Skip to content
Fake Ethereum L2 Chain Scam Steals $2M from Users

Fake Ethereum L2 Chain Scam Steals $2M from Users

First seen 30 Sep 2026, 18:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 20:30 UTC
  • •Over 766 ETH stolen in a scam involving a fake Ethereum Layer 2 chain.
  • •1,335 users were deceived into bridging funds to the counterfeit chain.
  • •The real Giwa project has not launched any mainnet, confirming the scam's nature.

A sophisticated scam involving a counterfeit Ethereum Layer 2 chain impersonating the Giwa project resulted in the theft of over 766 ETH (approximately $2 million) from 1,335 users. The fraudulent chain, which launched on September 26, featured a deceptive OP stack-style infrastructure and a functioning bridge, tricking users and the decentralized exchange DYORSWAP. The real Giwa project confirmed it has not launched any mainnet, indicating that the scam was entirely fabricated. DYORSWAP has initiated reimbursements for affected users and is currently investigating the incident. This event underscores ongoing security threats in the cryptocurrency sector, particularly from fake projects and social engineering tactics.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-26
Fake Ethereum Layer 2 chain launched
A counterfeit Ethereum Layer 2 chain mimicking the Giwa project was launched, leading to significant user losses.
Pluang
2026-09-28
DYORSWAP starts reimbursements
DYORSWAP began reimbursing users affected by the fraudulent chain and is investigating the incident.
Pluang

More articles in this cluster (2)

Following this threat?

Track Dyorswap in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

How did the scam operate?
The scam involved a fake Ethereum Layer 2 chain that impersonated the Giwa project, tricking users into bridging their funds.
What is the current status of reimbursements?
DYORSWAP has started reimbursing affected users and is investigating the incident further.
What should users do to protect themselves?
Users should verify the legitimacy of projects before bridging funds and remain cautious of social engineering tactics.