Close Menu

    Subscribe to Updates

    What's Hot

    Announcing the Devcon SEA venue!

    September 18, 2026

    Fake AI trading bot tutorials steal 274.6 ETH from 224 victims

    September 18, 2026

    Sepolia Incident | Ethereum Foundation Blog

    September 18, 2026
    Facebook X (Twitter) Instagram
    laicryptolaicrypto
    Demo
    • Ethereum
    • Crypto
    • Altcoins
    • Blockchain
    • Bitcoin
    • Lithosphere News Releases
    laicryptolaicrypto
    Home Fake AI trading bot tutorials steal 274.6 ETH from 224 victims
    Crypto

    Fake AI trading bot tutorials steal 274.6 ETH from 224 victims

    John SmithBy John SmithSeptember 18, 2026No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Fake YouTube tutorials promoting AI-powered crypto arbitrage bots have tricked 224 victims into deploying malicious smart contracts that stole 274.6 ETH worth about $517,000.

    Summary

    • Nine similar YouTube videos directed users to compilers controlled by the scam operators.
    • Victims deployed 234 contracts and funded them through transactions they approved themselves.
    • A malicious backend replaced the code shown to users with contracts designed to steal ETH.
    • Stolen funds moved to six collection addresses, with the median victim losing 1 ETH.

    TRM Labs said in a Sep. 14 report that the operation disguised malicious Ethereum contracts as automated trading tools built with Anthropic’s Claude, allowing the scammers to steal funds without relying on conventional phishing links or suspicious wallet approvals.

    The blockchain intelligence firm traced 234 contracts deployed by victims, although the campaign affected 224 people because some participants created more than one contract. Funds taken through the contracts eventually reached six collection addresses controlled by the operators.

    Based on ETH’s value when the transfers occurred, the 274.6 ETH stolen was worth approximately $517,000. TRM calculated a median loss of 1 ETH per incident, showing that the total did not depend on a single large victim.

    Fake AI trading bot tutorials turned victims into contract deployers

    Rather than sending users to a page that immediately requested access to their wallets, the operators presented the scheme as an educational process. Victims found the videos, followed the instructions, and took each onchain step themselves.

    TRM identified nine nearly identical YouTube tutorials presented under different creator identities. AI-generated virtual hosts and voiceovers gave the videos the appearance of independent guides, while each tutorial promised to help viewers create a fully automated crypto arbitrage bot using Claude.

    During the videos, users were told to copy code and open a compiler website selected by the presenter. Some of the websites copied the design of Remix, a commonly used browser-based development environment for writing and deploying Ethereum smart contracts.

    Victims then connected their wallets, compiled what appeared to be trading software, and deployed the resulting contracts. Because the users initiated and approved each action, the transactions looked different from attacks in which a fraudulent site asks for a direct token allowance or an unclear signature.

    Funding the newly deployed contracts completed the trap. Users believed they were supplying capital that the bot would use to exploit price differences between trading venues, but TRM found no arbitrage system or AI function in the malicious contract variant it examined.

    The malicious contracts drained deposits above 0.05 ETH

    In one version of the scheme, a backend script ignored the source code that victims pasted into the compiler. The website instead retrieved a separate contract from a server operated by the scammers and prepared the replacement for deployment.

    As a result, the clean code displayed in the browser was never placed onchain. Victims saw one program on their screens while their wallets deployed another, preventing them from verifying the real contract through a visual check of the compiler window alone.

    The replacement contract could accept ETH deposits, matching the expected behavior of a trading bot that needed funds to operate. Once its balance exceeded 0.05 ETH, however, the contract was set to transfer the money to an address controlled by the operators when the user selected either the Start or Withdraw function.

    Both buttons therefore served the same purpose despite carrying labels associated with normal bot controls. Pressing Start did not activate a trading strategy, while pressing Withdraw did not return the deposited funds to the user.

    No AI model interacted with the deployed contract, according to TRM’s findings. The Claude branding formed part of the sales pitch, while the onchain code only received deposits and moved qualifying balances to the scammers.

