Skip to main content
AVOID.NET

Audit log

Every state-changing event for "Claude AI" Crypto Arbitrage Bot YouTube Tutorial Scam: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-09-18 17:15:20Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 448,148,082
    sig
    3kZGRKsR5D8N…jt9Hkwkzexplorer ↗
    hash
    233zNyuewjER…kMZJtRsNsha256 → base58
    verifying row…full verify ↗
    canonical bytes (15235 B) ▸
    {"actor":"system:backfill","investigation_id":"dc3300f8-2b2d-4155-b379-79248c2538f8","kind":"publish","page_slug":"claude-ai-crypto-arbitrage-bot-youtube-tutorial-scam","published_at":"2026-09-18T17:15:19.964Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"\"Claude AI\" Crypto Arbitrage Bot YouTube Tutorial Scam","sections":[{"content":"Nine near-identical YouTube tutorials, attributed to nominally separate creators, instruct viewers to deploy what is described as an AI-powered crypto arbitrage bot \"built with Claude.\" According to TRM Labs' September 2026 investigation, Anthropic's Claude AI plays no actual role in any component of the scheme; the Claude branding is used purely as a trust signal to lend legitimacy to the tutorials. The smart contracts victims are instructed to deploy contain no arbitrage logic, no DEX router calls, and no connection to any AI system. Upon deployment and funding, the contracts route all deposited funds directly to operator-controlled collection addresses. TRM Labs identified six such collection addresses receiving stolen funds from 234 contracts deployed by 224 victims between February 12 and August 11, 2026. The total amount drained during this period was 274.60 ETH, valued at approximately $517,205 USD, with a median victim loss of 1 ETH.","heading":"Overview and Nature of the Scam","severity":"critical","sources":[{"credibility":2,"name":"Fake AI Trading Bots Are Getting Victims to Build Their Own Drainers — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/fake-ai-trading-bots-are-getting-victims-to-build-their-own-drainers"},{"credibility":2,"name":"Smart Contract Scams: Ethereum Drainers Pose as Trading Bots to Steal Crypto — SentinelOne","type":"research","url":"https://www.sentinelone.com/labs/smart-contract-scams-ethereum-drainers-pose-as-trading-bots-to-steal-crypto/"}]},{"content":"The attack flow is as follows: a viewer finds one of the tutorial videos, follows the on-screen instructions to a fake code compiler styled to resemble the legitimate Remix IDE, copies and deploys the displayed Solidity contract, funds it with ETH (tutorials typically instruct 1-2 ETH as startup capital), and calls a function labelled \"Start()\" or similar. Unknown to the victim, the compiler substitutes malicious bytecode for the legitimate-looking source code displayed on screen, resulting in a honeypot contract. The deployed contract contains no trading logic; its sole function is to forward any received ETH to a hardcoded attacker-controlled address. SentinelOne documented several obfuscation techniques used to conceal the destination address within the contract code, including XOR operations on 32-byte constants, string concatenation of address fragments, and decimal-to-hex conversion via uint160 casting. Stolen funds were subsequently moved through DeFi protocols, cross-chain bridges, and mixing services to avoid centralized exchange tracing, according to TRM Labs. As of TRM's reporting date, the most active single collection address identified by SentinelOne — 0x872528989c4D20349D0dB3Ca06751d83DC86D831 — had received approximately 244.9 ETH ($902,000 USD). Two additional attacker addresses identified by SentinelOne were 0x2eEE3A0ed51AE22813050212E8D9Fa216bd51df4 and 0x7359EA6AA3343b3238171e76F97e6aA3cDB8d696.","heading":"Attack Mechanism and Technical Details","severity":"critical","sources":[{"credibility":2,"name":"Fake AI Trading Bots Are Getting Victims to Build Their Own Drainers — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/fake-ai-trading-bots-are-getting-victims-to-build-their-own-drainers"},{"credibility":2,"name":"Smart Contract Scams: Ethereum Drainers Pose as Trading Bots to Steal Crypto — SentinelOne","type":"research","url":"https://www.sentinelone.com/labs/smart-contract-scams-ethereum-drainers-pose-as-trading-bots-to-steal-crypto/"}]},{"content":"A defining characteristic of this scam, noted by both TRM Labs and SentinelOne, is that victims deploy and fund the malicious contract themselves by following instructions they actively sought out. Because no phishing link, spoofed domain, or unsolicited approval prompt is ever presented to the victim, standard wallet-security warnings — MetaMask transaction simulations, browser anti-phishing filters, and approval-revoke tools — do not trigger. The victim authorizes all transactions willingly, believing they are funding their own profit-generating bot. This architecture makes the campaign substantially harder for conventional defenses to detect and for victims to identify as fraud until funds are already lost.","heading":"Evasion of Standard Security Warnings","severity":"critical","sources":[{"credibility":2,"name":"Fake AI Trading Bots Are Getting Victims to Build Their Own Drainers — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/fake-ai-trading-bots-are-getting-victims-to-build-their-own-drainers"}]},{"content":"The campaign was distributed through multiple YouTube channels presenting as independent educators. According to TRM Labs, nine nearly identical videos had accumulated a combined 310,474 views as of September 2026, with the earliest video in the identified cluster posted in April 2026. SentinelOne's earlier research on the overlapping pattern documented specific channels including @todd_tutorials (since made private), @SolidityTutorials, and @Jazz_Braze. SentinelOne noted that several presenters displayed characteristics consistent with AI-generated video: robotic voice synthesis with inconsistent speech pacing and unnatural facial movements. Both TRM Labs and SentinelOne observed that comment sections were curated to suppress negative feedback and amplify fabricated testimonials. SentinelOne further documented a secondary distribution channel via Telegram handles such as @janesolidity and noted that aged YouTube accounts are sold on Telegram for this type of operation. The use of AI-generated presenters across multiple nominally separate channels is consistent with a single coordinated operator or small group, though the operators' identities had not been publicly confirmed as of the reporting dates.","heading":"YouTube Distribution Infrastructure and AI-Generated Content","severity":"high","sources":[{"credibility":2,"name":"Fake AI Trading Bots Are Getting Victims to Build Their Own Drainers — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/fake-ai-trading-bots-are-getting-victims-to-build-their-own-drainers"},{"credibility":2,"name":"Smart Contract Scams: Ethereum Drainers Pose as Trading Bots to Steal Crypto — SentinelOne","type":"research","url":"https://www.sentinelone.com/labs/smart-contract-scams-ethereum-drainers-pose-as-trading-bots-to-steal-crypto/"}]},{"content":"TRM Labs traced 274.60 ETH (approximately $517,205 USD) from 224 victim wallets into six shared collection addresses between February 12 and August 11, 2026. A total of 234 malicious contracts were deployed by victims following tutorial instructions, meaning some victims deployed multiple contracts or some contracts received funds from more than one depositor. The median individual loss was 1 ETH, consistent with tutorial instructions to fund contracts with 1-2 ETH as startup capital. SentinelOne's overlapping investigation, which covered campaigns dating back to at least 2024, identified separate campaigns with losses of $28,000 USD (7.59 ETH) and $15,000 USD (4.19 ETH) in addition to the $902,000 USD collected by the most active identified address. No law enforcement actions or fund recoveries had been publicly reported as of the dates of TRM Labs' and SentinelOne's publications.","heading":"Financial Impact and Victim Profile","severity":"critical","sources":[{"credibility":2,"name":"Fake AI Trading Bots Are Getting Victims to Build Their Own Drainers — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/fake-ai-trading-bots-are-getting-victims-to-build-their-own-drainers"},{"credibility":2,"name":"Smart Contract Scams: Ethereum Drainers Pose as Trading Bots to Steal Crypto — SentinelOne","type":"research","url":"https://www.sentinelone.com/labs/smart-contract-scams-ethereum-drainers-pose-as-trading-bots-to-steal-crypto/"}]},{"content":"TRM Labs contextualized this campaign within a broader surge in AI-themed crypto fraud. Their 2026 AI-in-Crime Adoption Index found AI adoption by criminal actors rising 40% year-over-year, with scam operations identified as among the most mature adopters of AI tooling across the attack lifecycle. According to TRM Labs, losses from deepfake-assisted scams in 2026 had already surpassed the full-year 2025 total by 263% as of the August 2026 reporting date. The use of \"Claude\" branding specifically exploits public awareness of Anthropic's Claude as a leading large language model; the name is used as a social proof signal rather than reflecting any actual technical integration. This pattern — affixing a credible AI brand to a fraudulent product — has been observed independently of this campaign in other contexts, including alleged Polymarket arbitrage bot promotions flagged by independent researchers in mid-2026. Those separate incidents are distinct from the YouTube tutorial drainer campaign documented here.","heading":"Broader Context: AI Branding in Crypto Fraud","severity":"medium","sources":[{"credibility":2,"name":"Fake AI Trading Bots Are Getting Victims to Build Their Own Drainers — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/fake-ai-trading-bots-are-getting-victims-to-build-their-own-drainers"},{"credibility":2,"name":"AI adoption in crypto crime rose 40% over the past year, TRM Labs says — The Block","type":"news_article","url":"https://www.theblock.co/news/web3/2026-08-21-ai-adoption-in-crypto-crime-trm-412297"}]},{"content":"As of the dates of available reporting (TRM Labs, September 2026; SentinelOne, 2025), the operators behind the campaign had not been publicly identified. TRM Labs described the operation as a \"likely coordinated\" network