The newest crypto drainer doesn’t need a fake MetaMask popup. It needs a YouTube tutorial, a Remix lookalike, and your willingness to “build with Claude.” TRM Labs detailed a coordinated campaign in which viewers were coached to deploy and fund smart contracts that contained no trading logic at all—only plumbing to forward ETH to the operators.
Between February and August 2026, TRM traced roughly 274.60 ETH (about $517,205 at transfer-time values) from 224 victims into six shared collection addresses. As of early September, nine near-identical videos were still online with more than 310,000 combined views.

You chose the scam—and signed every step
Conventional drainers rely on phishing links, spoofed domains, or malicious token approvals. This campaign mostly skips those tripwires. Victims pick the tutorial themselves, set up a wallet, paste “bot” code, deploy a contract they believe they own, and fund it with 1–2 ETH of “startup capital.” Wallet warnings built for hostile sites and suspicious approvals never fire, because the user is authorizing transactions from their own wallet to a contract they just created.
The median loss was about 1 ETH, matching the tutorials’ funding advice. TRM counted 234 victim-deployed contracts feeding the same operator cluster—strong evidence the “different creators” were one production line.

AI branding, zero AI in the contract
Claude is plastered across titles, scripts, and descriptions: build a fully autonomous crypto arbitrage bot from scratch, no experience required. That pitch works because AI coding assistants really do help people write and deploy software. TRM found no Anthropic product, no model calls, and no API keys in the deployed contracts or compiler sites. The Claude name is marketing bait. Earlier 2025 variants used ChatGPT branding with the same mechanics—operators simply refreshed the AI logo for 2026.
Videos lean on AI-generated presenters and voices to fake independent creators. Scripts and claimed profits match down to decimals (including a recycled “1 ETH every 20 hours” line). Comment sections include fabricated success stories. Description links point to written guides hosted on Telegraph, Amazon S3, and Google Cloud Storage that converge on the same finale: fund the bot and press Start.
The fake Remix is the kill switch
Most of the walkthrough is theater until the compiler step. Instead of a known, independently chosen IDE, tutorials send viewers to operator-controlled sites styled like Remix, hosted on S3, GCS, or standalone domains. In one variant TRM examined, a background script discarded the pasted source entirely and compiled a different contract fetched from the operator’s server. The clean decoy code never hit the chain.
What did hit the chain was a honeypot: accept deposits, and when the victim hits Start or Withdraw—exactly as coached—forward any balance above 0.05 ETH to the operator. After the theft, some sites showed a nonsense error about “gas nonce liquidity,” urging victims to add up to another 1 ETH and try again. That phrase is not an Ethereum concept. It’s a second-bite script.
Cash-out stayed on-chain
Stolen funds moved through DeFi swaps (including into Dai), cross-chain bridges, and at least one mixer path. TRM said it identified no centralized exchange in the outbound flow—another reason these campaigns are hard to interrupt mid-flight. The earliest drain in this cluster was February 12, 2026; the latest August 11.
How not to deploy your own drainer
TRM’s practical advice is boring and correct: only deploy through tools you independently choose and can verify. A professional tutorial, familiar AI brand, active comments, and readable source on screen do not prove the bytecode that lands on-chain matches what you pasted. If a “compiler” arrived via a video description, treat it as hostile until proven otherwise. And if a site says your arbitrage bot is stuck and needs more liquidity after Start, you are not debugging DeFi—you are being upsold.
Geeknewz take
This is AI crime as packaging, not as agent. The model never traded; the brand did the social engineering. As labs race agentic coding demos into the mainstream, expect more tutorials that cosplay as education while the real exploit is a silent bytecode swap. Wallets optimized for phishing approvals are fighting yesterday’s war. The new war is “I deployed it myself.”
Source: TRM Labs — Fake AI Trading Bots Are Getting Victims to Build Their Own Drainers (TRM Team, Sep 14, 2026; resurfaced in Sep 19 coverage).
