📈 Get daily crypto insights that make you smarter about your money

Fake AI Trading Bot Tutorials Drained 274.6 ETH From 224 Victims Who Deployed the Malicious Contracts Themselves

Fake YouTube tutorials promising viewers a free AI-powered crypto arbitrage bot have drained 274.6 ETH, worth roughly 517,000 USD at the time of the transfers, from 224 victims who unknowingly deployed the malicious contracts themselves, according to blockchain intelligence firm TRM Labs.

The September 14 report describes a scam that abandons the classic phishing playbook entirely. There are no copied domains, no poisoned search results and no suspicious wallet approval pop-ups. Instead, victims are talked through building their own drainer, step by step, in a scheme that turns the mark into the attacker’s deployment tool.

How the fake AI bot tutorials worked

TRM identified nine nearly identical YouTube tutorials published under different creator identities, each presented by AI-generated virtual hosts with synthetic voiceovers. The videos promised to teach viewers how to build a fully automated crypto arbitrage bot using Anthropic’s Claude, presenting the process as an educational exercise rather than an investment opportunity.

Viewers were told to copy source code displayed in the video and open a compiler website chosen by the presenter. Several of these sites copied the design of Remix, the widely used browser-based development environment for writing and deploying Ethereum smart contracts. Victims then connected their wallets, compiled what looked like legitimate trading software and deployed the resulting contracts to the blockchain.

Because users initiated and approved every action themselves, the transaction flow looked nothing like a conventional attack. Wallets accurately showed their owners deploying a contract, funding it and later calling one of its functions. The missing context was that the tutorial and the compiler had quietly swapped out the code.

The bait-and-switch hidden in the compiler

In one documented variant, a backend script ignored the source code victims pasted into the compiler window. Instead, the website retrieved a separate contract from a server controlled by the operators and prepared that replacement for deployment. The clean code displayed on screen was never placed onchain.

The replacement contract behaved exactly as a trading bot should in its early life: it accepted ETH deposits, matching user expectations that the bot needed capital to exploit price differences between venues. But once the contract balance exceeded 0.05 ETH, the code was set to forward the funds to an operator-controlled address whenever the user pressed either the Start or the Withdraw button.

Both buttons served the same purpose despite carrying the labels of ordinary bot controls. Pressing Start did not activate any trading strategy. Pressing Withdraw did not return the deposit. TRM’s analysis found no arbitrage system and no AI function in the malicious variant it examined. The Claude branding was pure sales pitch, while the onchain code did nothing but collect deposits and sweep qualifying balances.

234 contracts, six collection addresses, one median loss of 1 ETH

TRM traced 234 contracts deployed through the campaign, against 224 affected people, meaning some participants created more than one contract before realizing what had happened. Stolen funds eventually funneled into six collection addresses controlled by the operators.

The distribution of losses is notable for what it lacks: a single whale victim propping up the total. TRM calculated a median loss of 1 ETH per incident, indicating the damage was spread across a broad base of ordinary users, many of whom likely funded the contracts with modest amounts expecting passive arbitrage returns.

Why wallet protections missed the attack

Traditional crypto phishing defenses rely on pattern recognition. Blocklists flag known malicious addresses, domain checks catch lookalike sites and transaction simulations warn users when a signature grants broad token allowances or control over existing assets.

This operation slipped past those layers because each victim deployed a freshly created contract from their own wallet. A new address has no history to match against a blocklist. A wallet simulation can show that a user is deploying a contract and sending ETH to it, but without the context that the tutorial and compiler misrepresented the code, the activity resembles ordinary development work.

The social engineering happened offchain, in the video and on the fake compiler site, while every onchain action was technically initiated by the victim. That structure is what makes the campaign distinct from wallet-drainer attacks that spread through malicious links and blanket approvals, and it suggests a growing overlap between AI-generated content fraud and smart contract crime.

AI branding as the trust mechanism

The campaign also reflects how attackers are weaponizing the credibility of mainstream AI tools. By framing the scam around Claude and automated arbitrage, the operators tapped into current enthusiasm for AI agents in crypto trading, a narrative that legitimate projects have spent the past year promoting.

AI-generated hosts and voiceovers gave each tutorial the appearance of an independent guide while allowing the same script to be republished across multiple channels at low cost. TRM’s count of nine near-identical videos under different identities suggests an industrialized content pipeline rather than a one-off effort.

