TRM Labs said fake YouTube tutorials lured victims into deploying and funding malicious smart contracts, resulting in the theft of 274.6 ETH from 224 victims. According to ChainCatcher, the stolen ETH was worth about $517,000 at the time of transfer, and the median loss per victim was 1 ETH.
The report, published on September 14, said the scheme did not rely on phishing links, fake domains, or malicious approval prompts. Instead, victims chose the tutorials, copied code, deployed contracts, and funded them from their own wallets, which prevented standard wallet security warnings and phishing blacklists from triggering.
TRM identified 234 contracts deployed by victims and said the funds ultimately flowed to six receiving addresses controlled by the operators. It also found nine nearly identical YouTube tutorials posted under different creators, using AI-generated virtual hosts and voiceovers to promote a supposed fully automated crypto trading bot built with Claude.
In one variant analyzed by TRM, a backend script discarded the source code pasted by victims and fetched a different contract from the operator's server, while the clean code shown on screen never reached the blockchain. The substituted contract accepted deposits and transferred balances above 0.05 ETH to the operator when victims pressed Start or Withdraw, without containing any arbitrage logic or AI functionality.