Scammers steal $2M in ETH as fake GIWA network fools DYORSWAP
DYORSWAP said it paid more than 200 ETH in compensation, while Upbit operator Dunamu’s GIWA warned that its mainnet had not launched.
Asanat Analysis — Why it matters
A fake GIWA network smart contract exploited DYORSWAP users through social engineering and impersonation, extracting ~$2M in ETH before detection. DYORSWAP's rapid 200 ETH compensation (~$660K) signals both the platform's commitment to user recovery and the high operational costs of security failures in DeFi. The scam exploited a common attack vector: users verifying legitimacy through visual similarity rather than cryptographic proof, compounded by GIWA's pre-mainnet status—creating plausible deniability cover for fraudsters.
This incident highlights persistent vulnerabilities in token swap aggregators and highlights the asymmetry between user vigilance and attack sophistication. DYORSWAP's name itself ('Do Your Own Research Swap') carries ironic weight; even informed users fell victim, suggesting the problem extends beyond superficial due diligence to infrastructure-level verification gaps. The timing—occurring while GIWA mainnet remained unlaunched—reveals how ecosystem fragmentation and token launch delays create exploitable windows where counterfeit versions operate undetected.
For the sector, this reinforces that compensation cultures and rapid response do not eliminate reputational damage or the underlying trust erosion. The prevalence of such attacks (fake token contracts, impersonation scams) continues to correlate with network congestion and user onboarding velocity, not security maturity. Platforms lacking hardened address registries or whitelisting mechanisms remain structurally exposed.