recipient wallets.
- The exchange paid over 200 ETH in compensation to affected users from its own funds.
Scammers stole roughly $2 million in ether from a bridge for a fake GIWA blockchain that the decentralised exchange DYORSWAP says it initially mistook for the project's mainnet, CoinTelegraph reports. The fraudulent bridge took in about 767.65 ETH from 1,335 addresses, and the attackers drained 766.25 ETH, according to DYORSWAP's reconstruction published on Monday.
GIWA, an Ethereum layer-2 network developed by Dunamu, the operator of the Upbit exchange, said on Sunday that its mainnet had not launched. The project warned that connection details for a purported mainnet circulating online were false, stating that it does not currently have a mainnet running.
Fake bridge drains funds
The background matters because GIWA is a real project still in testing. Dunamu launched GIWA's Sepolia testnet in September 2025 using Optimism's OP Stack, and in April the company, Hana Financial and POSCO International agreed to test a GIWA Chain-based cross-border remittance system using real trade transactions. No live mainnet exists for users to bridge funds to.
DYORSWAP said its own contracts had not been compromised. It added that it was tracing the bridge deployer, the funding sources behind it, suspected test wallets and the addresses that received the stolen funds. The exchange has used its own funds to pay more than 200 ETH to affected users as compensation.
GIWA mainnet not live
The incident highlights the risk of fake networks and bridges that borrow the branding of legitimate projects before those projects go live. Users who sent ether to the fraudulent bridge had no genuine mainnet to interact with, and the funds were moved out by the attackers.
CoinTelegraph notes that the case follows other recent security incidents in crypto, including a scare involving Magic Eden and a lawsuit by KelpDAO against LayerZero over a bridge exploit. Those stories were listed alongside the GIWA report but are separate matters.