TRM Labs says fake AI YouTube tutorials lured 224 victims into deploying malicious crypto contracts

TRM Labs says fake AI YouTube tutorials lured 224 victims into deploying malicious crypto contracts

N
News Editor
2026-09-18 17:07:18
TRM Labs said in a Sept. 14 report that scammers used fake YouTube tutorials about building an AI-powered crypto arbitrage bot to trick users into deploying and funding malicious smart contracts themselves. The blockchain intelligence firm said 224 victims lost a combined 274.6 ETH, worth about $517,000 at the time of transfer, with a median loss of 1 ETH. TRM identified 234 victim-deployed contracts, and the stolen funds ultimately moved to six collection addresses controlled by the operators. Unlike typical wallet-draining attacks, the scheme did not rely on phishing links, spoofed domains, or malicious approval prompts. Instead, victims voluntarily selected the tutorial, copied the code, deployed the contract, and funded it from their own wallets, which meant standard wallet warnings and phishing blacklists were not triggered. TRM also found nine near-identical YouTube videos posing as different creators. The videos used AI-generated presenters and voiceovers, promised a fully automated trading bot built with Claude, and directed users to compiler websites controlled by the attackers, some of which imitated the Remix development environment.

Blockchain intelligence firm TRM Labs said in a Sept. 14 report that fake YouTube tutorials pitching an AI-built crypto arbitrage bot were used to trick 224 victims into deploying and funding malicious smart contracts, leading to the theft of 274.6 ETH.

TRM said it identified 234 contracts deployed by victims. The funds ultimately flowed to six collection addresses controlled by the operators. The stolen ETH was worth about $517,000 at the time of transfer, and the median loss per incident was 1 ETH.

Victims authorized every step themselves

TRM said the scheme differed from common wallet-draining attacks because it did not involve phishing links, spoofed domains, or malicious approval prompts. Victims chose the tutorial themselves, copied the code, deployed the contract, and funded it from their own wallets.

Because each step was authorized by the victim, standard wallet security warnings and phishing blacklists were not triggered.

Nine near-identical videos posed as different creators

TRM found nine nearly identical YouTube tutorials published under the guise of different creators. The videos used AI-generated presenters and voiceovers, promised a fully automated crypto trading bot built with Claude, and directed victims to compiler websites controlled by the operators.

Some of those interfaces imitated the widely used Remix development environment.

Displayed code never reached the blockchain

In one variant analyzed by TRM, a backend script discarded the source code pasted by the victim and fetched a different contract from the operator's server. The clean code shown on screen was never deployed on-chain.

The substituted contract accepted deposits and, when the victim clicked Start or Withdraw, transferred any balance above 0.05 ETH to the operator. TRM said the contract contained no arbitrage logic and no AI functionality.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.