Fraudulent Network Stole 766 Ether
A network impersonating GIWA Chain 9134 successfully transferred hundreds of Ether from a cross-chain bridge.
Updated on Sept. 28, 2026 in Financial Crime

Live Poll
Do you trust cryptocurrency platforms to adequately protect and reimburse users from fraudulent bridge exploits?
A malicious network posing as GIWA Chain 9134 siphoned 766.25 Ether from a cross-chain bridge, impacting 1,335 individual addresses. In response, DYORSWAP has issued reimbursements totaling over 200 Ether to those affected by the security breach.
Why it matters
The incident highlights significant security vulnerabilities within cross-chain bridge infrastructure that can be exploited by fraudulent deployments. By utilizing its own capital to reimburse victims, the project team aims to mitigate the immediate impact on users while investigations continue.
A fraudulent network deployed on September 26 successfully drained 766.25 Ether from a cross-chain bridge, with 1,335 addresses collectively bridging 767.65 Ether into the compromised system.
The players
DYORSWAP
This organization is a decentralized exchange platform that managed the reimbursements for users affected by the fraudulent network attack.
ChangeHero
This is a cryptocurrency exchange service identified in the audit as the source of the initial 0.045 Ether used to fund the fraudulent network deployment.
The details
The fraudulent network, which impersonated GIWA Chain 9134, was launched using initial funding of 0.045 Ether linked to ChangeHero. DYORSWAP officials are currently tracking the bridge deployer as part of an ongoing security investigation.
Timeline
The deployment address received 0.045 Ether on September 26, 2026, at 09:40:59 UTC.
The fraudulent network was officially deployed on September 26, 2026, at 18:10:59 UTC.
Legal Context
This incident follows a pattern set by the 2022 Ronin Bridge exploit, illustrating the persistent security risks inherent in cross-chain bridge protocols. As these platforms continue to be targeted, regulatory scrutiny and security auditing requirements for decentralized infrastructure are likely to intensify.
Users who bridged funds to the compromised address should monitor official project communications regarding additional reimbursement steps. The investigation into the bridge deployer may result in further technical security updates to prevent similar fraudulent network deployments.
The takeaway
Users interacting with cross-chain bridges should verify the legitimacy of the network deployment to avoid falling victim to similar impersonation schemes. DYORSWAP users should remain vigilant and only interact with verified contract addresses to ensure the safety of their digital assets.
Further reading
For more information on current threats in the digital asset space, visit the Financial Crime section.
Live Poll
Do you trust cryptocurrency platforms to adequately protect and reimburse users from fraudulent bridge exploits?







