A surge in AI-enabled crypto cybercrime is targeting investors through sophisticated scams and on-chain malware. According to TRM Labs, a fake YouTube tutorial campaign promoting Claude-branded arbitrage bots has drained over $517,000 in Ethereum from 224 victims using fake Remix compiler websites. Meanwhile, Chainalysis reports a 440% surge in on-chain malware instructions, driven by unrestricted open-source AI models. The stolen funds are laundered entirely through decentralized infrastructure.
Fake AI bot tutorial scam
- ▪The fake AI bot tutorial scam campaign collected 274.60 ETH, worth approximately $517,205 at the time of transfer, across six operator-controlled addresses between February and August 2026.
- ▪The fake AI bot tutorial videos, which accumulated over 310,000 views as of September 2026, used AI-generated presenters, fabricated testimonials, and repeated profit claims to appear legitimate.
- ▪Fake YouTube tutorials promising to help users build crypto arbitrage bots using Anthropic's Claude drained over $517,000 in Ethereum from at least 224 victims, according to TRM Labs.
- ▪Anthropic's Claude was not involved in the malicious contracts deployed in a fake YouTube tutorial campaign promoting Claude-branded arbitrage bots that drained over $517,000 in Ethereum from 224 victims, and the Claude name was used solely to market that scheme, according to TRM Labs
Malicious smart contract deployment method
- ▪The fake AI bot tutorial scam directed victims to deploy smart contracts that transferred balances above 0.05 ETH to operators when users pressed 'Start' or 'Withdraw' buttons.
- ▪The fake AI bot tutorial scam differed from conventional wallet drainers because victims authorized every transaction themselves, bypassing security systems that detect phishing websites or spoofed wallet connections.
- ▪A fake YouTube tutorial campaign promoting Claude-branded arbitrage bots manipulated users through fake compiler websites resembling the Ethereum development tool Remix, which discarded the user's pasted code and deployed malicious code from the operator's server
AI-enabled blockchain malware surge
- ▪Instances of malware instructions written into on-chain transactions and smart contracts increased by 440% in less than a year, averaging 11 cases per day, according to a September 2026 Chainalysis report.
- ▪Chainalysis reported that on-chain malware cases averaged two per day prior to the mid-2025 release of powerful Chinese open-source AI models with no restrictions on generating malicious code, according to a report published on September 17, 2026
Stolen funds laundering through DeFi
- ▪TRM Labs found that the stolen funds from the fake AI bot tutorial scam were moved entirely through decentralized infrastructure, including DeFi services, cross-chain bridges, and a mixer.
- ▪TRM Labs identified no centralized exchanges in the outbound flow of the stolen funds from the fake AI bot tutorial scam.
Debatable claims
- ▪Governments should restrict open-source AI to prevent malicious code generation
- ▪DeFi protocols should face the same AML regulations as centralized exchanges
- ▪Video platforms should be legally liable for hosting fraudulent crypto tutorials
Story comments
Loading comments…