-
Scammers used fake YouTube tutorials to convince victims to build and fund their own crypto wallet drainers.
-
The tutorials swapped out the code victims saw with a hidden contract that sent funds straight to the scammers.
-
Over 274 ETH (around $517,000) was stolen from 224 wallets between February and August 2026.
A new crypto scam did not send victims a suspicious link. It did not ask them to approve a shady transaction either. Instead, scammers convinced 224 people to build the trap themselves, step by step.
Blockchain intelligence firm TRM Labs uncovered the scheme. According to their findings, fake YouTube tutorials promised to teach viewers how to build an AI-powered crypto trading bot using Anthropic’s Claude.
The videos led to the theft of 274.60 ETH from 224 wallets. At the time of the transfers, that amount was worth roughly $517,205. The campaign ran from February to August 2026. The typical victim lost about 1 ETH.
How the Scam Pulled People In
The operation used nine nearly identical YouTube tutorials. Each video appeared to come from a different creator. The videos featured AI-generated presenters and voices. They promised viewers a way to build an automated crypto trading bot. Some even suggested the bot could deliver highly unrealistic returns.
Viewers were told to follow a simple set of steps. They had to set up a crypto wallet. Then they copied the code shown in the tutorial. After that, they deployed a smart contract and funded it with their own cryptocurrency. At every stage, it looked like the user was in full control and doing everything voluntarily.
TRM Labs identified 234 smart contracts that victims deployed. The stolen funds eventually flowed into just six addresses. Those addresses were controlled by the people running the scam. The scheme did not use a typical phishing website. It did not ask for a token approval or a suspicious wallet signature. That helped it stay under the radar of many common security tools.
The Code Swap Victims Never Saw Coming
The real trick happened inside the compiler tool the tutorials recommended. TRM Labs found that some tutorials sent users to compiler websites the scammers controlled. Attackers built several of those sites to look like real development tools. Some even copied the look of Remix, a widely used and trusted coding platform.
In one version TRM analyzed, a hidden background script ran without the victim knowing. When a user pasted their code into the compiler, the script quietly threw it away. It then pulled a completely different contract from the scammers’ own server. The attacker never deployed the clean code the victim saw on screen to the Ethereum blockchain.
The replacement contract had no real trading or AI features at all. It simply accepted deposits. When a user clicked buttons like “Start” or “Withdraw,” the contract transferred any balance above 0.05 ETH directly to the scam operators. The victim thought they were launching a bot. They were actually handing over their funds.
The scam also tried to squeeze more money from victims after the first theft. TRM Labs found one compiler site that showed a fake error message. The message claimed the bot needed something called “gas nonce liquidity” to keep running.
Victims were told to add another 50% of their original deposit, up to 1 ETH, to fix the problem. According to TRM Labs, “gas nonce liquidity” is not a real Ethereum concept. The firm described the message as a trick to push victims into making a second transfer.
After collecting the funds, the operators moved the money through decentralized finance platforms, cross-chain bridges, and a mixer. Similar crypto attacks have also exploited weaknesses in trading systems, such as the $23.75 million theft from Ostium through an off-chain price system. TRM Labs found no centralized exchange in the outbound money trail. That made tracking and recovering the funds much harder.
The Warning Signs Were Hidden by Design
The nine fake tutorial videos had gathered more than 310,000 views as of September 2026, according to TRM Labs.
The scale of the campaign points to a growing problem for crypto users. A scam does not always announce itself. A professional-looking video, a familiar AI brand name, or readable source code does not prove that everything is safe. In this case, the code shown on screen did not match the code being deployed. Victims had no way to know that just by watching.
TRM Labs recommends that users independently verify any development tool before deploying or funding a smart contract. Following video instructions alone is not enough to confirm that the software, compiler, or contract is what it claims to be.
As different media houses reported, this campaign shows how scammers are evolving. They no longer need to hack into wallets. They just need victims to do it for them.