Home News Fake GIWA Bridge Scams Users Out of $2M as Circle and Tether Freeze Bitget Hack Funds

Fake GIWA Bridge Scams Users Out of $2M as Circle and Tether Freeze Bitget Hack Funds

Fake GIWA Bridge Scams Users Out of $2M as Circle and Tether Freeze Bitget Hack Funds

The latest wave of crypto security incidents highlights two different vulnerabilities in the digital-asset economy: the ability to manufacture convincing blockchain infrastructure and the difficulty of recovering assets once a major exchange breach has occurred.

A fake GIWA bridge reportedly drained about $2 million in Ether, while Circle and Tether moved to freeze a small portion of assets connected to the much larger Bitget hack. The GIWA incident is particularly revealing because the attackers did not simply create a fraudulent website.

They constructed a counterfeit Layer-2 environment that appeared to represent GIWA, an Ethereum-based network developed by Dunamu, the operator of South Korean crypto exchange Upbit. GIWA’s actual mainnet had not launched, yet the fraudulent network presented users with infrastructure that looked sufficiently legitimate to attract deposits.

According to DYORSWAP’s reconstruction, approximately 1,335 addresses deposited around 767.65 ETH into the fake bridge. About 766.25 ETH was subsequently drained, representing roughly $2 million at the time.

The attackers reportedly used GIWA-associated chain information, including Chain ID 9134, alongside an RPC endpoint and bridge infrastructure. The combination created a convincing imitation of a blockchain that users expected to become operational.

The episode demonstrates why blockchain verification cannot depend on a single identifier. A chain ID can help wallets distinguish networks, but it does not establish who controls the network, bridge contracts or RPC infrastructure.

DYORSWAP said its own contracts were not compromised and has begun compensating affected users, reportedly distributing more than 200 ETH from its own funds while continuing to investigate the attackers. The Bitget incident presents a different security problem.

The exchange initially reported that approximately $351.6 million in assets had been affected by unauthorized transfers from some hot wallets. Bitget later revised the estimated amount to approximately $387.5 million after accounting for additional assets on Zcash and TRON.

The company said its cold wallets and separate self-custodial Bitget Wallet were not affected. In response, stablecoin issuers Circle and Tether froze a wallet associated with the attack. The address contained approximately 218,023 USDT and 99,990 USDC.

Meaning only about $318,000 in stablecoins was immobilized. That amount is small compared with the overall losses, but the intervention illustrates an important characteristic of centralized stablecoins: issuers can sometimes blacklist specific addresses and prevent their tokens from being transferred.

The limitations are equally important. Freezing USDC and USDT does not freeze Ether, XRP or other native blockchain assets. Reports indicated that substantial amounts of stolen XRP were moved after the breach, demonstrating how quickly assets can travel beyond the reach of issuer-level controls.

The incidents underline a broader lesson for crypto markets. Security is no longer simply about auditing smart contracts. Users must also verify bridge addresses, RPC endpoints, chain identifiers, deployment status and official announcements.

Meanwhile, exchanges and stablecoin issuers must balance rapid intervention against the decentralized architecture of the networks they serve. As blockchain adoption expands.

Trust increasingly depends on infrastructure verification as much as cryptographic security. The GIWA scam showed how easily legitimacy can be manufactured, while the Bitget response showed how difficult it can be to contain stolen assets once they cross multiple networks.

No posts to display

Post Comment

Please enter your comment!
Please enter your name here