
A counterfeit network posing as GIWA, the blockchain being developed by South Korean crypto exchange Upbit, has caused losses for users before the real network has even launched. Decentralized exchange DYORSwap mistook the fake chain for the actual GIWA mainnet and added support for it, sending user funds into a fraudulent bridge.
DYORSwap said on the 27th that the network it had supported believing it was the GIWA chain turned out to be a fake chain unrelated to the official GIWA project, according to blockchain industry sources on the 29th. DYORSwap is a decentralized exchange that supports cryptocurrency trading across multiple blockchains.
The fake network used chain ID 9134. A chain ID is a number that distinguishes one blockchain from another. GIWA's official Sepolia testnet carries the chain ID 91342, but some third-party blockchain information sites had listed 9134 as the chain ID for the GIWA mainnet.
The fake network also had a remote procedure call (RPC) address and a bridge. An RPC serves as the communication channel that wallets and trading services use to connect to a blockchain. A bridge is a service that moves cryptocurrency between different blockchains. Neither a chain ID nor an RPC address serves as proof that a network is official.
According to DYORSwap, the network was not merely a fake website but operated as a functioning blockchain capable of processing real transactions. Users sent ether (ETH) to the bridge believing they were moving assets to the GIWA mainnet.
DYORSwap's analysis of transaction records left on Ethereum showed that about 767.65 ETH from 1,335 addresses entered the bridge that moved assets to the fake network. Of those, 298 wallets were confirmed to have traded on DYORSwap. About 766.25 ETH held in the bridge was then transferred out to external addresses. As a result, it has become difficult for users to convert the ETH shown as held within the fake network back into actual ETH.
GIWA said through its official X account on the 27th that it has not yet launched its mainnet and that there was no possibility of its mainnet RPC being leaked. It urged users to practice "DYOR," or do your own research, and to watch out for false information and scams.
The incident did not involve a hack of the GIWA blockchain itself. Instead, a separate network with no connection to the official GIWA project was built and dressed up to look like the real mainnet in order to lure users. Still, questions over responsibility are expected to persist regarding DYORSwap's verification procedures, given that the official documentation showed the mainnet had not yet launched.
DYORSwap has reconstructed the record of losses and begun compensating users. It said it had paid out more than 200 ETH from its own funds as of the 29th. It is also tracing the party that deployed the fake bridge, the source of the initial funding and the path the withdrawn ETH took.







