Fraudsters created a bogus replica of the Upbit‑backed GIWA blockchain, enticing 1,333 wallets to deposit a total of 767 ETH—approximately $2 million—before siphoning off nearly the entire amount.

The counterfeit platform masqueraded as GIWA’s upcoming Ethereum Layer 2 mainnet, complete with an RPC endpoint, a cross‑chain bridge, and Chain ID 9134—the identifier earmarked for the planned launch.

However, GIWA’s mainnet was still offline.

GIWA clarified in a post on X that rumors of a leaked production RPC were unfounded, noting that no mainnet RPC currently exists. The project’s documentation lists only the GIWA Sepolia testnet (Chain ID 91342), while the production network is still in development.

DYORSWAP, whose community had initially engaged with the impostor chain, later denounced it as fraudulent and cautioned users against using unofficial RPC endpoints, bridges, and contracts. The statement read:

“The counterfeit network exploited the legitimate GIWA Chain ID 9134, lending it an appearance of authenticity during our initial verification. We have also flagged specific suspicious communications and community members that may be linked to this incident.”

Dunamu, the operator of South Korea’s largest crypto exchange Upbit, is developing GIWA using Optimism’s OP Stack.

In May, Dunamu and the Optimism Foundation announced that GIWA is intended to become the first Self‑Managed OP Enterprise chain, giving Upbit operational control while Optimism supplies ancillary infrastructure and support.

Attackers waited for deposits before changing the bridge

On‑chain analysis indicates that the perpetrators spent many hours erecting the fraudulent infrastructure before the first substantial deposits were made.

The pseudonymous analyst Stablemark reported that the wallets linked to the scheme were initially funded via ChangeHero on 26 September. Roughly eleven hours later, the Safe wallet managing the operation and the fake bridge became active.

During the subsequent thirteen hours, a total of 1,333 wallets collectively deposited 767 ETH.

How Attackers Moved Stolen Funds on the Fake GIWA Chain (Source: Stablemark)

Thereafter, the operators altered the bridge’s portal code and siphoned 766 ETH in a single transaction, Stablemark noted.

The timeline indicates that the bridge stayed functional long enough to collect the deposits before the operators swapped out its control code and withdrew the assets.

The scheme exploited a characteristic of EVM networks: a Chain ID informs a wallet which network it is connecting to, yet it does not authenticate the entity operating the RPC endpoint or bridge.

By leveraging GIWA’s anticipated Chain ID 9134, the attackers made the environment appear congruent with the planned mainnet while maintaining control over the infrastructure that collected users’ funds.

Since the heist, the stolen ETH has started moving.

Stablemark reported that 177 ETH had been sent through Tornado Cash, obscuring its further trajectory, whereas the remaining 589 ETH was still distributed across four wallets at the time of his latest update.

Consequently, the bulk of the stolen funds remain observable on‑chain at present; however, any additional transfers to mixers, exchanges, or other services could reduce the time window available for investigators to freeze or recover the assets.

DYORSWAP offers 40% compensation to smaller victims

DYORSWAP has initiated a compensation program for users affected by the fraudulent blockchain scheme, following a review of the impacted addresses.

The project announced that wallets which bridged less than 5 ETH would be reimbursed with an amount equal to 40 % of their cross‑chain transfer.

Claims exceeding 5 ETH will be processed on a case‑by‑case basis and will require identity and address verification, as DYORSWAP suspects that some larger wallets may be associated with phishing or other illicit activities.

DYORSWAP also disclosed a distribution address for the reimbursements and cautioned victims to confirm its authenticity through official channels, emphasizing that fraudsters might attempt to capitalize on the incident with deceptive refund requests.

Even when claims are approved, the compensation scheme still leaves many users with significant losses; smaller victims would recoup less than half of their original deposits under the announced terms, while larger wallets face outcomes that remain subject to individual assessment.

DYORSWAP has indicated that it is preserving RPC logs, bridge addresses, transaction data, and community communications to aid investigators in reconstructing the proliferation of the fraudulent network.

Source link

Exit mobile version