A crypto scam tactic is no longer relying on phishing links or suspicious wallet approval requests. This time, fraudsters are convincing victims to deploy malicious smart contracts onto the blockchain themselves.
A report by TRM Labs on September 14, 2026, revealed a scam operation capitalizing on the artificial intelligence trend. Through fake YouTube videos, the perpetrators promoted an AI-powered crypto arbitrage bot, impersonating Anthropic’s virtual assistant Claude. The scheme resulted in the loss of 274.6 ETH worth $517,000, drained across 234 contracts deployed by 224 distinct victims.
The median loss per incident stood at 1 ETH. This figure suggests the attackers targeted a broad audience with smaller amounts, rather than exploiting a handful of high-net-worth victims. Several victims even created multiple contracts before realizing their funds were gone. All proceeds from the hundreds of malicious contracts were ultimately routed to six collector addresses controlled by the scammers.
Not a Typical Phishing Attack
The new exploit scheme differs significantly from conventional hacking methods. The theft occurred because the victims themselves pressed the execution button at every on-chain step. TRM Labs identified nine identical YouTube tutorial videos uploaded under different creator identities. To bolster an impression of professionalism, the network used virtual presenters and AI-generated voiceovers.
Users who followed the video instructions were directed to a fake compiler website. The interface was crafted to mimic Remix, a popular programming tool widely used by Ethereum developers. This is where the fraud took place. While believing they were compiling code for a Claude AI arbitrage bot, targets were actually building and deploying scam smart contracts that would drain their initial deposits.
The transaction flow was intentionally designed to blur the line between an exploit and routine activity. Because the sequence of steps - from code compilation to wallet approval - was willingly initiated by the user, standard security warning systems were not triggered. There were no phishing link clicks, nor were there any third-party fund withdrawal authorization requests.
Bypassing Defenses Through the Illusion of Control
The absence of outside interference made the operational flow difficult for crypto wallet extensions to detect. Asset holders seeking quick profits with limited code literacy were vulnerable to a process that appeared safe. They believed their funds were protected simply because they remained in control of every line of instruction on the cloned Remix interface.
The loss of 274.6 ETH highlights an emerging angle in on-chain security risks. Threats do not always stem from underlying protocol vulnerabilities. By spoofing reputable AI entities and developer tool interfaces, attackers were able to guide victims into voluntarily depositing assets into trap wallets of their own creation.
Sourced from crypto.news.
Also read: Revolut Hacker Demands 6,000 Monero Ransom - 680 Victims Selected via On-Chain Analysis
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




