The promise looked familiar: build a crypto arbitrage bot with Claude, follow a few steps on YouTube, fund the smart contract and let the software do the work.
Instead, at least 224 crypto users lost more than $517,000 in Ethereum to a scam that used Anthropic’s Claude name as bait, according to blockchain intelligence firm TRM Labs.
The campaign relied on nine YouTube tutorials that presented what appeared to be legitimate guides for creating an AI-powered trading bot. The videos had accumulated more than 310,000 views by September, giving the scheme a sizable audience.
But there was no trading bot quietly generating arbitrage profits in the background. Victims were actually being guided through the deployment and funding of smart contracts built to move their crypto to addresses controlled by the scammers.
Between February and August, the operation collected 274.60 ETH across six addresses linked to its operators. At the time those transfers were made, the funds were worth about $517,205.
TRM identified 234 victim-deployed contracts connected to 224 wallets. The median loss was 1 ETH.
The Claude Trading Bot Was the Distraction
What makes the scheme particularly notable is how much of the process looked completely legitimate.
Unlike a conventional wallet drainer, the attack did not depend on a phishing page, a fake wallet connection or a malicious approval request. Users were authorizing the transactions themselves after being walked through the instructions in the videos.
The critical deception happened at the development stage.
TRM found fake compiler websites designed to resemble Remix, the Ethereum development tool. In at least one version of the scheme, the site ignored the source code users pasted into it and instead retrieved malicious code from a server controlled by the operators.
That code created a contract capable of transferring balances above 0.05 ETH when users clicked buttons such as “Start” or “Withdraw.”
In other words, the dangerous part of the tutorial was not hidden inside a suspicious wallet prompt. It was embedded in the code users were encouraged to deploy themselves.
Claude itself had nothing to do with the contracts. TRM found no Anthropic product or AI functionality in the deployed code. The company’s name was simply used to make the tutorials sound current, sophisticated and potentially profitable.
The tactic also appears to have borrowed from an earlier playbook. TRM said similar scams identified in 2025 used ChatGPT branding while relying on the same underlying method.
The videos added another layer of polish. The presenters and voices were AI-generated, while the scripts, fabricated testimonials and repeated profit claims were designed to reinforce the appearance of a genuine tutorial.
Once the funds were stolen, the operators moved them through decentralized infrastructure. TRM traced the money through DeFi services, cross-chain bridges and a mixer, and found no centralized exchange in the outbound flow.
The result was a scam built less around breaking through crypto security systems than persuading users to operate the system for the attackers.
For anyone watching a tutorial promising an easy-to-deploy Claude trading bot, that distinction matters. The code can look like the technical part of the opportunity while the real objective is hidden in what the user is being asked to execute.
