Invest3 publishers3 min readPublished Updated
Scammers used GIWA's reserved chain ID to drain 766 ETH before its mainnet launched
Scammers ran a working copy of Dunamu's unlaunched GIWA network on its reserved chain ID 9134 and drained 766.25 ETH from users. The ID got through an exchange's listing checks, so a matching network ID is now weak evidence that a chain is the real one.
The Investor · Invest desk

What happened
- DYORSWAP, a decentralized exchange, listed the fraudulent network as the genuine GIWA mainnet, and deposits sped up once it did.
- The fake came with a working bridge that took ETH from Ethereum mainnet, an OP Stack compatibility layer and a batcher to process transactions.
- By September 27, GIWA had said its mainnet had not launched and that the RPC and infrastructure details circulating online were fabricated.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- cost So far the loss sits with the exchange that vouched for the chain, not the network's developer: DYORSWAP's own funds already cover at least about 26% of the drained ETH, before any recovery.
- decision Listing, bridge and treasury teams that accept a network because its chain ID matches now need a second check against the project's own launch statement, because the ID is the check that passed here.
- exposure Any project that reserves an ID before launch can be copied the same way until it goes live, and GIWA's own reserved ID is still exposed because its mainnet has not launched.
Deposits into the fake bridge came to about 767.65 ETH from 1,335 addresses [3]. The attackers took about 99.8% of that and left roughly 1.4 ETH behind [1]. The average deposit was about 0.58 ETH per address [2]. Crypto Briefing reported community estimates of losses near $2M [4], which works out to roughly $1,500 a wallet [4].
Everything a user or an exchange might check pointed at the real project. The counterfeit ran on OP Stack [5], the same Optimism framework Dunamu used for GIWA's Sepolia testnet in September 2025 [6]. GIWA says its network has no native token and uses ETH for gas [7], so a bridge that took ETH deposits [5] looked like what users would expect. DYORSWAP said the reuse of the reserved chain ID made the fake look legitimate enough to pass its initial checks [9].
Chain IDs exist to stop a transaction signed for one network from being replayed on another [10]. According to Crypto Briefing, a project can reserve one before launch, and until the real network goes live, bad actors can claim it [10].
So far the cost has fallen on the intermediary, or more precisely, on the one intermediary that vouched for the chain. DYORSWAP's payout to users who lost larger sums already comes to at least 26% of the drained ETH [3]. The reparations come from DYORSWAP's own treasury, and the effort to trace the stolen ETH and identify the attackers is still going on [c13, c17]. The sources do not report any payment from Dunamu or GIWA.
Recovery would change the bill. DYORSWAP says its contracts were not compromised and that it is tracing the bridge deployer, funding sources, suspected test wallets and receiving addresses [14]. Community members also flagged suspicious trading in a meme token called $FAKER before the fraud came out, according to Crypto Briefing [15], and that could turn out to be part of the same scheme. The strongest counter-reading blames a single listing, since deposits sped up after DYORSWAP presented the fake as genuine [8]. I think the two readings describe the same failure, because the chain ID is what DYORSWAP checked [9]. My thesis would be weaker if a deposit timeline showed users followed the listing and never looked at the ID. The reconstruction, as reported, does not split deposits into before and after the listing [3].
In my view, the check that would have caught this was the simplest one available: had GIWA itself said its mainnet was live? It had a testnet and no mainnet [c1, c6]. The users with the most at stake are the ones Dunamu has already signed up. In April, Dunamu, Hana Financial and POSCO International agreed to test a GIWA Chain-based cross-border remittance system using real trade transactions [16]. Treasury desks sending those payments will see chain ID 9134 and OP Stack, the two features the scammers copied [c2, c6].
GIWA and DYORSWAP have both told users to avoid unofficial endpoints and contracts [18]. GIWA's own status update was short: "We do not have our mainnet running currently," the project wrote [12].
What to watch
- Whether DYORSWAP's tracing of the bridge deployer, funding sources and receiving addresses recovers ETH and shrinks its reparations bill.
- A deposit timeline from DYORSWAP's reconstruction showing how much ETH arrived before and after it listed the fake as GIWA mainnet.
- The date GIWA's real mainnet goes live on chain ID 9134, which closes the window in which the reserved ID can be claimed by someone else.