224 Victims Lost 274.6 ETH to Fake AI Bot Tutorials on YouTube
A coordinated scam operation running from February through August 2026 tricked 224 victims into deploying their own drainer contracts after following fake AI bot tutorial videos on YouTube, resulting in the loss of 274.6 ETH. TRM Labs traced the stolen funds to six operator addresses.
224 Victims Lost 274.6 ETH to Fake AI Bot Tutorials on YouTube
A six-month scam operation tricked crypto users into draining their own wallets, according to a TRM Labs investigation. The campaign ran from February through August 2026, targeting 224 victims who collectively lost 274.6 ETH through fraudulent AI bot tutorial videos hosted on YouTube.
The mechanics were unusually calculated. Rather than compromising wallets directly, the scammers published videos posing as guides for deploying AI-powered trading bots. Viewers who followed the instructions ended up signing malicious smart contracts and, critically, funding and deploying drainer contracts themselves. The victims did the operational work. Six operator addresses identified by TRM Labs simply collected what came out the other end.
This architecture matters. By making victims the deployers, the scammers created plausible deniability and shifted the on-chain footprint away from a single point of failure. There was no phishing site to take down, no single malicious contract address to blacklist. Each victim's deployment was technically distinct, making pattern detection harder and complicating any platform-level intervention.
"TRM traced 274.60 ETH to six operator addresses after victims signed and funded malicious contracts themselves between February and August."
TRM Labs, via investigation
The AI angle is the newest layer on a well-worn attack surface. YouTube cryptocurrency scams date to at least 2017, when fake livestreams impersonating Vitalik Buterin and other figures became a platform staple. What has changed is the content wrapper. AI bot tutorials carry an aura of technical legitimacy that celebrity giveaway streams no longer do. A user who would dismiss a "Elon Musk sends 2x ETH" livestream might genuinely believe they are watching a developer walk through a working arbitrage script. The perceived complexity of the content is itself the social engineering.
Drainer contracts have proliferated sharply across 2024 and 2026, typically targeting decentralized finance users through wallet approval exploits. Most drainer campaigns rely on users clicking a link and approving a transaction they do not fully understand. This campaign went further: victims were coached through a multi-step process that felt like education. That distinction has real implications for how the industry thinks about user protection. A user who believes they are learning something is far less likely to pause and verify what they are actually signing.
"The rise of AI-driven scams highlights the urgent need for enhanced user education and robust security measures in the crypto space."
TRM Labs, via report
Every step of this attack required a victim to take action: watch a video, copy code, fund a contract, sign a transaction. Basic due diligence, specifically reading what a smart contract does before executing it, would have stopped the scam cold. Wallet simulation tools like Tenderly and transaction preview features in wallets such as Rabby now flag suspicious approval patterns before a user confirms. That those tools exist and 224 people still lost ETH points to an education gap that neither YouTube's content moderation nor the crypto industry's scattered security messaging has closed.
YouTube's responsibility here is also worth scrutiny. The platform has been aware of cryptocurrency scam content as a systemic problem for years and has introduced verification labels and content policies in response. That a coordinated campaign running for six consecutive months across multiple videos avoided enforcement long enough to claim 224 victims suggests those systems remain inadequate for technically sophisticated scam content that does not rely on the usual signals, fake celebrity faces, giveaway language, or livestream formats that moderation tools are tuned to catch.
The 274.6 ETH total represents a significant financial loss to victims. The method is the more significant data point. As AI-themed content becomes a normalized part of the developer education landscape, scammers have a growing library of legitimate-looking formats to imitate. The attack surface is expanding precisely because the content it mimics is genuinely useful and widely consumed. That combination, plausible format, technical framing, self-directed victim action, is likely to attract more operators before it attracts adequate countermeasures.




