
Fake YouTube tutorials promoting AI-powered crypto arbitrage bots have successfully tricked 224 victims into deploying malicious smart contracts that stole 274.6 ETH worth approximately $517,000. According to a report by TRM Labs released on September 14, the operation disguised malicious Ethereum contracts as automated trading tools built with Anthropic's Claude, allowing scammers to steal funds without relying on conventional phishing links or suspicious wallet approvals. The blockchain intelligence firm traced 234 contracts deployed by victims, although the campaign affected 224 people because some participants created more than one contract. The investigation revealed that the attackers deceived users into deploying their own token drainers, effectively tricking them into authorizing the theft of their own assets.
The scammers presented the scheme as an educational process rather than a direct wallet attack. As reported by TRM Labs, victims found the videos, followed instructions, and took each onchain step themselves. TRM identified nine nearly identical YouTube tutorials presented under different creator identities, with AI-generated virtual hosts and voiceovers giving the videos the appearance of independent guides. During the videos, users were told to copy code and open a compiler website selected by the presenter, with some websites copying the design of Remix, a commonly used browser-based development environment for writing and deploying Ethereum smart contracts.
The replacement contract could accept ETH deposits, matching the expected behavior of a trading bot that needed funds to operate. According to TRM Labs, once its balance exceeded 0.05 ETH, the contract was set to transfer the money to an address controlled by the operators when the user selected either the Start or Withdraw function. Both buttons served the same purpose despite carrying labels associated with normal bot controls, with pressing Start not activating a trading strategy and pressing Withdraw not returning deposited funds to the user. No AI model interacted with the deployed contract, and the method reduced the chance that common wallet protections would interrupt the process.
Based on ETH's value when the transfers occurred, the 274.6 ETH stolen was worth approximately $517,000. As reported by TRM Labs, the stolen funds eventually reached six collection addresses controlled by the operators. The firm calculated a median loss of 1 ETH per incident, showing that the total did not depend on a single large victim. The campaign used a different approach than traditional crypto phishing campaigns, as each victim became the deployer of a newly created contract and authorized the deployment and funding transactions without surrendering a seed phrase.
For U.S. users, the FBI's Internet Crime Complaint Center accepts reports involving cryptocurrency fraud and other cyber-enabled crimes. According to the FBI, complaint data can help investigators identify connected cases and follow emerging methods, with the agency recording $16.6 billion in reported internet-crime losses during 2024, up from $12.5 billion in 2023. The Ethereum Foundation has also increased focus on attacks using valid user actions to execute theft, with the Security Alliance citing data placing drainer-related losses at $84 million in 2025, the lowest level on record.