Scammers Create Fake Ethereum Layer-2, Steal $2M

A counterfeit Ethereum Layer-2 lured users to connect wallets and approve transfers, allowing attackers to withdraw about $2 million from traders’ accounts.

Fraudsters launched a fake Ethereum Layer-2 network that persuaded traders to bridge assets and grant token approvals. Attackers then drained roughly $2 million from user wallets into addresses they control before the bogus service was taken offline.

The counterfeit platform presented lower fees and faster transactions to attract users away from the main Ethereum chain. Victims were directed to a website, asked to connect their wallets and confirm transfers or token allowances for a fake bridge and associated contracts. Once approvals or transfers were completed, funds moved to attacker-controlled addresses and were consolidated into a few recipient wallets.

Blockchain records show funds flowing from many user addresses into a small number of wallets, consistent with coordinated extraction. Some of the stolen assets were routed through multiple addresses and mixed, apparently to hide their origin. Law enforcement and blockchain-tracing firms are analysing transaction histories and tracking possible cash-out paths; recovery of the assets has not been confirmed.

Affected traders reported losses across stablecoins and other Ethereum-based tokens. The attack relied on impersonation and social engineering: the fake site copied the look and language of legitimate Layer-2 services, and domain names and messages resembled known projects to reduce suspicion. Because bridging often requires signing approvals or moving funds off the main chain, the attackers exploited that required step to seize tokens.

Security firms warn that scams impersonating networks or bridges can be hard to detect, especially for users seeking lower fees and faster transactions. A wallet approval can let an external contract move approved tokens without additional confirmations from the user’s wallet interface.

Investigators recommend that users verify official project domains, cross-check contract addresses in blockchain explorers and confirm links through project channels before approving contracts or bridging assets. Wallet providers and community resources publish guidance on spotting fake sites and suspicious contract behavior.

The investigation into who operated the fake Layer-2 network is ongoing. Blockchain tracing continues as authorities and private firms try to follow the funds and identify any points where the assets were converted or cashed out.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author