What users can take from it

The lesson from the TRM findings is uncomfortable: verifying what you see on screen is no longer enough when the deployment pipeline itself is compromised. Users who paste code into a third-party compiler are trusting that platform to compile exactly what is shown, and in this scheme that trust was the exploit.

Practical defenses include compiling code only through official or verified channels, treating any tutorial that requires funding a self-deployed contract with deep skepticism, and remembering that legitimate arbitrage opportunities rarely require retail users to build their own bots from a YouTube video. As AI tools make polished fraudulent content cheaper to produce, the burden of verification keeps shifting toward the user, and campaigns like this one show exactly how that gap gets exploited.

19 thoughts on “Fake AI Trading Bot Tutorials Drained 274.6 ETH From 224 Victims Who Deployed the Malicious Contracts Themselves”

  1. 224 people copied random code from a youtube video and pasted it into a compiler. the bot drains YOU, that was the whole product lol

  2. 274.6 ETH from 224 victims is around 2.3 ETH per person on average. These were not small wallets, which makes the fake Claude arbitrage framing even more effective.

    1. 2.3 ETH average says they filtered for people with real balances. the tutorial was pitched at intermediate users for a reason

      1. agreed, the 2.3 ETH average was not random. nobody with that kind of balance thinks of themselves as the beginner mark, thats exactly who the pitch was tuned for

  3. AI generated hosts reading a script about an AI bot. the scam pipeline is fully automated now except the part where the victim deploys the drainer for them

    1. and youtube takes weeks to pull these while the ai hosts keep uploading fresh ones. platform incentives are completely broken

  4. Nine tutorials, different creator identities, same contract. TRM Labs connecting those dots is good work, but YouTube should have caught this long before half a million dollars moved.

  5. the compiler ignored the code you pasted and served its own build. so even reading the solidity line by line wouldnt have saved you. grim

    1. exactly. the explorer even showed a verified badge because the code you pasted was real. the attack was the compiler output nobody could inspect

  6. the wildest part is the attacker had zero onchain footprint until a victim deployed. no poisoned approvals, nothing to trace. no wonder TRM needed the transfers themselves to map it

  7. 224 people copy pasted a free arbitrage bot from youtube and deployed the drainer themselves. TRM Labs calling it and i still can barely believe it

      1. easy to say ngmi but the tutorials had ai hosts and a fake Claude arbitrage framing pitched at intermediate users. blame the scammer, not the 224 people

        1. fair, but blaming the scammer only goes so far. the whole pitch leaned on an anthropic brand that nobody at anthropic was policing

  8. the genius part is no phishing link needed. the tutorial IS the attack. 274.6 ETH off a few synthetic voiceover videos, insane roi on that scam

    1. thats the part that breaks all the standard safety advice too. never share your seed, verify urls, none of it matters when you deploy the drainer yourself

  9. 517k usd from videos with ai voices and nobody thought to audit the contract before deploying it. ten minutes on a verifier would have caught this

    1. most of those 224 probably never deployed a contract before, they had no idea a verifier even exists. the tutorial format skipped right past that step

  10. TRM counted nine tutorials under nine different creator names with the same drainer underneath. someone ran this like a content pipeline

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$81,495.00+0.8%ETH$2,645.77+1.6%SOL$111.49-0.8%BNB$763.59+0.2%XRP$1.43+3.0%ADA$0.2298+4.1%DOGE$0.0903+3.4%DOT$1.13-0.2%AVAX$9.76+20.0%LINK$12.56+3.0%UNI$8.71-2.0%ATOM$1.73+3.3%LTC$57.74+2.3%ARB$0.2068-7.1%NEAR$3.65-4.3%FIL$1.11+25.0%SUI$0.8653+8.0%BTC$81,495.00+0.8%ETH$2,645.77+1.6%SOL$111.49-0.8%BNB$763.59+0.2%XRP$1.43+3.0%ADA$0.2298+4.1%DOGE$0.0903+3.4%DOT$1.13-0.2%AVAX$9.76+20.0%LINK$12.56+3.0%UNI$8.71-2.0%ATOM$1.73+3.3%LTC$57.74+2.3%ARB$0.2068-7.1%NEAR$3.65-4.3%FIL$1.11+25.0%SUI$0.8653+8.0%
Scroll to Top