Blockchain intelligence firm TRM Labs has documented a scam campaign that inverts the standard wallet-drainer model: instead of tricking victims into approving a malicious transaction, the attackers get victims to deploy and fund the malicious smart contract themselves — from their own wallet, with every step willingly authorized.

Between February and August 2026, TRM traced 274.60 ETH — approximately $517,205 — drained from 224 victims into six shared collection addresses, in what the firm's analysis points to as a likely coordinated operation.

The lure: build your own arbitrage bot

The campaign runs on YouTube. Tutorials promise to teach viewers how to build an AI-powered crypto arbitrage bot using Claude, then walk them through the process in real time: setting up a wallet, copying the provided code, deploying a smart contract, and funding it with cryptocurrency. The videos use AI-generated presenters and voices to create the appearance of separate, independent creators.

The contract the victim deploys contains no trading logic. It forwards any cryptocurrency sent to it on to the operators. The critical deception sits in a fake compiler: the bytecode actually deployed differs from the source code shown on screen, so the victim never sees the mechanism that will take their funds.

TRM identified nine nearly identical tutorials presented as the work of different creators. Scripts matched across channels, on-screen sequences followed the same order, and several videos displayed the same claimed profits down to the decimal — including a return of 1 ETH every 20 hours. Comment sections carried fabricated testimonials. As of September 2026, the nine videos remained online with a combined 310,474 views since the earliest was posted in April 2026; TRM also found earlier, since-removed versions of the same approach, indicating the activity predates the current set.

Why conventional defenses do not fire

Two properties make the campaign structurally resistant to standard protections. The victim deploys the malicious contract themselves, following instructions they actively sought out. And the process contains none of the signals wallet security tools look for: no phishing link, no spoofed domain, no suspicious approval signature. Phishing blocklists, wallet warnings and approval analysis are all aimed at hostile third parties — not at code the victim owns and funded from their own address.

The cash-out path compounds the problem. TRM found the stolen funds moving entirely through decentralized finance, cross-chain bridges and a mixer, with no centralized exchange anywhere in the route — leaving no compliance checkpoint where a withdrawal would be flagged or frozen.

The AI layer is not the vulnerability

TRM's wider findings frame the campaign: the firm's 2026 AI-in-Crime Adoption Index reports criminal adoption of AI rising 40% year over year, with scammers leading that adoption. But the mechanics here predate AI. The same scam has run for years with "flash loan arbitrage" tutorials and plain code dumps; AI-generated presenters simply lower the cost of manufacturing an unlimited roster of seemingly independent creators, and the Claude branding supplies the current credible lure.

The actual failure is the supply chain of trust in "build it yourself" finance: a tutorial that ends with the viewer pasting unknown bytecode into a mainnet deployment. The rule that has always protected developers — never deploy code you have not verified, regardless of who showed it to you — now needs to reach the audience least equipped to apply it.

TrustGrade tracks the security posture of protocols and the threat landscape around them. Verified registry scores and security scans arrive with TrustGrade Code Scoring in December 2026.