Fake GIWA mainnet bridge hack — September 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | September 27, 2026 |
| Target type | Other |
| Loss | $2,073,500Price at time of incident |
| Method | Phishing signatureScammers ran a working imitation of GIWA, Dunamu's unlaunched Ethereum layer-2, under its published chain ID 9134; after DYORSWAP listed it as the GIWA mainnet, users bridged real ether into the imitation's bridge contract and the operators withdrew it in one transfer |
| Chains | Ethereum |
| Outcome | Unresolved |
What happened
Scammers ran a counterfeit version of GIWA, the Ethereum layer-2 network being built by Dunamu, the operator of the Korean exchange Upbit, and drained the ether users bridged into it. GIWA's mainnet had not launched, but its chain ID, 9134, was public, and a chain ID is only a number that a network declares for itself. The imitation was not a fake web page but a working OP Stack-style network, with a bridge contract on Ethereum that accepted real ether and a batcher posting transaction data back to the main chain. Its bridge was deployed at 18:10:59 UTC on 26 September 2026, in Ethereum block 26,063,331.
The decentralised exchange DYORSWAP deployed its application on the network and presented it as the GIWA mainnet, and deposits followed: 1,335 addresses bridged about 767.65 ETH, according to DYORSWAP's reconstruction of the chain. At 07:29:59 UTC on 27 September, in block 26,067,309, the bridge contract sent 766.254 ETH to a single address in one internal transfer, which this registry read from the chain. At the ether price of that hour it was worth about $2.07m, the figure recorded here. Everything shown on the fake network, including ETH balances and liquidity pools, lost its backing at that moment. GIWA said the same day that its mainnet was not running and that the connection details circulating online were false.
DYORSWAP says its own contracts were not exploited and that it was deceived by the reused chain ID along with its users, though users criticised it for listing the network at all. It rebuilt the fake chain's history from the batches the scammers had posted to Ethereum and began paying compensation from its own treasury: 40% for addresses that bridged less than 5 ETH, with larger deposits reviewed one by one because some may belong to the operators themselves. By 28 September it had paid out more than 200 ETH. That compensation is not recorded as recovery, because none of the drained ether has come back. DYORSWAP traced the deployer's first funding, about 0.045 ETH, to an address it associates with the instant-exchange service ChangeHero; no one has been identified.
Sources
- CointelegraphSecondary · retrieved 2026-09-30
- The Crypto TimesSecondary · retrieved 2026-09-30
- Crypto BriefingSecondary · retrieved 2026-09-30
- Bitcoin.com NewsSecondary · retrieved 2026-09-30
- Ethereum transaction trace, read by this registryOn-chain · retrieved 2026-09-30
Changes to this entry
- Recorded three days after the drain. The amount is the 766.254 ETH the fake bridge contract sent to the operators' address in one internal transfer, read by this registry from block 26,067,309 and valued at the ether price of that hour; DYORSWAP's reconstruction puts total deposits at 767.65 ETH from 1,335 addresses. DYORSWAP's compensation from its own treasury is not counted as recovery.
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Fake GIWA mainnet bridge hack — September 2026", iTokenly, accessed 2026-09-30, https://itokenly.com/hacks/fake-giwa-mainnet-bridgehttps://itokenly.com/hacks/fake-giwa-mainnet-bridgePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.