Counterfeit GIWA Blockchain Siphons $2M in Ethereum Through Fraudulent Bridge
A $2 million Ethereum heist occurred over the weekend when DYORSWAP mistakenly identified a counterfeit GIWA Blockchain as its legitimate mainnet. The fraudulent network, which operated with chain ID 9134, one digit shorter than the actual identifier for GIWA's Sepolia testnet, processed transactions and even posted batches to Ethereum before the funds were removed.
The attackers built convincing infrastructure that included a functioning bridge, transaction batcher, and RPC endpoint. This made it difficult for users interacting with the fake setup to detect the deception without careful chain verification.
DYORSWAP has begun reimbursing affected users with its own funds, distributing over 200 ETH so far, but this leaves the recovery effort well below the roughly 766 ETH removed through the fraudulent bridge. The exchange is tracing the bridge deployer, suspected test wallets, and the addresses that ultimately received the stolen Ether.
The incident highlights a growing security risk in the crypto space: the fabrication of entire blockchain infrastructures convincing enough to attract real deposits. This threat extends beyond conventional smart contract exploits and underscores the importance of validating a blockchain itself, not just checking the application running on it.