How Did A Fake Blockchain Drain 766 ETH?
A fraudulent blockchain impersonating Upbit operator Dunamu’s GIWA network drained about $2 million in Ether after decentralized exchange DYORSWAP initially treated the fake network as GIWA’s mainnet.
DYORSWAP said Monday that 1,335 addresses sent roughly 767.65 ETH through the fraudulent bridge before its operators withdrew 766.25 ETH.
The incident differed from a typical smart contract exploit. DYORSWAP said its own contracts were not compromised. Instead, the attackers created infrastructure that appeared to represent the unreleased GIWA mainnet, including a bridge that users could send real ETH into.
GIWA warned on Sunday that its mainnet had not launched and that connection details circulating online were false.
“We do not have our mainnet running currently,” the project said.
The distinction matters because users were not interacting with a malicious copy of a website alone. The fraudulent setup was convincing enough to be treated as a functioning blockchain environment, creating a route through which hundreds of users transferred assets before the funds were removed.
Why Was The Fake GIWA Network Convincing?
GIWA is an Ethereum layer-2 network being developed by Dunamu, the operator of South Korean crypto exchange Upbit. Dunamu launched a GIWA Sepolia testnet in September 2025 using Optimism’s OP Stack, but the project has not yet released its production mainnet.
That gap between a public testnet and an anticipated mainnet created an opening for impersonation. False connection information could appear plausible to users already expecting the network to move closer to launch.
DYORSWAP’s account of the incident shows how that problem can extend beyond individual users. Once an application recognizes fraudulent infrastructure as legitimate, the mistake can give the fake network additional credibility and expose more wallets to it.
GIWA has also been moving beyond experimentation. Dunamu, Hana Financial and POSCO International agreed earlier this year to test a GIWA Chain-based cross-border remittance system using real trade transactions, giving the network a growing profile before its mainnet launch.
Investor Takeaway
The loss was not caused by a vulnerability in DYORSWAP’s contracts. The failure came from trusting fraudulent network infrastructure, showing that chain verification can become a security risk before users interact with any DeFi application or smart contract.
What Is DYORSWAP Doing For Affected Users?
DYORSWAP said it has used its own funds to reimburse affected users with more than 200 ETH so far, leaving the recovery effort well below the roughly 766 ETH removed through the fraudulent bridge.
The exchange said it is tracing the bridge deployer, the sources that funded the operation, suspected test wallets and the addresses that ultimately received the stolen ETH.
Those traces could become important if funds eventually reach centralized exchanges or other services capable of freezing assets after receiving valid requests. They do not guarantee recovery, particularly if the operators use multiple wallets, decentralized protocols or other methods to complicate the transaction trail.
The reimbursement also shifts part of the financial cost onto DYORSWAP even though the exchange says its contracts were not hacked. For DeFi applications, that creates a wider operational question: how much responsibility a platform assumes when it exposes users to a fraudulent network that has been incorrectly recognized as legitimate.
What Does The GIWA Scam Mean For New Layer-2 Networks?
The case exposes a security problem that sits outside traditional smart contract auditing. Crypto users typically focus on malicious tokens, compromised contracts and phishing links, but counterfeit blockchain infrastructure can create another attack surface.
A user connecting to the wrong network may still see familiar wallet interfaces, bridges and transaction flows. If an application also accepts that network, the distinction between authentic and fraudulent infrastructure becomes harder for less technical users to detect.
The risk may be highest around anticipated launches, when official mainnet details are not yet widely known and traders are actively looking for early access, liquidity opportunities or new applications.
For GIWA, the immediate task is separating the legitimate project from the fraudulent network while its actual mainnet remains unreleased. For DYORSWAP, attention will remain on reimbursements and whether investigators can follow the stolen ETH to identifiable services.
The broader lesson is that validating a blockchain itself can be as important as checking the application running on it. In this case, the bridge worked well enough to receive hundreds of deposits. The problem was that the network behind it was never GIWA in the first place.
