
Fake GIWA “mainnet” bridge drains 766.25 ETH after DYORSWAP treated it as legit
DYORSWAP says core contracts were not compromised and has reimbursed users with more than 200 ETH from its own funds.
A fraudulent “GIWA mainnet” bridge pulled in 767.65 ETH from 1,335 addresses and was then drained for 766.25 ETH, in a scam DYORSWAP said it initially mistook for GIWA’s real network. GIWA, developed by Upbit operator Dunamu, has reiterated that no mainnet is live and that purported connection details circulating online are false.
Fake GIWA “Mainnet” Bridge Pulls In 767.65 ETH, Then Gets Drained
DYORSWAP says scammers siphoned about $2 million in Ether from a bridge tied to a fake “GIWA blockchain” after the venue initially treated the setup as GIWA’s mainnet. The loss did not come from a typical decentralized exchange smart-contract exploit narrative. It came through a separate bridge that used GIWA branding and “mainnet” framing to pull users into sending funds.
In a reconstruction DYORSWAP published Monday, the venue said the fraudulent bridge contract received about 767.65 ETH in total inflows from 1,335 depositing addresses, before scammers drained 766.25 ETH. That address count matters because it points to a broad, retail-heavy distribution of victims rather than a single large transfer, which is consistent with scams that spread via connection details and interface prompts instead of one-off key compromise.
GIWA, an Ethereum layer-2 network developed by Dunamu, warned on Sunday that its mainnet had not launched and that purported mainnet connection details circulating online were false. “We do not have our mainnet running currently,” GIWA wrote.
The context here is messy in the way bridge scams usually are. GIWA has had real public development signals, including a Sepolia testnet launched in September 2025 using Optimism’s OP Stack, and an April 2026 agreement involving Dunamu, Hana Financial, and POSCO International to test a GIWA Chain-based cross-border remittance system using real trade transactions. That backdrop makes “mainnet soon” narratives easier to sell, even when the operational reality is that no production network is live.
DYORSWAP’s Post-Mortem: No Core-Contract Compromise, Reimbursements Underway
DYORSWAP’s post-mortem draws a bright line between its own core contracts and the fraudulent bridge. The venue said its contracts were not compromised, and framed the incident as a brand-impersonation trap that routed user funds into a separate bridge contract rather than an exploit of DYORSWAP’s DEX logic.
On remediation, DYORSWAP said it used its own funds to pay more than 200 ETH in compensation to affected users. That shifts immediate user-loss risk away from depositors and onto DYORSWAP’s balance sheet, but it also leaves a practical gap: the reconstruction, as described, does not state that any portion of the 766.25 ETH drained has been recovered or frozen.
DYORSWAP said it is tracing the bridge deployer, funding sources, suspected test wallets, and the recipient addresses that received the stolen funds. The provided material does not identify the scammers, does not specify when the fake “mainnet” connection details began circulating, and does not establish whether the failure mode was primarily DYORSWAP’s listing and verification process, user-side deception, or a combination of both.
What I’m Watching Next: Tracing Results, Copycat Bridges, and Any Official GIWA Mainnet Signals
The next concrete datapoint is whether DYORSWAP can publish recipient addresses and funding-source links in a way that leads to real-world containment, meaning freezes, recoveries, or at least clustering that narrows the set of counterparties that touched the funds. Without that, “tracing” remains a process statement, not an outcome, and the market tends to price these incidents as unrecovered until proven otherwise.
GIWA’s side of the story is simpler but more important for risk control: it says no mainnet is running, and that connection details circulating now are false. The threshold that matters is whether GIWA follows with validated, canonical endpoints and an explicit launch confirmation, because until then any “GIWA mainnet” RPCs and bridges floating around should be treated as unverified infrastructure.
The other near-term risk is copycats. Once a fake-bridge campaign proves it can pull in hundreds of ETH from many small depositors, the playbook gets recycled, sometimes with the same endpoint patterns and sometimes with a new brand. If DYORSWAP expands compensation beyond the stated more-than-200-ETH figure or changes how it verifies new-chain bridges, that will be the clearest signal that it views this as an operational control failure, not just an external scam it happened to touch.
How I'm Reading Fake GIWA bridge drains 766 ETH
I don’t think the cleanest read here is “DEX hacked,” and DYORSWAP’s own reconstruction is why. It is describing a loss path that runs through a separate fraudulent bridge, with DYORSWAP saying its core contracts were not compromised and pointing its investigation at the bridge deployer, funding sources, and recipient addresses.
The real test is whether the tracing produces containment, and whether GIWA’s “no mainnet” warning is followed by a single canonical set of connection details when it is ready to launch. If neither happens, this stays a retail-facing endpoint trap that can be cloned quickly, and the practical difference will come down to which venues harden verification and which keep absorbing reimbursements on their own balance sheets.