AI Crypto Arbitrage Bot Scam: Fake Claude Tutorials That Drain ETH Wallets

A video promises to show you how to build a crypto arbitrage bot with Claude. The instructions look approachable, even if you have never written a contract.

Before funding anything, pay attention to the tool the tutorial asks you to use. That one choice can change what actually reaches the blockchain.

Illustrative video page promoting a Claude AI crypto arbitrage bot tutorial

Overview

The promise is a self-built trading machine

In September 2026, TRM Labs described YouTube tutorials presenting an AI-powered arbitrage bot that viewers could supposedly build with Claude.

The videos guided people through a wallet setup, source code, contract deployment, and funding. That sequence resembled an educational coding lesson.

But the contract deployed through the operators’ compiler had no genuine trading logic. It was designed to forward deposited cryptocurrency to the operators.

Claude was the marketing hook, not a component of the deployed contracts. TRM found no Anthropic product or AI functionality in the scam’s contract or compiler.

The reported harm was measurable

TRM traced one coordinated cluster of nine similar videos to 224 victim wallets and 274.60 ETH taken between February and August 2026.

The research valued that ETH at approximately $517,205 at the time of the transfers. Those figures describe the analyzed cluster, not every fake bot tutorial online.

The same study found 234 deployed and funded contracts and six collection addresses associated with that cluster.

Several videos looked like separate creators, but their scripts, figures, and linked guides were strikingly similar.

Why this is different from a standard wallet phishing page

The victim did not need to connect a wallet to a spoofed exchange or approve a hostile token allowance.

Instead, they deployed a contract and funded it themselves. The deceptive step was the compiler that substituted different bytecode for the displayed source.

  • The tutorial claimed an AI trading strategy that the deployed contract did not contain.
  • Viewers were sent to an operator-controlled compiler.
  • The code shown on screen was not the code that reached the blockchain.
  • Funding the contract exposed the deposit to its hidden transfer logic.
  • A later error message could demand yet more cryptocurrency.

That sequence makes the AI crypto arbitrage bot scam especially deceptive for people who expect their wallet to warn them about a malicious approval.

Why the Tutorial Format Builds Trust

A long video feels different from an anonymous ad. It appears to teach, demonstrate, and let the viewer repeat each action.

The presenter may look like a real coding instructor. TRM found AI-generated presenters and voices in some of the reviewed videos.

Other versions paired an AI voice with screen recordings. The scripts and claimed profit figures were similar despite different channels.

That repetition matters because it can create an illusion of independent success. Several creators appearing to prove the same result may actually share one production process.

Comments claiming the bot worked can deepen the impression. TRM identified fabricated testimonials in the comment sections.

The guide links also appeared in different places, including Telegraph, Amazon S3, and Google Cloud Storage. Different hosting did not make the instructions independent.

According to the research, those guides converged on the same endpoint: deploy the bot, provide liquidity, and press Start.

None of this means every AI-assisted trading tutorial is fraudulent. The concern is the verified chain of substitution and fund diversion in this campaign.

How the AI Crypto Arbitrage Bot Scam Works

Step 1: A video makes automated profit sound buildable

The title combines Claude, crypto arbitrage, and a beginner-friendly promise. It suggests the difficult part of trading can be delegated to an AI tool.

Real arbitrage is complex and competitive. It depends on execution costs, liquidity, timing, and market conditions, none of which disappear because a tutorial says “AI.”

In the researched cluster, videos presented polished walkthroughs and similar profit claims. Viewers could mistake production quality for evidence of working software.

Pause before treating a demonstrated balance or comment as independent proof. Both can be selected or fabricated by the uploader.

Step 2: The written guide moves the viewer to a chosen tool

Video descriptions linked to written instructions. Those guides differed visually, but TRM observed near-identical order and final funding instructions.

This is the crucial handoff. A guide can choose the website where you compile, deploy, and fund the supposed bot.