    The method also reduced the chance that common wallet protections would interrupt the process. A wallet could accurately show that its owner was deploying a contract, sending ETH to it and later calling one of its functions, yet still lack the context needed to determine that the tutorial and compiler had misrepresented the code.

    AI trading bot scam bypassed common phishing defenses

    Traditional crypto phishing campaigns often depend on copied domains, poisoned search results or prompts that request broad token permissions. Blocklists and wallet simulations can sometimes identify a known malicious address, deceptive domain, or transaction that grants an attacker control over existing assets.

    The AI trading bot operation used a different path because each victim became the deployer of a newly created contract. A fresh address would not necessarily appear on an existing blacklist, and the wallet owner authorized the deployment and funding transactions without surrendering a seed phrase.

    In July, crypto.news explained how drainers commonly abuse legitimate blockchain permissions. Such tools often convince a user to approve a malicious contract, which can then transfer tokens while the blockchain processes the action as authorized.

    The campaign described by TRM moved the deception one step earlier by controlling the code-generation and deployment process. Instead of asking victims to trust an existing contract, the tutorials convinced them that they were creating the software themselves.

    A separate Hyperliquid phishing case in August showed how online advertising can also direct crypto users toward malicious infrastructure. One user lost about 550,000 USDC after a sponsored Google result led to a fake Hyperliquid website linked by security firm Salus to the Inferno drainer ecosystem.

    Salus said the infrastructure in that incident automatically divided stolen funds among addresses connected to the operation. Investigators linked related groups to approximately $52.74 million in losses, showing how backend services can handle theft, swaps, consolidation, and revenue sharing while separate operators focus on attracting victims.

    U.S. users can report crypto losses through the FBI

    For U.S. users, the FBI’s Internet Crime Complaint Center accepts reports involving cryptocurrency fraud and other cyber-enabled crimes. The bureau says complaint data can help investigators identify connected cases, follow emerging methods and, in some situations, freeze stolen funds.

    The FBI recorded $16.6 billion in reported internet-crime losses during 2024, up from $12.5 billion in 2023, according to figures published by the center. The agency advises victims to file reports even when they are unsure whether a complaint meets a specific crime category because submissions may be shared with federal, state, local, or international law enforcement agencies.

    Onchain security groups have also increased their focus on attacks that use valid user actions to execute theft. In February, the Ethereum Foundation backed a Security Alliance engineer assigned to track and disrupt wallet drainers targeting Ethereum users.

    Security Alliance cited data placing drainer-related losses at $84 million in 2025, the lowest level on record. Its security network includes MetaMask, Phantom, WalletConnect, and Backpack, which share threat intelligence designed to identify phishing campaigns and other malicious infrastructure.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    John Smith

    Related Posts

    Bitcoin price breaks channel as RSI climbs to 63

    September 18, 2026

    Morpho adds USDC lending for five Coinbase tokenized stocks

    September 18, 2026

    CFTC submits crypto market framework for White House review

    September 18, 2026
    Leave A Reply Cancel Reply

    Demo
    Don't Miss
    Ethereum

    Announcing the Devcon SEA venue!

    By Michael JohnsonSeptember 18, 20260

    Hello, Devcon awaiters! We are thrilled to announce the venue where we’ll meet for Devcon…

    Fake AI trading bot tutorials steal 274.6 ETH from 224 victims

    September 18, 2026

    Sepolia Incident | Ethereum Foundation Blog

    September 18, 2026

    Bitcoin price breaks channel as RSI climbs to 63

    September 18, 2026

    LAI Crypto is a user-friendly platform that empowers individuals to navigate the world of cryptocurrency trading and investment with ease and confidence.

    Our Posts
    • Altcoins (23)
    • Bitcoin (11)
    • Blockchain (16)
    • Crypto (716)
    • Ethereum (454)

    Subscribe to Updates

    • Twitter
    • Instagram
    • YouTube
    • LinkedIn

    Type above and press Enter to search. Press Esc to cancel.