Blockchain intelligence firm TRM Labs said in a Sept. 14 report that fake YouTube tutorials pitching an AI-built crypto arbitrage bot were used to trick 224 victims into deploying and funding malicious smart contracts, leading to the theft of 274.6 ETH.
TRM said it identified 234 contracts deployed by victims. The funds ultimately flowed to six collection addresses controlled by the operators. The stolen ETH was worth about $517,000 at the time of transfer, and the median loss per incident was 1 ETH.
Victims authorized every step themselves
TRM said the scheme differed from common wallet-draining attacks because it did not involve phishing links, spoofed domains, or malicious approval prompts. Victims chose the tutorial themselves, copied the code, deployed the contract, and funded it from their own wallets.
Because each step was authorized by the victim, standard wallet security warnings and phishing blacklists were not triggered.
Nine near-identical videos posed as different creators
TRM found nine nearly identical YouTube tutorials published under the guise of different creators. The videos used AI-generated presenters and voiceovers, promised a fully automated crypto trading bot built with Claude, and directed victims to compiler websites controlled by the operators.
Some of those interfaces imitated the widely used Remix development environment.
Displayed code never reached the blockchain
In one variant analyzed by TRM, a backend script discarded the source code pasted by the victim and fetched a different contract from the operator's server. The clean code shown on screen was never deployed on-chain.
The substituted contract accepted deposits and, when the victim clicked Start or Withdraw, transferred any balance above 0.05 ETH to the operator. TRM said the contract contained no arbitrage logic and no AI functionality.

