Fake Claude Trading Bot Tutorials Stole 274.6 ETH From 224 Victims — How the Scam Worked

TRM Labs traced a YouTube campaign that tricked users into deploying malicious Ethereum contracts disguised as AI arbitrage bots. Here's the playbook—and how to avoid it.

3 min read

A September TRM Labs report, widely covered on September 19, describes a scam that stole 274.6 ETH—roughly $517,000 at transfer-time prices—from 224 victims using fake "AI trading bot" tutorials on YouTube. The twist: Anthropic's Claude was marketing bait, not the engine behind the theft.

The scam architecture

Nine nearly identical YouTube videos, often featuring AI-generated hosts and voiceovers, promised viewers they could build a fully automated crypto arbitrage bot using Claude. Each video directed users to an online compiler controlled by scammers.

Victims believed they were deploying legitimate trading logic. In reality, a malicious backend substituted contracts designed to drain ETH. Users funded the contracts themselves through transactions they initiated—no traditional phishing link required.

TRM traced 234 malicious contracts across 224 unique victims; some deployed multiple contracts. Stolen funds consolidated across six collection addresses. The median loss was about 1 ETH per incident, indicating broad small-victim harvesting rather than a single whale hit.

Why AI branding works for fraud

The campaign exploited two trends simultaneously: appetite for passive crypto income and hype around AI coding assistants. Claude's name lent credibility to tutorials that never invoked Claude's API onchain.

TRM emphasized that no AI model interacted with deployed contracts. The AI label was pure social engineering—similar to past "ChatGPT bot" scams, updated for 2026's model roster.

Red flags developers and traders should know

Compilers you do not control. Never deploy production funds through a third-party IDE linked from a video.

Opaque bytecode. Verify contract source on Etherscan before funding.

Promises of risk-free arbitrage. MEV competition and fees make "set and forget" retail arbitrage rare.

AI-generated presenters. Synthetic media is now a scam signal, not a novelty.

Unverified "official" partnerships. Claude, OpenAI, and others do not sponsor random YouTube bot tutorials.

Broader context: AI agents plus crypto

The same week, Bankr enabled Meta Muse agents to operate wallets legitimately. The contrast is stark: real agent-wallet integrations come with disclosures, plugins, and platform oversight; scams mimic that narrative without any of the safeguards.

Regulators are moving on structural crypto rules—the SEC's Innovation Exemption for tokenized stocks, CFTC rulemaking sent to the White House—but consumer fraud often outpaces formal policy.

Protect yourself and your community

Use hardware wallets for significant holdings. Treat tutorial-deployed contracts as untrusted until audited. Educate less technical community members that "AI bot" videos are a top fraud category in 2026.

For Cubed readers, this story is a reminder that crypto's threat model now includes AI-themed social engineering—not just bridge exploits and protocol bugs. The technology changes; the goal of separating you from your keys does not.

More in cryptocurrency

Cubed

Write about the technologies shaping the future.

For developers, founders, and curious minds exploring AI, crypto, Web3, and emerging tech—signal over noise.

One free account across In Plain English, Stackademic, Venture, and Cubed.

How it works
  • AI, crypto & Web3
  • Software & emerging technologies
  • Analysis & practical resources
  • Thoughtful voices, not hype
1

Sign in

Google or GitHub

2

Complete profile

Takes a few minutes

3

Get approved & publish

Start sharing

Why write for Cubed?

The future deserves thoughtful voices, not just louder headlines.

Comments

Loading comments…

Posts Across the Network