‘Spoofed’ Layer 2 Mainnet Scam Emerges, Draining Millions in User Funds

A new and technically sophisticated scam has surfaced within the cryptocurrency ecosystem, moving beyond fake websites to the creation of entire counterfeit blockchain mainnets that impersonate legitimate Layer 2 projects.

Anatomy of the Scam: A Complete Fabrication from Chain ID to Bridge

According to security reports, the fraudsters targeted GIWA, an Ethereum Layer 2 scaling project developed by Dunamu, the parent company of Upbit. Despite official confirmation that GIWA’s mainnet had not launched, the scammers exploited the project’s reserved Chain ID (9134) to create an identical-looking fake chain.

The crucial element was the deployment of a corresponding cross-chain bridge for this spoofed network, advertised as compatible with the popular OP Stack. This full-scale imitation made it difficult for average users and even some platforms to distinguish it from the genuine article without rigorous verification.

  • Core Exploit: The reuse of GIWA's officially reserved Chain ID 9134, a primary identifier for wallets and blockchain explorers.
  • Funds Conduit: The fraudulent bridge acted as a drain, funneling approximately 767.65 ETH into addresses controlled by the scammers.
  • Impact Scale: The scheme ultimately affected 1,335 unique wallet addresses, with total losses amounting to roughly 766.25 ETH, valued at over $2 million at the time.

Platform Mislisting Accelerates Losses, Triggers Compensation

The spread of the scam was accelerated by a decentralized exchange (DEX) platform. This platform added the fraudulent GIWA chain to its list of supported networks, incorrectly labeling it as the “real mainnet,” without sufficient due diligence. This mislisting lent significant credibility to the scam, hastening the inflow of user funds.

Following the incident, the DEX platform clarified that its own smart contracts were not compromised; the losses stemmed solely from the misidentification of the blockchain network. Accepting partial responsibility, the platform initiated a compensation program using its own treasury.

The compensation plan disclosed that over 200 ETH would be distributed to affected users. Specifically, users with smaller losses are eligible for a reimbursement of 40% of their lost amount. This move has sparked industry debate regarding the responsibilities of infrastructure platforms.

Security Takeaway: The High-Risk Period Around Mainnet Launches

GIWA’s team had publicly stated on September 27th—just before the incident gained widespread attention—that its mainnet was still in preparation and not live. This highlights a critical risk window common in the lifecycle of blockchain projects, especially Layer 2s.

In the period surrounding a highly anticipated mainnet launch, community excitement peaks, often accompanied by a flood of information about potential airdrops and early interaction guides. Scammers exploit this information gap and hype by pre-deploying convincing replica infrastructure, luring users with promises of “early access” or “interaction opportunities.”

This incident serves as a stark reminder: Before connecting to any new network or using a new bridge, it is imperative to double-check critical data like Chain ID, contract addresses, and bridge addresses through a project’s sole official channels (e.g., official website, GitHub, verified social media). Even information listed by established platforms requires cross-verification.