Fake AI Bot Tutorials Tricked 224 Victims Into Deploying Their Own Drainers
Fake YouTube tutorials claiming to show how to build AI-driven crypto arbitrage bots tricked 224 victims into deploying malicious smart contracts that funneled 274.60 ETH to six operator addresses, TRM Labs reported. The scams ran from Feb. 12 to Aug. 11 and used spoofed compiler sites that swapped clean-looking source code for drain contracts at deployment.
Why It Matters
The campaign bypassed conventional wallet security checks by having victims deploy and fund contracts themselves, making the transactions appear legitimate and harder to detect. The case shows how social-engineered developer workflows and fabricated AI branding can be weaponized to steal crypto funds.
Key Facts
- Victims: 224
- ETH stolen: 274.60 ETH
- USD value at transfer: about $517,205
- Timeframe: Feb. 12 to Aug. 11
- Operator addresses: six collection addresses
Blockchain intelligence firm TRM Labs traced 274.60 ETH to six operator-controlled collection addresses after identifying a campaign that convinced victims to deploy malicious smart contracts themselves. According to TRMs Sept. 14 analysis, 224 people followed fake YouTube tutorials that purported to teach how to build arbitrage bots using the AI Claude, and in doing so created 234 victim-deployed contracts that forwarded funds to the operators.
The operators hosted nine nearly identical tutorial videos presented as if from different creators and linked viewers to web-based compiler sites. Some of those sites were styled to look like popular development environments such as Remix. TRM found that when victims pasted the on-screen source code into the fake compiler, a background script discarded that code and instead fetched a different contract from the operators server, so the source shown in the tutorial never reached the blockchain.
The substituted contracts accepted deposits and were coded to forward any balance above 0.05 ETH to the operator when victims clicked the tutorials instructed Start or Withdraw buttons. TRM said the contracts contained no arbitrage logic or AI-driven functionality and that the Claude branding was used solely as a marketing lure. One of the compiler sites attempted to extract a second payment by presenting a fabricated "gas nonce liquidity" error and prompting victims to add up to 1 ETH more, a term TRM noted is not an Ethereum concept.
TRM reported the cluster of nine tutorial videos had accumulated 310,474 views as of its analysis, and it also identified earlier variants of the scheme that used ChatGPT as the lure in 2025. The firm put the median individual loss at 1 ETH and valued the total stolen ETH at about $517,205 at the time of the transfers. The operation differed from typical drainer campaigns because victims themselves initiated the contract deployments and funding, which can make such transactions appear self-directed to wallet security systems.
Keep Reading

WisdomTree Opens Tokenized Treasury Fund To MoonPay's 35 Million Accounts
Morpho Opens Borrowing Against Coinbase's Tokenized Stocks
Bitcoin Runs to $81,000 and NEAR Adds 32% as Tokenization Tokens Lead
Blockchain Dead Drop Attacks Jump 420% as State Hackers Expand
Original source: The Defiant