REKLAMCILIK
REKLAMCILIK
EGW-NewsDolandırıcılar sahte bir Upbit L2 cihazı kurarak 2 milyon dolarlık ETH çaldı.
Dolandırıcılar sahte bir Upbit L2 cihazı kurarak 2 milyon dolarlık ETH çaldı.
134
Add as a Preferred Source
0
0

Dolandırıcılar sahte bir Upbit L2 cihazı kurarak 2 milyon dolarlık ETH çaldı.

Bu makale aşağıdaki dillerde mevcuttur

Crypto scammers used to settle for a cloned website or a knockoff token. This time someone built a whole blockchain.

Over the weekend, a counterfeit version of GIWA, the Ethereum Layer 2 that Upbit's operator Dunamu is building, pulled in about 767 ETH from 1,335 addresses. Then the bridge was emptied. Roughly 766 ETH, around $2 million at current prices, left in a single transaction.

The real GIWA mainnet doesn't exist. Dunamu's own documentation lists only a Sepolia testnet, and GIWA said on X that no production RPC has been released. Everyone who bridged real ETH was sending it to a network that isn't Upbit's, doesn't run Upbit code, and never will.

How A Fake Chain Got Real Deposits

The fake network wasn't a landing page with a "connect wallet" button. It had an RPC endpoint, a working bridge, a batcher, and OP Stack-style infrastructure. Users could bridge in, and Gokhshtein Media reports that the chain even showed buys, sells, and token launches, so it looked busy.

It also used Chain ID 9134, the identifier tied to the planned GIWA launch. That detail did most of the work. A chain ID tells a wallet which network it's talking to, but it says nothing about who controls the RPC or the bridge behind it, as CryptoSlate pointed out in its coverage.

On-chain analyst Stablemark traced the setup. Wallets tied to the operation were funded through ChangeHero on Sept. 26. About 11 hours later, the Safe wallet controlling the scheme and the fake bridge went live. For the next 13 hours, deposits kept coming: 1,333 wallets and 767 ETH by Stablemark's count.

Then the operators swapped the bridge's portal code and pulled out 766 ETH in one go. Nobody exploited a bug. The scammers owned the contract, so they changed it.

The stolen funds are already moving. Stablemark said 177 ETH went through Tornado Cash, while the other 589 ETH sat across four wallets at the time of his update. That adds up to the full 766, and most of it is still visible on-chain for now.

The DEX That Vouched For It

Here's the part that stings. The fake chain didn't spread on its own. DYORSWAP, a multichain DEX, initially treated it as the real GIWA mainnet and added support, which is how so many users ended up bridging.

DYORSWAP later said the chain was fraudulent and that the correct chain ID had made it look legitimate during its first verification. It also said its own smart contracts weren't compromised, and that it has flagged suspicious messages and individuals in the related community. Its warning to users was blunt: don't touch any unofficial GIWA RPC, bridge, or contract.

Users were not gentle about the initial listing. Plenty argued that the DEX's endorsement is exactly what made the bridge look safe.

Reimbursement reporting doesn't fully line up yet. CryptoSlate says DYORSWAP will pay 40% of the bridged amount to wallets that sent less than 5 ETH, with larger claims handled separately and requiring identity and address checks, because some big wallets may be tied to phishing or other fraud. Gokhshtein Media reports that DYORSWAP has already distributed more than 200 ETH from its own treasury. Either way, the payout is a fraction of the 766 ETH that disappeared.

Why GIWA Was The Perfect Bait

The timing wasn't random. Dunamu and the Optimism Foundation announced in May that GIWA would be the first Self-Managed OP Enterprise chain, with Upbit keeping operational control and Optimism providing backup infrastructure. Dunamu has been running the Sepolia testnet since September 2025, and in April it partnered with Hana Financial and POSCO International to test a cross-border remittance system on GIWA Chain.

GIWA also has no separate native token. ETH is the base asset. So "bridge some ETH to the new Upbit chain" sounds like a perfectly normal thing to do, and nothing about the ask looks off. There's no token to check, no airdrop to question.

Korean outlet Seoul Economic Daily stressed that this was not a hack of GIWA itself. That's true, and also a bit beside the point for the people who lost money.

What's Still Open

DYORSWAP says it's tracing the bridge deployer, the initial funding, the test wallets, and the final recipients. It's also preserving RPC records and community messages. The 589 ETH parked in four wallets is the number to watch. If it heads to a mixer or an exchange, the window for a freeze gets a lot smaller.

Espor haberlerini ve güncellemelerini kaçırmayın! Kaydolun ve haftalık makale özetini alın!
Kaydolun

The lesson for users is dull and unfortunate: a chain ID is a label. If the network isn't in the project's official docs, it doesn't exist yet, no matter how many people are trading on it.

REKLAMCILIK
Canlı bir yorum
Makaleyi beğiniz mi?
0
0

Yorum

REKLAMCILIK
FREE SUBSCRIPTION ON EXCLUSIVE CONTENT
Receive a selection of the most important and up-to-date news in the industry.
*
*Only important news, no spam.
SUBSCRIBE
LATER