The site may look like a familiar development environment. Appearance cannot establish that it handles the code you pasted honestly.

Do not treat a cloud-hosted guide as automatically safer. A legitimate hosting provider can carry content placed there by an attacker.

Step 3: A fake compiler swaps the contract

TRM found operator-controlled compiler sites styled to resemble Remix, a genuine smart-contract development environment.

In one analyzed variant, the site discarded the source code the viewer pasted and compiled different code obtained from the operator’s server.

The clean source shown to the victim was a decoy. It never became the on-chain bytecode they thought they were deploying.

This is a supply-chain deception at the tool boundary. The victim can read apparently harmless code and still deploy something different.

Step 4: The victim deploys and funds the contract

The wallet signs ordinary deployment and funding transactions initiated by its owner. That is why a standard phishing-warning pattern may not appear.

The operator-controlled contract accepts the funds, but it does not execute arbitrage trades. Its logic routes value toward the criminal collection addresses.

TRM reported that the studied variant forwarded balances above a threshold when the user pressed Start or Withdraw.

The image below illustrates the funding stage in a fictional guide. It does not show the actual malicious compiler or executable code.

Illustrative fake AI arbitrage bot guide directing a user to deploy and fund a contract

Do not copy a contract from this or any unverified tutorial into a wallet workflow. An on-chain action is difficult to reverse.

Step 5: The apparent bot diverts the deposit

The operator receives funds through the contract’s hidden behavior. From the victim’s perspective, the bot may simply seem to fail or show a confusing result.

TRM followed the money through decentralized swaps, bridges, and a mixer in the analyzed cluster. It found no centralized exchange in the outbound path.

That tracing supports the conclusion that the tutorial did not merely teach a bad strategy. The deposited funds were redirected.

The research gives aggregate results. It does not mean every viewer of one video deposited cryptocurrency or lost the same amount.

Step 6: A fake error asks for a second deposit

One operator-controlled compiler displayed an error claiming the bot needed additional liquidity after the funds had already gone.

The message used technical-sounding words about gas and nonce, but TRM said the supposed condition was not a real Ethereum concept.

That false explanation turned a loss into a new sales pitch: add more cryptocurrency and try again.

If a bot needs money to “unlock” money already sent, stop. Do not fund another transaction to test the claim.

What Claude and the Wallet Actually Did

Claude is a real AI service. The researchers did not find it performing the alleged trading inside this campaign’s contracts.

The wallet is also real. It signed transactions that its owner approved, which is why ordinary account-security checks might show no unauthorized login.

The deception sat between the code the viewer believed they were deploying and the bytecode supplied by the chosen compiler.

That separation is hard for a beginner to spot. A readable source window is comforting, but it does not prove the deployed contract matches it.

Developers can verify bytecode and use trusted, independently selected tools. If those steps are unfamiliar, do not deploy a contract involving real funds.

A professional-looking video or large view count cannot substitute for an independent technical review of what the contract actually does.

How to Check a Crypto Bot Tutorial Before You Risk Funds

Ask whether the creator gives a verifiable contract source, an independently reproducible build, and a clear explanation of how trades would happen.

Be wary when the tutorial insists on one obscure compiler link rather than allowing a trusted development environment chosen by you.

Look for the actual trading components in the deployed contract, not just the pasted text in a browser window.

Do not assume a well-known AI brand in the title has endorsed the project. In this case, the name was a lure.

Never treat comments, profit screenshots, or repeated near-identical videos as independent audit evidence.

If a guide says you must deposit substantial ETH before you can see whether a strategy works, the claimed demonstration is not a safe test.

Why a Clean-Looking Source File Is Not Enough

Readers who know some programming may inspect the pasted source and feel reassured when they find no obvious transfer to an attacker.

That inspection is useful only if the tool deploys the same source. TRM’s analyzed compiler did not.

The site showed one thing in the editor and sent a different compiled contract to the blockchain. The mismatch happened after the source was pasted.

