Official GIWA image documenting the project ecosystem in coverage of a counterfeit network

Fake GIWA Chain Drains $2 Million in Ether After Fooling DYORSWAP

• September 28, 2026 8:44 am • Comments

A fake blockchain copied the identifying details of GIWA’s planned network closely enough to fool a decentralized exchange. By the time the mistake was understood, scammers had taken roughly $2 million in Ether.

This was not an exploit of Ethereum or GIWA’s real mainnet. It was an identity and verification failure: a counterfeit network presented itself as something that had not even launched.

Cointelegraph reported that DYORSWAP connected to the fake GIWA network after scammers used the correct chain ID, 9134. That familiar identifier helped the impostor chain look legitimate during the exchange’s initial checks.

The report said the attackers used their counterfeit environment to reach real Ether, draining roughly $2 million before the deception was fully understood. GIWA’s own warning established the crucial timeline: the genuine mainnet was not live, so any claimed mainnet RPC endpoint should have failed an independent launch-status check.

The failure was therefore not a break in Ethereum’s consensus or GIWA’s unfinished mainnet. It was a verification gap at the service layer, where a copied identifier was treated as stronger proof than the project’s canonical deployment information.

GIWA had already issued the clearest possible warning. Its mainnet was not running, and any supposed mainnet RPC information circulating online was false:

The incident shows why a chain ID cannot serve as proof of identity. It tells software which network rules and transaction namespace to use, but it does not establish who operates the RPC endpoint or whether that network is the authentic project.

DYORSWAP later acknowledged the failure and said the counterfeit chain used the correct GIWA chain ID:

For users and exchanges, the lesson is painfully simple. RPC endpoints, contract addresses and launch status must be checked against an official project source.

A matching chain ID is one data point, not authentication.

The fact that Ether was stolen can also confuse the story. ETH was the asset taken, but Ethereum’s base network was not breached.

The scammers built a false environment, persuaded a service to trust it and then used that trust to reach real value.

Projects can make this harder by publishing signed network configuration files and a single canonical launch page. Exchanges still have to verify those details independently before listing contracts or routing user funds.

A fake chain does not need to survive for long. It only needs to look real at the moment someone connects.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.