Bitget Theft Drives September Crypto Hack Losses to $766M
September's crypto hack losses hit $766.49 million, up 462% from August, led by Bitget's $387 million theft. PeckShield logged 55 major incidents.
Scammers created a fake GIWA chain and bridge, tricking DYORSWAP and over 1,000 users into sending 767 ETH, later funneled to Tornado Cash.
Scammers deceived the multi-chain decentralized exchange DYORSWAP over the weekend, causing it to integrate a fake version of the upcoming GIWA blockchain, resulting in $2 million in losses.
More than a thousand users, keen to get in early on a new chain, transferred 767 ETH in total to the fraudulent bridge contract. The scammers later withdrew those funds and channeled them through Tornado Cash.
stop bridge and trade in giwa and we are checking
— DYORSWAP (@DYORSWAPDEX) September 27, 2026
Not long after the bridge funds were taken, DYORSWAP acknowledged that “the so-called GIWA Mainnet we previously identified was in fact a fake chain set up by scammers.”
In a twist of irony, DYORSWAP's name comes from the acronym for "do your own research," a phrase frequently recommended as essential for crypto safety.
The fake OP Stack chain used the same chain ID as the real GIWA network, 9134, which made it "appear legitimate during [DYORSWAP’s] initial verification."
DYORSWAP's statement also referred to "specific suspicious messages" that might have introduced the false information to its community.
The fake bridge, deployed shortly after 6 PM UTC on Saturday, was drained just over 12 hours later.
DYORSWAP provided a 40% refund to users who had bridged less than five ETH. Addresses that surpassed that threshold will be considered on a case-by-case basis.
"Powered by UPbit," GIWA is an upcoming Layer 2 network built on the OP Stack, which launched its testnet last year.
The official GIWA X account was forced to emphatically debunk the existence of its mainnet. However, the post came too late, just minutes before the fake GIWA bridge contract was emptied.
One observer described the theft as "social engineering at the highest level."
someone faked the entire GIWA chain setup, got the bridge/RPC picked up by DYOR, and made $2m+ in a few hours
— stablemark (@stablemark_) September 27, 2026
social engineering at the highest levelhttps://t.co/RpUX7yvZux pic.twitter.com/E5MS97OOgA
DYORSWAP published a later update identifying addresses that, "based on timing and behavior," it believes were behind the scam, funded from exchanges Binance and Gate.
That post also counted 1,335 addresses that had bridged a total of 767.65 ETH, nearly all of which was later drained.
The post presents DYORSWAP as a victim along with its users and states that it has distributed more than 200 ETH in compensation.
An address claiming to be from the DYORSWAP team has reached out to the scammers on-chain requesting the return of the stolen funds.
Share to
Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.
September's crypto hack losses hit $766.49 million, up 462% from August, led by Bitget's $387 million theft. PeckShield logged 55 major incidents.
A MetaMask security incident poses no immediate threat to wallets, but the company is exiting affected Lido staking validators as a precaution.
Misha Komarov from alloc/init discussed Shielded Bitcoin, a research concept using zero-knowledge proofs to hide transaction details, requiring no soft fork.
HSBC named its Hong Kong dollar stablecoin RedCoin, set to launch in H2 2026 via PayMe and HSBC HK app, but key details are missing.