A fake network impersonating GIWA, the Ethereum layer 2 backed by Upbit operator Dunamu, drained about 766 ETH from 1,335 addresses before anyone could stop it. The counterfeit chain used Chain ID 9134 and convinced users to bridge funds into infrastructure the attackers controlled. GIWA says its real mainnet has not launched.
The scheme came to light through DYOR Swap, a research outfit that traced the incident. The fake network replicated the branding and documentation style of the genuine project closely enough that wallets and bridging tools treated it as legitimate. Once users deposited, the attacker-controlled infrastructure drained roughly 766.25 ETH of the 767.65 ETH that arrived, a near-total capture.
How the fake worked
Layer 2 launches involve chain IDs, bridge contracts and RPC endpoints, and each of those is a place where a counterfeit can slip in. A wrong chain ID in a wallet configuration, or a fraudulent RPC endpoint, points users at a network that looks identical on screen but is controlled by someone else. Funds bridged to such a network go straight to the operator.
The GIWA case stands out for scale and timing. The genuine project, announced by Dunamu, the operator of South Korean exchange Upbit, has attracted attention because of its exchange pedigree. That anticipation created the opening: users wanted in early, and instructions circulating on social media were enough to route them to the wrong place.
What GIWA says
GIWA stated that its mainnet has not launched and that any network asking for deposits under its name is fraudulent. The project has not announced compensation for victims. Dunamu did not immediately respond to requests for comment on whether it would pursue the attackers or support affected users.
The mainnet has not launched. Any network asking users to bridge funds under the GIWA name is not ours.
Losses of about 766 ETH put the incident in the mid-range for crypto scams this year, well below the eight-figure exploits that hit exchanges, but the mechanics matter more than the amount. Fake chain deployments do not require breaking any contract. They exploit the gap between a brand and the infrastructure users think they are connecting to.
A recurring pattern
Counterfeit networks and fake bridge frontends have become a standard attack class. In past incidents, attackers cloned documentation sites, paid for search ads above the real project, and posted RPC details in community channels before moderators could remove them. The defense is unglamorous: verify chain IDs against the project own official channels, never sign a bridge transaction based on instructions from social media, and treat any pre-launch deposit opportunity with suspicion.
The incident lands during a rough week for crypto security. Bitget is still restoring withdrawals after a 87.5 million hot wallet breach, and researchers continue tracing those funds across mixing services. Two large incidents in four days keep the spotlight on operational security across the industry, and both cases share a theme: the weakest link was not cryptography but the process around it.
For the Korean market, the reputational sting is sharper because GIWA carries the Upbit name. Dunamu operates the largest crypto exchange in South Korea, and any project associated with it draws immediate retail attention. That attention cuts both ways: it builds communities quickly, and it gives scammers a credible flag to borrow.
Monitoring of the attacker wallets continues. Funds moved off the fake network have started passing through standard laundering routes, and the possibility of freezes depends on which services the money touches next. Users who interacted with the counterfeit chain should assume their wallet signatures and approvals are compromised and rotate accordingly.
The response from the wider ecosystem was faster than in earlier cases of this type. Wallet providers flagged the fraudulent chain ID within hours, and several Korean crypto media outlets ran warnings in the same news cycle. That speed limited the damage, though not before more than a thousand addresses had deposited. Earlier fake-network incidents often ran for days before detection, with losses several times higher.
Legal recourse is uncertain. The attackers likely operated from jurisdictions where Korean law enforcement has limited reach, and stolen crypto that passes through mixers is rarely recovered in full. Dunamu has resources most victims lack, though, and Korean prosecutors have pursued exchange-related fraud aggressively in past cases. Whether that happens here depends on how much the company sees its brand as damaged.
For users waiting for the real GIWA launch, the project has said announcements will come only through its official channels. The safest rule remains the boring one: type the URL yourself, check the chain ID against the documentation on that domain, and start with a small test transaction. No airdrop or early access is worth a bridge deposit to an unverified network.
The economics of the scam deserve a note. Setting up a counterfeit chain costs almost nothing: the software is open source, the branding is copy-paste, and the distribution happens through social platforms that moderate fraud inconsistently. Against that, 766 ETH is a strong return on a low-effort attack. Expect copies. Any anticipated layer 2 launch with a recognizable backer is now a template for this scheme, and the GIWA case will likely be cited in future warnings precisely because it worked.
Security researchers also point to a structural gap. Wallets display chain names as provided by the RPC endpoint, not as independently verified facts. Some providers have begun cross-checking chain IDs against public registries, but coverage is incomplete, and the check only helps if users update their wallets. The industry has no equivalent of the certificate authority system that secures websites, so the burden of verification stays with the individual user, which is exactly where it fails most often.