Rug confirmed and traced — DYOR "GIWA Mainnet" (chainId 9134)
• 2026-09-27, 07:29:59 UTC — 766.25 ETH left the L1 Portal 0xba9938c0b96a70e6479661b915e7e481fe435ab2 in a single call, sent to 0x04a9c8d8fee491411bda28b68ad80f0122fc4134. After that the Portal was left with ~2.25 ETH — and users kept depositing without knowing (0.006 / 0.0018 ETH…).
• A legitimate OptimismPortal has no function to send ETH to an arbitrary address — withdrawals require a valid proof from L2. So this was a backdoored implementation / malicious upgrade / withdrawal finalized with a fake proof (they control the "L2"). The proxy is admin-controlled by a Gnosis Safe (0xccc2aecf5d24f0ea30cf81ec0dbec59f19ddcd10) that executed the drain via execTransaction at 07:29 — permissioned fault proofs mean the operator can "prove" any withdrawal.
• The RPC giwarpc.dyorrpc.fun is fake — it feeds falsified data to bots (e.g., it reported the proxy-admin owner as 0xddd3aecf…, while the real on-chain owner is 0xccc2aecf…).
Money trail: 0x04a9c8d8… (EOA) is laundering the 766 ETH in 10-ETH tranches to 0xd90e2f925da726b50c4ed8d0fb90ad053324f31b (+37 ETH to 0xec160acd…); ~107 ETH still sitting in the drain wallet.
Deployer: 0x119e68b59c44291f76324c76377b776d0b4dd38c.
Do not use giwarpc.dyorrpc.fun or dyorv3.org, and warn any bot users to stop bridging/depositing to that chain immediately.
Post #3624
161