A victim could therefore make a careful decision about the visible text and still authorize a transaction based on the wrong premise.

Independent compilation and bytecode verification address that gap. They require technical skill and a development environment you selected yourself.

If a tutorial forbids or discourages such checks, there is no safe reason to use it with real funds.

What the On-Chain Numbers Do and Do Not Prove

TRM traced a specific set of funded contracts and recipient addresses. That is stronger evidence than counting angry comments under a video.

The traced transactions support a documented loss within the analyzed campaign. They do not establish the identities of every person behind it.

Likewise, the reported 224 wallets are not a count of every viewer deceived. Many people may have watched without sending funds.

Some videos may have been removed or replaced since the analysis. A new title or channel can reuse the same kind of fake compiler.

Focus on the behavior rather than a single video URL: an unverifiable tool receives the source, then asks you to deploy and fund a contract.

The name of the AI assistant can change too. TRM observed older versions using ChatGPT language before Claude became the hook.

No brand name in a video title can certify an on-chain contract. The independently verified deployment is the part that matters.

If you cannot establish what bytecode a contract contains, do not use a live wallet as the testing environment.

What to Do if You Have Fallen Victim to This Scam

  1. Stop funding the contract. Do not follow a “gas liquidity” or reset instruction. In the analyzed case, that message was designed to produce another deposit.
  2. Preserve transaction details. Save the contract address, transaction hashes, tutorial URL, guide link, timestamps, and any messages from the operator.
  3. Secure the wallet according to your actual exposure. If you entered a recovery phrase anywhere, move remaining assets to a fresh wallet created safely. If you did not, avoid assuming the seed was stolen.
  4. Review connected sites and approvals. This campaign did not rely on malicious approvals, but a separate site in your path could. Revoke permissions you do not recognize.
  5. Report the video and site. Use the platform’s abuse tools and the relevant cybercrime authority. Share the addresses and hashes without posting your seed phrase.
  6. Check for downloads. The described campaign centered on a malicious compiler, not necessarily installed malware. If you downloaded software, scan with Malwarebytes and remove unknown extensions.
  7. Beware recovery impostors. A stranger promising to reverse an on-chain transfer for an upfront fee may be another scammer.

An ad blocker such as AdGuard may help with malicious advertisements, but it would not detect an operator-controlled compiler reached through a voluntarily chosen tutorial.

Some on-chain losses cannot be reversed. Reporting still matters because it preserves evidence and may help investigators connect related addresses.

Frequently Asked Questions

Is Claude itself involved in this crypto bot scam?

TRM found no Anthropic product or AI functionality in the examined contracts or compiler. Claude’s name was used to market the fraudulent tutorial.

Why did the wallet not warn before the funds moved?

The victim deployed and funded a contract they controlled. The trap was substituted bytecode, not the usual spoofed wallet connection or hostile approval.

Were the videos from one creator?

They appeared across separate channels. Similar scripts, figures, and guides led TRM to assess them as a likely coordinated cluster.

Did the code displayed on screen contain the theft logic?

In the analyzed compiler variant, no. The displayed source was a clean decoy, while different code was compiled and deployed.

Can adding more ETH fix the bot after an error?

Do not do it. TRM identified one technical-sounding error as a fabricated pretext for another deposit after funds were already diverted.

How much did the documented cluster take?

TRM traced 274.60 ETH from 224 victim wallets, valued at about $517,205 at the time of those transfers. That is a cluster total, not a universal estimate.

The Bottom Line

This AI crypto arbitrage bot scam hid behind an educational video and a fake compiler. The wallet performed genuine actions, but the deployed contract was not the promised bot.

Do not fund a contract from an unfamiliar tutorial tool. Verify the development environment and deployed code independently, or walk away.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Child Modeling Fee Scam: The Fake Events That Cost One Family $4.6 Million

Next

Invoice Email With a Real Unsubscribe Link: The Fake Payment Scam Exposed