Fake YouTube tutorials promoting AI-powered cryptocurrency trading bots led 224 people to deploy malicious Ethereum smart contracts, allowing scammers to steal 274.6 ETH worth about $517,000.
Blockchain intelligence firm TRM Labs said in a Sep. 14 report that the operation used nine near-identical videos to direct viewers to compilers controlled by the scammers. Victims deployed 234 contracts and funded them through transactions they personally approved.
The campaign disguised malicious contracts as automated arbitrage tools supposedly built with Anthropic’s Claude. However, the code examined by TRM contained no AI model or trading function.
The stolen funds were ultimately transferred to six collection addresses controlled by the operators. The median victim lost 1 ETH, indicating the theft was spread across many users rather than being driven by a single large loss.
Users believed they were building trading bots
The scheme did not begin with a conventional phishing page asking for a wallet connection or broad token permissions. Instead, users were presented with what appeared to be an educational process and were encouraged to complete every onchain step themselves.
TRM found nine almost identical YouTube tutorials published under different creator identities. AI-generated presenters and voiceovers made the videos look like independent guides. Each promised to show viewers how to build a fully automated crypto arbitrage bot using Claude.
Viewers were instructed to copy code into a compiler website chosen by the presenter. Some of the sites imitated Remix, a widely used browser-based environment for writing and deploying Ethereum smart contracts.
Victims connected their wallets, compiled what appeared to be trading software and deployed the contracts. They then sent ETH to the newly created addresses, believing the funds would be used to profit from price differences between trading venues.
But in one version of the scam, a backend script ignored the code pasted by the victim. Instead, the website retrieved a separate contract from a server controlled by the operators and prepared that code for deployment.
This meant the clean-looking programme shown in the browser was not the one placed onchain. A visual check of the compiler window could therefore not reveal the actual contract being deployed.
The replacement contract accepted ETH, as a genuine trading bot might. Once its balance passed 0.05 ETH, pressing either the Start or Withdraw button transferred the funds to an address controlled by the scammers.
Start did not launch a trading strategy and Withdraw did not return the deposit. Both controls performed the same theft-related function.
Scam avoided several common wallet warnings
The approach differed from attacks involving fraudulent websites that request token allowances or unclear wallet signatures. Since users authorised the deployment, funding and later contract calls themselves, wallets could accurately display each transaction without recognising that the underlying code had been misrepresented.
Newly created contract addresses would also not necessarily appear on existing blocklists. Victims did not hand over seed phrases or approve an existing malicious contract; they were persuaded that they were creating the software themselves.
Traditional phishing campaigns often rely on copied domains, poisoned search results or permissions allowing a contract to move existing tokens. Wallet simulations and blocklists can sometimes detect those techniques, but they offered less protection against this deployment-based model.
In July, crypto.news explained how drainers commonly exploit legitimate blockchain permissions. A separate Hyperliquid phishing case in August saw one user lose about 550,000 USDC after a sponsored Google result led to a fake Hyperliquid website. Security firm Salus linked that site to the Inferno drainer ecosystem.
Salus said the infrastructure automatically divided stolen funds among connected addresses. Investigators associated related groups with approximately $52.74 million in losses, while backend services handled theft, swaps, consolidation and revenue sharing.
FBI accepts reports from US victims
US users can report cryptocurrency fraud and other cyber-enabled crimes to the FBI’s Internet Crime Complaint Center. The bureau says reports can help investigators connect cases, track emerging methods and, in some circumstances, freeze stolen funds.
The centre recorded $16.6 billion in reported internet-crime losses during 2024, compared with $12.5 billion in 2023. The FBI advises victims to report incidents even if they are uncertain whether the circumstances fit a particular crime category, as complaints may be shared with federal, state, local or international law enforcement.
In February, the Ethereum Foundation backed a Security Alliance engineer working to track and disrupt wallet drainers targeting Ethereum users.
Security Alliance cited figures showing drainer-related losses of $84 million in 2025, the lowest level on record. Its security network includes MetaMask, Phantom, WalletConnect and Backpack, which share threat intelligence about phishing campaigns and other malicious infrastructure.
