DYORSWAP Hack
What happened
On September 26–27, 2026, scammers deployed a fake OP Stack Layer 2 network impersonating the unreleased GIWA Mainnet (Chain ID 9134) and set up a fraudulent bridge. 1,335 user addresses deposited 767.65 ETH into the fake bridge to trade on DYORSWAP, allowing the scammers to extract 766.25 ETH (~$2.0 million USD) on Ethereum.
The incident was a fake infrastructure scam rather than a smart contract flaw in DYORSWAP's protocols. Scammers configured a malicious network using GIWA's official Chain ID (9134) alongside a fake bridge and OP Stack batcher. When traders connected to the fake RPC and deposited ETH to trade on DYORSWAP, the malicious bridge contract captured the L1 funds.
The scammers drained 766.25 ETH at Ethereum block 26,067,309. DYORSWAP confirmed its core contracts were safe, published a claims collection form, and distributed over 200 ETH from its treasury to compensate affected users while tracing the scammers' funding sources.
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.