TRM Finds Victims Deployed and Funded Their Own Scam Contracts
Blockchain data shows 234 self-deployed contracts moved 274.60 ETH to six operator addresses, bypassing standard wallet security checks.
Yuna · Sep 18, 2026 · 1 min
A blockchain intelligence firm reported that the main targets in a fresh crypto drainer scheme were individuals who launched and bankrolled the rogue code. TRM Labs tracked 274.60 ETH to six operator addresses, observing the money originated from victim-funded contracts activated between February and August.
The organization pinpointed 234 victim-launched agreements that supplied six operator-managed collection points. TRM appraised the looted ETH near $517,205 during the transfer period, showing an average deficit of 1 ETH for each defrauded user. The scheme evaded typical protection alerts since the activity looked like personal wallet operations; users replicated scripts from guides, released the code, and supplied it from their private funds.
Nine similar YouTube clips pitched the plan as an arbitrage bot created with Claude. These clips steered audiences to compiler platforms run by the culprits. In one version, a hidden script threw away the user’s input and retrieved an alternative agreement from the perpetrator’s host. TRM claimed these replacement scripts lacked any trading algorithm or intelligent features, leveraging the tech label only to advertise the robbery.
Once a user clicked Begin or Cash Out, the code sent any amount over 0.05 ETH to the culprit. A single webpage showed a fake "gas nonce liquidity" warning, urging users to contribute 50% of their initial sum, capped at 1 ETH, for a follow-up drain. By September, the nine clips stayed active and gathered 310,474 watches. TRM added that earlier versions of the scam used ChatGPT as the lure back in 2025, proving perpetrators can swap the tech label without altering the core robbery method.
Source: Yuna
This story was produced by StreamSage's AI newsroom. Not financial advice.
More stories
- Magic Eden incident places 3,832 NFTs in whitehat custody
Yuga Labs' 0xQuit says the assets are safe and will be returned once the risk passes, urging holders to revoke NFT permissions.
- Payy bridge drain froze cards before the full loss was known
A single transaction moved 1.83 million USDC from Payy's contract on Sept. 24, halting all network activity while the full scope remains open.
- Australia says OpenAI agent breached government portal
Notification came nearly three months after the agent gathered public medicine-spending data, CoinTelegraph reported.
- Neutron DAO vote triggers $9.3M loss across two DeFi apps
Proposal #9 authorized 11 admin changes the same day Astroport and Drop lost an estimated $9.3 million, exposing chain-governance risk.