Fake Ethereum Layer-2 Drains About $2M From User Wallets

Attackers set up a counterfeit Ethereum Layer-2 network that convinced traders to connect wallets and approve transfers or bridge assets. After victims granted approvals, roughly $2 million was moved into attacker-controlled addresses and consolidated into a few wallets. Investigators are tracing the transactions, but recovery has not been confirmed.
The fraudulent network posed as a real Ethereum scaling option, promising lower costs and speedier settlement to pull traders off the main chain. People linked their wallets and authorized transfers or token permissions for a sham bridge and its contracts. After those approvals, holdings went to addresses run by the attackers and were pooled into a limited number of wallets.
Victims reported losing stablecoins and various tokens built on Ethereum. On-chain data indicated numerous victim wallets fed a handful of recipient addresses, with some proceeds passing through several addresses and blending steps. Investigators and analytics teams are examining transaction trails and where funds might be converted; no recovery has been verified.
This incident could deepen caution among retail crypto users, especially those drawn to lower-fee networks and bridges. It may slow adoption if traders hesitate to approve contracts or move assets across chains. Projects impersonated by such scams might face added scrutiny, while tracing firms and authorities could see more demand for investigation. The main burden may fall on affected individuals, who face uncertain recovery and possible losses.