A counterfeit blockchain posing as the unreleased GIWA mainnet received roughly 767.65 ETH from 1,335 addresses before operators removed approximately 766.25 ETH from its bridge, according to the latest accounting released by DYORSWAP.
The incident is unusual because the attackers did considerably more than clone a website or publish a fraudulent wallet address. DYORSWAP says the operators built what appeared to be a functioning Ethereum Layer 2 network, complete with an RPC endpoint, bridge infrastructure, a batcher resembling the architecture used by OP Stack chains and the chain identifier 9134.
That infrastructure was convincing enough that DYORSWAP initially treated the network as GIWA mainnet before later warning that it was entirely fraudulent. The team says its own smart contracts were not compromised and that the loss resulted from users sending real ETH through infrastructure controlled by the counterfeit network’s operators.
Counterfeit GIWA Network Took in 767.65 ETH Before the Bridge Was Drained
According to DYORSWAP’s September 28 update, the fraudulent network was deployed at 02:10:59 UTC+8 on September 27. Around 8.5 hours before deployment, the address involved received approximately 0.045 ETH from an address DYORSWAP described as associated with ChangeHero.
That attribution is potentially useful for investigators, but it does not by itself identify the person behind the network. Funds passing through a swap or exchange-linked address can provide an investigative lead without proving who ultimately controlled the receiving wallet.
Once active, the counterfeit network behaved more like working blockchain infrastructure than a conventional phishing page. DYORSWAP says it operated a bridge and batcher, processed transactions and submitted batches to Ethereum mainnet. The eventual removal of approximately 766.25 ETH occurred at Ethereum block 26,067,309.
Recovered data cited by the team showed 1,479 recorded operations on the network, including 1,148 successful transactions involving 298 wallets and 104 liquidity pools. That apparent activity is important because users interacting with the chain were not simply staring at a static imitation. They were seeing transactions execute inside an environment that behaved like a live Layer 2.
The structure makes the case different from familiar bridge exploits, where attackers typically abuse a vulnerability in legitimate infrastructure. DYORSWAP’s account instead describes fraudulent infrastructure built specifically to receive genuine Ethereum deposits.
SlowMist has listed the case as a phishing attack with losses of roughly $2 million rather than a DYORSWAP smart-contract exploit. That distinction matters for anyone trying to understand where the security failure occurred. In other recent incidents, such as Bitget’s reported backend infrastructure compromise, attackers penetrated systems belonging to a real platform. Here, the infrastructure users trusted was itself counterfeit.
GIWA Says Its Mainnet Was Never Live
The strongest evidence that something was wrong was available outside the fraudulent network itself.
GIWA’s official documentation continues to mark its mainnet as under development. The only publicly documented live environment is GIWA Sepolia, its Ethereum testnet Layer 2, which uses chain ID 91342 and test ETH rather than real assets.
GIWA also said on September 27 that it had not launched mainnet and therefore could not have suffered a leak of a mainnet RPC endpoint. The project urged users to verify information and remain alert to scams circulating ahead of launch.
That creates a critical contrast with what users apparently saw elsewhere. The fake chain had enough technical detail to appear credible, while the project’s own documentation said the production network did not yet exist.
Crypto investors have faced similar provenance problems with fake wallet software, where attackers reproduce the appearance of trusted infrastructure and rely on users encountering the imitation before verifying it through an official channel. The GIWA incident takes that model further by reproducing not merely an interface but much of the environment behind it.
Early Wallet Activity Has Become Part of the Attribution Trail
DYORSWAP has also highlighted activity shortly after the bridge became operational that it believes could help investigators reconstruct how the network was prepared.
Only 39 blocks after launch, three deposits totaling 0.4 ETH reportedly arrived within the same second. DYORSWAP says two of the sending wallets were making their first outbound transactions and described the behavior as strongly resembling internal test activity.
That remains an investigative interpretation rather than proof that the wallets belonged to the scammers. However, the addresses may help analysts map relationships between the network deployer, bridge operator, batcher infrastructure and wallets used before ordinary users began depositing.
The broader tracing effort is likely to become increasingly important as the stolen ETH moves. Other crypto investigations have demonstrated both the value and limitations of tracking stolen assets across wallets: public ledgers can make movements visible, but visibility does not automatically give investigators the ability to freeze native cryptocurrency.
DYORSWAP says it has already distributed more than 200 ETH from its own funds to affected users. The team says it continues to investigate the deployer, initial funding source, suspected test wallets, batcher infrastructure and destination of the removed funds.
Why a Fake Chain Is More Dangerous Than a Fake Website
The most important lesson from this incident is that technical sophistication can now be part of the social-engineering layer.
A crypto user is normally taught to distrust suspicious domains, fake token contracts and unexpected wallet prompts. Those rules are still useful, but they become less effective when the attacker creates an RPC that responds normally, a bridge that accepts deposits and a network that produces blocks and publishes transaction batches.
A chain ID also should not be treated as a certificate of authenticity. In an EVM environment, the identifier helps software distinguish one network from another, but possession of a particular number does not prove that the party operating a network is the organization users think it is.
That changes the verification problem. The relevant question is no longer simply whether a website looks real or whether a transaction executes successfully. Users also need to establish whether the RPC endpoint, bridge contracts and network announcement originate from the project’s official documentation.
The problem resembles clone operations in traditional finance. A convincing impersonator can copy information that is genuinely associated with a legitimate organization. The existence of accurate branding or plausible technical details therefore does not establish that the service presenting them is genuine.
Crypto makes the consequences harsher because transactions can become irreversible almost immediately. A user can correctly protect a seed phrase and still lose funds by deliberately signing a transaction to infrastructure they incorrectly believe is authentic. That is a different security problem from the self-custody risks created when key generation or wallet credentials themselves are compromised.
The Next Question Is Who Created the Infrastructure and How It Spread
The stolen ETH is only one part of the investigation. The more consequential question is how a fake production network became credible enough to attract 1,335 depositing addresses before GIWA publicly clarified that its mainnet had never launched.
The deployer funding trail, the 0.4 ETH of unusually early activity, the batcher and bridge relationships, and the first accounts that distributed the RPC information could help reconstruct that sequence. Investigators will also be watching whether the removed ETH eventually reaches centralized exchanges or other services where intervention becomes possible.
But on-chain clustering has limits. A wallet can be linked to another wallet with high confidence without identifying the human controlling either one. Similarly, an address associated with a service such as ChangeHero is an investigative lead, not evidence that the service itself participated in the scheme.
For DYORSWAP, compensation will also remain part of the story. More than 200 ETH has reportedly been paid from the team’s own funds, but the amount removed from the bridge was substantially larger. How the remaining claims are handled, whether any ETH is recovered and whether investigators can distinguish genuine victims from addresses connected to the operators will determine the eventual financial cost.
For the wider market, however, the incident exposes a more uncomfortable risk. Crypto users have spent years learning that smart contracts can contain bugs and that protocol exploits can compromise legitimate networks. The fake GIWA case shows that attackers may not need to break legitimate infrastructure at all.
They can build their own.
Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.
His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.
Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

