BackAI Scam

AI Scam

TRM Labs
2026-09-18 17:00:08

Fake AI bot tutorials led 224 victims to deploy and fund their own drainers, TRM says

A scam built around fake YouTube tutorials persuaded 224 people to deploy and fund malicious smart contracts themselves, according to a Sept. 14 analysis from TRM Labs. The blockchain intelligence firm said the operation drained 274.60 ETH between Feb. 12 and Aug. 11 through 234 victim-deployed contracts that routed funds to six collection addresses controlled by the operators. At the time of the transfers, the stolen ETH was worth about $517,205, and the median loss was 1 ETH. TRM said the scheme stood apart from standard drainer campaigns because it did not depend on malicious token approvals or spoofed websites. Victims selected a tutorial, copied code, deployed a contract, and funded it from their own wallets, making the activity look self-initiated to wallet security tools. In the version TRM reviewed, a fake compiler site replaced the code pasted by the user with a different contract fetched from an operator-controlled server. The substituted contract had no arbitrage logic and no AI capability. Instead, it accepted deposits and sent balances above 0.05 ETH to the operators when users clicked Start or Withdraw. TRM also said one site tried to trigger a second payment with a fabricated error message, while the nine identified videos were still online in September with 310,474 combined views.

40
Fake AI bot tutorials led 224 victims to deploy and fund their own drainers, TRM says
Policy and Re
2026-08-31 10:55:47

AI-driven impersonation scams are overtaking code exploits as a core crypto security threat

Impersonation and AI-assisted fraud are becoming one of the most serious security problems in crypto, shifting attention away from code bugs alone and toward identity, access control, and accountability. Chainalysis said at least $14 billion in on-chain funds flowed into crypto scams in 2025, though not all of that activity was tied to AI. Within a subset of cases linked on-chain to AI vendors, the average scam operation was about $3.2 million, compared with roughly $719,000 for scams without those links, a correlation the company did not describe as causal. Executives interviewed across the sector pointed to a broad change in attack methods. Binance Chief Security Officer Jimmy Su said smart-contract security has improved enough that attackers now focus more on people around protocols, credentials, and governance systems, citing Binance security team assistance in stopping a $1.2 million governance attack on BrainTrust. Binance Research also said access control failures accounted for about two-thirds of the $621 million lost to DeFi exploits in April 2026 alone. The report also highlights unresolved attribution issues, mixer-related tracing gaps, and a new frontier in AI agents that can pay, register for services, and potentially transact on users’ behalf. Several executives argued that the missing layer is not transaction verification itself, but trustworthy identity and responsibility behind those actions.

590
AI-driven impersonation scams are overtaking code exploits as a core crypto security threat