Fake AI bot tutorial drain campaigns on YouTube
TRM Labs’ September analysis found that fake YouTube tutorials promising AI-built arbitrage bots tricked 224 victims into deploying and funding malicious smart contracts that drained 274.60 ETH between February and August 2026. The firm traced 234 victim-deployed contracts feeding six operator-controlled collection addresses; using ETH’s value at the time of transfers, the total was about $517,205 and the median loss per victim was 1 ETH. Operators presented nine nearly identical videos with AI-generated hosts and scripts, using Anthropic’s Claude name as part of the sales pitch even though no Anthropic product or AI functionality was present in the onchain code.
The schemers routed victims to compiler websites they controlled, some styled to resemble the widely used Remix development environment. In the variant TRM examined, a backend script discarded the source code pasted by the victim and instead fetched a different contract from the operator’s server. The clean code shown on screen never reached the blockchain. The replacement contract accepted ETH deposits and was configured to forward balances above 0.05 ETH to operator addresses when users pressed on-screen Start or Withdraw buttons. Because victims themselves initiated and approved the deployments and funding transactions, common wallet protections and blocklists were less likely to flag the operation as malicious.
TRM noted the nine videos had accumulated more than 310,000 views as of September and that similar campaigns had previously used ChatGPT branding in 2025, demonstrating how operators can swap AI labels without changing the theft mechanism. The stolen funds moved entirely over decentralized infrastructure, including DeFi services, cross-chain bridges, and a mixer; investigators did not identify a centralized exchange in the outbound flow. For U.S. victims, the FBI’s Internet Crime Complaint Center accepts reports of cryptocurrency fraud, and TRM’s report highlighted that filing complaints can help link related cases or, in some instances, support law enforcement actions. Onchain security groups such as the Security Alliance have also increased efforts to track and disrupt drainers that exploit valid user actions to execute theft.
This summary is composed by the cFlash AI agent from multiple public sources, under human supervision. The content is for informational purposes only and does not constitute investment, financial, legal, or tax advice.