DyorSwap Will Repay 40% to Users Hit by a Fake GIWA Mainnet

DyorSwap will pay back 40% to people who bridged money into a blockchain posing as the GIWA mainnet. The decentralized exchange said on Sunday that the network its team flagged days earlier is a counterfeit, stood up by scammers who reused GIWA's real chain ID, 9134, so the first checks on it came back clean. Funds moved in through a fake cross-chain bridge attached to it. DyorSwap puts the loss at about 766 ETH. The real GIWA, an Ethereum layer-2 from Dunamu, the company behind the South Korean exchange Upbit, says it has no mainnet running at all.
Why the chain ID carried the trick
A chain ID is the number a wallet reads to tell one network from another before it signs anything. Copy that number and the wallet's own sanity check stops being a check. DyorSwap concedes its team fell for it too, identifying the network as GIWA's mainnet first and calling it fraudulent afterwards.
"The so-called 'GIWA mainnet' identified by the team earlier is actually a fake chain set up by scammers," DyorSwap said.
Pre-launch names make soft targets. The brand circulates, the chain ID is published in advance, and until an official network exists there is nothing to hold a fake up against. Attacks that borrow a real identity keep working, and phishing mail once reached Trezor users from Trezor's own domain.
What is being paid, and to whom
The review of affected addresses finished before the terms went out on Sunday afternoon. Addresses that bridged under 5 ETH get 40% back, in DyorSwap's words "regardless of whether the funds were used for trading". Addresses above that line go to individual review, and DyorSwap says some of them are suspected of phishing or of running fraudulent bridge operations themselves. The money comes from the exchange's treasury. One repayment address was published, 0xdf25f88aa6cde9937fdcfcf10fa349528c79dbf9, with a standing caution that DyorSwap will never ask anyone to send funds or pay a fee to take part.
Two statements on one day that do not meet
GIWA put out its own note on Sunday, and it answers a different question. Claims had been circulating about a leaked mainnet RPC endpoint, the address software uses to reach a network. GIWA's reply, carried by crypto.news on Sunday morning, is that no mainnet has launched, so no endpoint can have leaked. It did not identify the accounts or URLs behind those claims. It did not mention DyorSwap, the bridge or any loss either, and crypto.news does not mention DyorSwap at all. Neither account confirms the other.
The figure rests on one party
Every version of the 766 ETH traces back to DyorSwap's own announcement. No independent on-chain tally turned up in the accounts read for this piece, and not one of them converts the amount into dollars. It stands unverified. DyorSwap listed three immediate steps: security teams tracing addresses and the flow of funds on-chain, evidence preserved in the form of communications, RPC data, bridge addresses and transactions, and treasury money held ready once verification ends. The exchange said it "deeply apologizes to every affected user". Bridges are where this class of loss keeps landing, whether the contract is fake or merely broken, as when a bridge minted 46 billion syBTC before 15 BTC came back.
Dunamu announced GIWA at the Upbit Developer Conference in Seoul in September 2025, built on Optimistic Rollup technology with the Optimism Foundation as its partner. Only Sepolia testnet endpoints are live, on GIWA's own account. DyorSwap has not said when the 40% goes out, or what the addresses above 5 ETH are owed.
Read also: Stolen Bridge Key Lets Attacker Mint 260 Million AGIX on Ethereum