DYORSWAP, a multi-chain decentralized exchange, said scammers managed to get a fake version of the upcoming GIWA blockchain integrated into the platform over the weekend, setting off losses of about $2 million. More than 1,000 users trying to get in early on a new chain sent ETH to a spoofed bridge contract, and the funds were later withdrawn before being routed into Tornado Cash.
After the bridged funds were drained, DYORSWAP said that “the so-called GIWA Mainnet we previously identified was in fact a fake chain set up by scammers.” The episode is awkward for a platform whose name comes from “do your own research,” a phrase widely repeated in crypto as basic safety advice.
How the spoofed chain got through
DYORSWAP said the falsified OP Stack chain used the same chain ID as the legitimate GIWA network, 9134. That made it “appear legitimate during initial verification.” The exchange also referred to “specific suspicious messages” that may have introduced false information into the DYORSWAP community.
The fake bridge was deployed shortly after 6 PM UTC on Saturday. Just over 12 hours later, it was drained. Around that time, DYORSWAP posted on X telling users to stop bridging and trading in GIWA while it checked the situation.
GIWA denied its mainnet existed
GIWA is an upcoming Layer 2 network built on the OP Stack and described as “Powered by UPbit,” the South Korean centralized exchange. Its testnet launched last year.
The project’s official X account later moved to explicitly deny that a GIWA mainnet existed. The post arrived only minutes before the fake GIWA bridge contract was emptied.
One observer described the theft as “social engineering at the highest level,” saying someone had faked the entire GIWA chain setup, got the bridge and RPC picked up by DYORSWAP, and made more than $2 million within a few hours.
User losses, compensation, and flagged addresses
In a later update, DYORSWAP said it had identified addresses that it believes were behind the scam “based on timing and behavior.” It added that those addresses were funded from Binance and Gate.
The update said 1,335 addresses bridged a total of 767.65 ETH and that almost all of those funds were later drained. DYORSWAP framed itself as a victim alongside its users and said it had already distributed more than 200 ETH in compensation.
Users who bridged less than 5 ETH were offered a 40% refund. Addresses above that threshold will be handled case by case.
An address claiming to belong to the DYORSWAP team has also contacted the scammers on-chain and asked for the stolen funds to be returned.

