Scammers stole about $2 million in Ether (ETH) from a bridge associated with a fake GIWA blockchain, an incident that decentralized exchange DYORSWAP reported on Monday. The fraudulent bridge received approximately 767.65 ETH from 1,335 addresses before attackers drained 766.25 ETH. GIWA is an Ethereum layer-2 network developed by Dunamu, the operator of Upbit. On Sunday, GIWA clarified that its mainnet had not launched and warned that connection details circulating online were false, stating, “We do not have our mainnet running currently.”
Dunamu previously launched GIWA’s Sepolia testnet in September 2025 using Optimism’s OP Stack. In April, Dunamu, Hana Financial, and POSCO International agreed to test a GIWA Chain-based cross-border remittance system using real trade transactions. Following the theft, DYORSWAP stated that its own contracts remained uncompromised and that it was tracing the bridge deployer, funding sources, suspected test wallets, and recipient addresses. To mitigate user losses, DYORSWAP used its own funds to pay more than 200 ETH to affected users.
The incident highlights the operational risks inherent in early-stage infrastructure projects where public anticipation outpaces technical readiness. By exploiting the gap between a project's marketing narrative and its actual deployment status, scammers successfully deceived both a major decentralized exchange and over 1,300 individual users. The fact that DYORSWAP, a significant trading venue, initially mistook the fraudulent bridge for the official mainnet suggests insufficient verification protocols regarding contract addresses and network status during high-profile launches.
From a market structure perspective, this event underscores the fragility of trust in emerging Layer-2 ecosystems. While DYORSWAP absorbed some financial liability by compensating users with over 200 ETH, the broader implication is the potential chilling effect on institutional adoption of new networks if security due diligence fails at the interface level. The involvement of established entities like Dunamu and Hana Financial in the underlying project adds weight to the deception, making the distinction between legitimate development milestones and fraudulent exploits critical for future compliance frameworks.


