Fake YouTube tutorials promoting "AI-built crypto arbitrage bots" led to the theft of 274.60 ETH from 224 victims, according to a Sept. 14 analysis by blockchain intelligence firm TRM Labs.

The scam operated by convincing users to deploy their own smart contracts. These contracts, supposedly for arbitrage operations, were embedded with malicious code that executed token-draining functions.

TRM Labs identified nine nearly identical YouTube tutorials presented as the work of separate creators but exhibiting signs of common production. Victims interacted with these tutorials between Feb. 12 and Aug. 11, deploying a total of 234 malicious Ethereum contracts during this period.

The core mechanism involved swapping the contracts with ETH-stealing code at compile time, meaning users unknowingly deployed token drainers onto the blockchain. Once deployed and funded, these contracts automatically siphoned victims' Ethereum to six distinct operator addresses that accumulated the stolen 274.60 ETH.

Token drainers are malicious smart contracts designed to automatically transfer digital assets from a connected wallet. The scam exploited the gap between what users believed they were deploying and what actually executed on-chain.

The incident underscores how social engineering remains effective against DeFi users, particularly when combined with unverified smart contract code. Promises of automated yield strategies—especially those involving AI—often obscure the technical risks beneath.