based on the near-identical tutorial scripts, shared collection addresses, and common post-theft fund movement patterns. Six Ethereum addresses were identified by TRM Labs as collection endpoints; SentinelOne identified three specific wallet addresses (0x872528989c4D20349D0dB3Ca06751d83DC86D831, 0x2eEE3A0ed51AE22813050212E8D9Fa216bd51df4, 0x7359EA6AA3343b3238171e76F97e6aA3cDB8d696). No law enforcement charges, indictments, or regulatory actions had been publicly announced as of the time of this investigation. AVOID.NET will update this page if enforcement actions or operator identifications are publicly confirmed.","heading":"Attribution and Investigation Status","severity":"high","sources":[{"credibility":2,"name":"Fake AI Trading Bots Are Getting Victims to Build Their Own Drainers — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/fake-ai-trading-bots-are-getting-victims-to-build-their-own-drainers"},{"credibility":2,"name":"Smart Contract Scams: Ethereum Drainers Pose as Trading Bots to Steal Crypto — SentinelOne","type":"research","url":"https://www.sentinelone.com/labs/smart-contract-scams-ethereum-drainers-pose-as-trading-bots-to-steal-crypto/"}]}],"sources_used":[{"credibility":2,"name":"Fake AI Trading Bots Are Getting Victims to Build Their Own Drainers — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/fake-ai-trading-bots-are-getting-victims-to-build-their-own-drainers"},{"credibility":2,"name":"Smart Contract Scams: Ethereum Drainers Pose as Trading Bots to Steal Crypto — SentinelOne Labs","type":"research","url":"https://www.sentinelone.com/labs/smart-contract-scams-ethereum-drainers-pose-as-trading-bots-to-steal-crypto/"},{"credibility":2,"name":"AI adoption in crypto crime rose 40% over the past year, TRM Labs says — The Block","type":"news_article","url":"https://www.theblock.co/news/web3/2026-08-21-ai-adoption-in-crypto-crime-trm-412297"}],"summary":"A coordinated scam operation, active between at least February and August 2026, distributed nine near-identical YouTube tutorials purporting to teach viewers how to deploy a \"Claude-built\" AI crypto arbitrage bot. According to TRM Labs, the deployed smart contracts contained no trading logic whatsoever and simply forwarded any funds sent to them to operator-controlled addresses; 224 victims lost 274.60 ETH (approximately $517,205 USD) across six shared collection addresses. SentinelOne independently documented the same pattern of Ethereum drainers masquerading as AI trading bots on YouTube, tracing an overlapping campaign that collected over $900,000 USD from a single operator address.","timeline":[{"date":"2024-06-06","event":"YouTube channel @Jazz_Braze published \"How to Create Passive Income MEV Bot on Ethereum,\" an early iteration of the drainer-as-trading-bot pattern documented by SentinelOne. The video accumulated over 387,000 views before SentinelOne's report. A \"free offer\" urgency window (June 6-30, 2024) was used as a persuasion tactic.","source":"SentinelOne Labs","source_url":"https://www.sentinelone.com/labs/smart-contract-scams-ethereum-drainers-pose-as-trading-bots-to-steal-crypto/"},{"date":"2025-08-07","event":"SentinelOne published research documenting Ethereum drainers posing as MEV and trading bot tutorials on YouTube, identifying specific channels, wallet addresses, and obfuscation techniques. The most active identified address had received over $900,000 USD.","source":"SentinelOne Labs","source_url":"https://www.sentinelone.com/labs/smart-contract-scams-ethereum-drainers-pose-as-trading-bots-to-steal-crypto/"},{"date":"2026-02-12","event":"Earliest victim transaction in the TRM Labs-tracked cluster of \"Claude-built arbitrage bot\" YouTube tutorial drainers, based on on-chain data analysis.","source":"TRM Labs","source_url":"https://www.trmlabs.com/resources/blog/fake-ai-trading-bots-are-getting-victims-to-build-their-own-drainers"},{"date":"2026-04-01","event":"Earliest YouTube video in the nine-video \"Claude AI arbitrage bot\" cluster identified by TRM Labs was posted, approximately.","source":"TRM Labs","source_url":"https://www.trmlabs.com/resources/blog/fake-ai-trading-bots-are-getting-victims-to-build-their-own-drainers"},{"date":"2026-08-11","event":"Latest victim transaction in TRM Labs' tracked window. By this date, 224 victims had lost 274.60 ETH (~$517,205 USD) across 234 deployed contracts, all funds flowing to six shared operator collection addresses.","source":"TRM Labs","source_url":"https://www.trmlabs.com/resources/blog/fake-ai-trading-bots-are-getting-victims-to-build-their-own-drainers"},{"date":"2026-09-01","event":"TRM Labs published its investigation into fake AI trading bot drainers, documenting the nine-video \"Claude-built arbitrage bot\" YouTube cluster, victim count, total ETH drained, and fund movement patterns. Nine videos had accumulated 310,474 combined views as of publication.","source":"TRM Labs","source_url":"https://www.trmlabs.com/resources/blog/fake-ai-trading-bots-are-getting-victims-to-build-their-own-drainers"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision f9d5415d-684f-4495-b1a6-d261a2aa5d76
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.