ChainCatcher reported that on-chain investigator Specter tracked an attack in which the perpetrators used YouTube videos to offer so-called arbitrage bot tutorials and code, then directed victims to compile and deploy contracts through a fake Remix-like development interface. According to ChainCatcher, the attackers registered ENS names containing "Uniswap" and disguised related addresses as legitimate DeFi revenue sources, making victims believe the deployed arbitrage bot was generating profits through Uniswap.
After victims deposited their own assets into the contracts, the funds were transferred away by the attackers. The attackers also appear to remain active and are still holding a significant portion of the stolen funds across two addresses.