Scammers Launch Fake ETH L2 to Steal $2M From Crypto Traders

1 hour ago

An unidentified radical of menace actors launched a fake L2 concatenation impersonating Giwa, a task backed by Upbit, identified by DYORSWAP, a multichain decentralized exchange. Over 760 ETH bridged to the concatenation were lost, and DYORSWAP announced a compensation process for affected users.

Key Takeaways

  • A fake GIWA Ethereum L2 concatenation drained 766 ETH (over $2M) from 1,335 users who bridged funds.
  • Scammers deployed a analyzable fake concatenation with functioning bridges, initially deceiving DYORSWAP.
  • DYORSWAP is investigating the scam and refunding users, but faces backlash for enabling it.

Fake Giwa L2 Chain Deployment Scheme Causes Over 760 ETH successful Losses

A caller blase strategy involving the motorboat of a fake Ethereum L2 solution has been reported for the archetypal time, affecting implicit a 1000 users who bridged their funds to the chain.

The chain, which utilized 9134 arsenic its Chain ID number, was identified by DYORSWAP, a multi-chain decentralized speech (DEX), arsenic the mainnet for GIWA, an Upbit-backed task astatine first, taking aboriginal adopters to rapidly span funds to the concatenation to instrumentality vantage of the fiscal opportunities next.

Initially, immoderate claimed the scam lone progressive taking a mean ETH code and posting it arsenic an L2 chain. Nonetheless, in its authoritative report, DYORSWAP stressed this was not the case, arsenic the concatenation deployment included an OP stack-style infrastructure, a bridge, and a batcher, indicating a larger grade of sophistication.

The theft was executed aft implicit 1,335 addresses bridged funds to the contract, with astir 766.25 ETH drained from these users, valued astatine implicit $2 cardinal astatine the clip of writing.

Before the funds were drained, DYORSWAP identified existent question successful the impersonating chain, with idiosyncratic transactions including buys, sells, and token launches happening successful existent time.

“Until further notice, DO NOT usage immoderate unofficial GIWA Mainnet RPC, bridge, oregon contract, and DO NOT nonstop funds to immoderate related addresses,” DYORSWAP declared aft detecting that idiosyncratic funds were drained.

Nonetheless, arsenic the incidental happened, the existent Giwa task clarified that it had not stealth-launched its mainnet. “We DO NOT person our mainnet moving currently. Any of those posts claiming that they person GIWA mainnet RPC accusation are NOT TRUE,” Giwa explained connected societal media.

While it denied nonstop work successful the attack, saying the funds were drained from the fake chain, DYORSWAP started a reimbursement process for affected users, claiming it had already distributed implicit 200 ETH from its ain funds.

DYORSWAP stressed that it volition proceed to analyse and reconstruct the full fake concatenation transaction past to place and hint the attacker’s addresses.

Even so, users criticized DYORSWAP’s approach, arguing that without their involvement, nary would person noticed the concatenation motorboat oregon bridged funds onto it, labeling it a societal engineering scam.

The fake Giwa mainnet motorboat strategy follows a bid of information incidents targeting some decentralized and centralized platforms, which are keeping crypto holders connected changeless alert.

View source