Fake GIWA Bridge Trick Drains 767 ETH

Protos · High sophistication
Last updated September 28, 2026

Scammers convinced DYORSWAP to integrate a fake version of the upcoming GIWA blockchain, making it look legitimate to users. More than 1,300 wallets then sent roughly 767 ETH (about $2M) to a spoofed bridge contract, which was quickly drained and routed through Tornado Cash.

Key findings

  • Attackers tricked DYORSWAP into integrating a spoofed “GIWA” chain, causing users to bridge funds to a fake contract.
  • The fake chain reused the real GIWA chain ID (9134) to look legitimate during initial checks.
  • Over 1,300 addresses bridged ~767.65 ETH, and the bridge was drained about 12 hours after deployment.
  • Funds were withdrawn by the scammers and routed into Tornado Cash.

Who’s being targeted

  • Commonly targeted roles: Crypto/DeFi community managers, Partnerships/BD and integrations teams, Support teams handling user reports, End users/customers of crypto platforms.
  • Affected industries: Cryptocurrency / DeFi, Fintech.
  • Attack channels: website.
  • Impersonated: GIWA (Powered by Upbit) / GIWA bridge.

Awareness takeaways

  • Treat ‘new network launched’ announcements as untrusted until confirmed through official channels (project website and verified accounts).
  • Don’t rely on “it looks right” technical identifiers (like matching chain IDs) as proof something is legitimate, use verified source-of-truth lists and signed announcements.
  • Be cautious of community ‘tips’ and hype-driven messages that push users to act quickly (FOMO), especially around bridges and deposits.

Red flags to watch for

  • Mainnet announcement appears before official confirmation from the project
  • Bridge/chain legitimacy is based on superficial checks (e.g., matching chain ID) rather than verified official sources
  • Urgency/FOMO language encouraging users to act quickly to be 'early'
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine DYORSWAP showing: “GIWA mainnet is live, bridge now to get in early.” Over 1,300 wallets believed that. But DYORSWAP later admitted that GIWA mainnet was fake. Scammers spun up a spoofed GIWA chain, even copied the real chain ID 9134, and got it integrated so users sent 767 ETH straight into their fake bridge contract. Here’s the trap: everything looked right. GIWA name, GIWA logo, chain ID 9134. FOMO did the rest, “bridge now to be early”, and twelve hours after deployment, the fake bridge was drained and funds pushed through Tornado Cash. Your move: if a new chain or bridge claims to be live, pause. Before you bridge a single token, go to the project’s official website or verified accounts and confirm the launch and the exact bridge address yourself.

Similar attacks

Bitcoin ATM Payment Demand? It’s a Scam Script

Bitcoin ATM Payment Demand? It’s a Scam Script

The article describes a common fraud pattern where scammers impersonate police, government officials, or other trusted authorities over the phone to pressure victims into paying via a Bitcoin/crypto ATM. The victim is told their money is at risk, instructed to withdraw cash, and then directed to…

September 25, 2026
Revolut Smishing Uses Fake Identity Check

Revolut Smishing Uses Fake Identity Check

Following a Revolut data breach, scammers sent text messages that appeared to come from the same message thread as legitimate Revolut texts. The texts pushed victims to click a link for a fake identity “liveness check,” request camera access, and then capture passwords, information that could be…

September 21, 2026
Revolut Fooled by Govt Impersonation Email

Revolut Fooled by Govt Impersonation Email

A person posing as a government agency used an email address on that agency’s real domain to obtain sensitive customer records from Revolut. The same weekly roundup also describes a fake antivirus renewal web page impersonating Avast, telling victims their subscription renewed for €129.99 and…

September 20, 2026
Trusted Channels Hijacked for Phishing and Malware

Trusted Channels Hijacked for Phishing and Malware

The article describes multiple real-world social engineering operations this week, including phishing sent from a legitimate Trezor newsletter channel and malware pushed through a verified HBO Max Reddit ad account. It also highlights a large-scale network of fake online stores impersonating real…

September 18, 2026
Revolut Users Hit With SMS Phish After Breach

Revolut Users Hit With SMS Phish After Breach

Days after Revolut disclosed that customer records were shared with an unauthorized party, some customers reported receiving phishing texts that appeared in the same SMS thread as real Revolut messages. The link led to a fake site that asked for camera access to mimic Revolut’s identity “liveness”…

September 17, 2026
Apollo Breach Tied to IT Support Impersonation

Apollo Breach Tied to IT Support Impersonation

Apollo Global Management disclosed a data breach after attackers used social engineering to gain unauthorized access to certain cloud platforms over several days in July. The attackers obtained sensitive personal data (including Social Security numbers), highlighting how stolen credentials and…

August 25, 2026