Meet the Top 101 in Crypto
News
5 min read

Fake AI Crypto Bot Tutorials Steal $517,000 in ETH From YouTube Users

Published 21 September 2026
Giuseppe Ciccomascolo
Authors

Key Takeaways

  • Fake YouTube tutorials tricked 224 users into deploying and funding malicious smart contracts disguised as AI-powered crypto trading bots.
  • The campaign stole 274.6 ETH, worth about $517,000, by replacing the code shown to victims with wallet-draining contracts.
  • Conventional phishing alerts and wallet-security warnings failed to detect the scam.

Scammers used fake YouTube tutorials about AI-powered crypto trading bots to trick hundreds of users into building and funding their own wallet drainers, according to blockchain intelligence firm TRM Labs.

The campaign stole 274.6 Ether, worth approximately $517,000 at the time of transfer, from at least 224 wallets between February and August 2026. The median victim lost 1 ETH, while the stolen funds ultimately flowed through six addresses believed to be controlled by the operators.

Unlike traditional crypto scams, the scheme did not rely on unsolicited phishing links or suspicious token approvals. Victims found the tutorials, copied the supplied code, deployed smart contracts, and authorized every transaction themselves.

The supposed trading bots contained no artificial intelligence or arbitrage functionality. Instead, they were designed to transfer deposited ETH directly to the scammers.

New Trending Crypto Wallet Offers
Sponsored
Disclosure
Opened in 2018
Promotions
Trusted, Secure & Crypto Friendly
Coins
Bitcoin Ethereum Tether Wrapped BNB USD Coin +87
Opened in 2017
Promotions
Receive Up to $10 in BTC when you buy and activate a Tangem Wallet.
Coins
Bitcoin Ethereum Tether Wrapped BNB Solana +68

Fake Tutorials Promised Automated Crypto Profits

TRM Labs identified nine nearly identical YouTube tutorials presented as content from separate creators. The videos promised to show viewers how to create fully automated crypto arbitrage bots using Anthropic’s Claude AI assistant.

The tutorials featured AI-generated presenters and voiceovers, alongside detailed screen recordings that walked viewers through setting up a wallet, copying source code, deploying a contract, and supplying it with trading capital.

Several videos used virtually identical scripts and displayed the same purported profits, including claims that users could earn 1 ETH every 20 hours. Fabricated comments and testimonials reinforced the impression that the bots worked.

The nine videos had accumulated more than 310,000 views since the earliest appeared in April. TRM also found older versions of the scam that had already been removed from YouTube.

Claude did not play any role in the deployed contracts. TRM found no model queries, API keys, or other AI functionality. The scammers were simply exploiting growing interest in AI coding tools to make an unrealistic trading system appear accessible to inexperienced users.

Similar campaigns detected in 2025 used ChatGPT’s name instead, suggesting operators can change the AI branding without substantially altering the scam.

Fake Compiler Secretly Replaced the Code

Most steps demonstrated in the tutorials appeared legitimate. The crucial compromise occurred when viewers were instructed to use a compiler website selected by the video’s creator.

Some of these websites imitated Remix, a widely used development environment for Ethereum smart contracts. Although the sites displayed apparently harmless source code, they did not necessarily compile the user-pasted code.

In one version analyzed by TRM, a background script discarded the visible source code and downloaded a different contract from a server controlled by the scammers. The clean code shown on the screen never reached the blockchain.

Instead, victims deployed a malicious contract that accepted deposits but contained no trading logic, decentralized exchange integrations, or arbitrage functions. When a victim pressed “Start” or “Withdraw,” any balance above 0.05 ETH was transferred to the operators.

This substitution made the transaction appear legitimate because the victim deployed the contract from their own wallet.

Some victims were then targeted a second time. After their funds disappeared, the fake compiler displayed an error claiming the arbitrage bot needed an additional 50% deposit to resolve a “gas nonce liquidity” problem.

TRM said gas nonce liquidity is not an Ethereum concept. The message existed solely to persuade victims to send more ETH.

Scam Bypassed Conventional Wallet Warnings

The attack was particularly effective because it avoided many signals used by crypto-security products.

Victims did not connect their wallets to an obvious phishing page or approve an unknown third party to spend their tokens. They funded contracts they had deployed and signed transactions they believed were required to operate the bot.

Consequently, phishing blocklists, wallet alerts, and approval-analysis tools had little suspicious activity to detect. The malicious component appeared at the compiler level, where one set of code was displayed, and different bytecode was deployed.

TRM traced 234 victim-deployed contracts to 224 funding wallets. The earliest identified theft occurred on Feb. 12, while the latest took place on Aug. 11.

The operators subsequently moved the funds entirely through decentralized infrastructure.

Some ETH was exchanged for DAI via decentralized finance protocols and swap services, while other assets were moved across blockchain bridges. At least one route passed through a crypto mixer, and TRM found no centralized exchange in the outbound flow.

How Users Can Avoid Malicious Trading Bots

TRM advised users to treat the development environment as a critical security decision and avoid compilers supplied through tutorials, comments or unofficial guides.

Developers should use independently verified tools and confirm that deployed bytecode corresponds to the source code they inspected.

A professional presenter, a recognizable AI brand, or an active comment section does not prove that a tutorial is legitimate.

The campaign demonstrates how scammers can turn users’ willingness to follow instructions into an attack vector.

Rather than stealing wallet credentials, the operators persuaded victims to construct, fund, and activate the theft mechanism themselves.

Disclaimer: The information provided in this article is for informational purposes only. It is not intended to be, nor should it be construed as, financial advice. We do not make any warranties regarding the completeness, reliability, or accuracy of this information. All investments involve risk, and past performance does not guarantee future results. We recommend consulting a financial advisor before making any investment decisions.
Giuseppe Ciccomascolo

Giuseppe Ciccomascolo began his career as an investigative journalist in Italy, where he contributed to both local and national newspapers, focusing on various financial sectors.

Upon relocating to London, he worked as an analyst for Fitch's CapitalStructure and later as a Senior Reporter for Alliance News. In 2017, Giuseppe transitioned to covering cryptocurrency-related news, producing documentaries and articles on Bitcoin and other emerging digital currencies. He also played a pivotal role in establishing the academy for a cryptocurrency exchange website. Crypto remained his primary area of interest throughout his tenure as a writer for ThirdFloor.

Related

Survey Icon
Help us improve
1 of 4
Is this your first time here?
What brought you here today?
What are you most interested in?
Would you be interested in:
Thank you icon
Thank you for your feedback!
DMCA.com Protection Status