A network of crypto scammers is leveraging aged YouTube accounts to push trading bots that lure users into deploying malicious smart contracts capable of draining their wallets. Sounding the alarm on this “widespread and ongoing” threat, senior threat researcher Alex…A network of crypto scammers is leveraging aged YouTube accounts to push trading bots that lure users into deploying malicious smart contracts capable of draining their wallets. Sounding the alarm on this “widespread and ongoing” threat, senior threat researcher Alex…

Malicious crypto trading bots siphon over $900k via aged YouTube accounts

A network of crypto scammers is leveraging aged YouTube accounts to push trading bots that lure users into deploying malicious smart contracts capable of draining their wallets.

Summary
  • Scammers are using aged YouTube accounts to promote malicious crypto trading bots.
  • Victims are tricked into deploying obfuscated Ethereum contracts that redirect funds to attacker-controlled addresses.

Sounding the alarm on this “widespread and ongoing” threat, senior threat researcher Alex Delamottea from SentinelLABS warned that crypto users who rely on unvetted tools promoted through video content are exposing themselves to sophisticated theft scams disguised as opportunity.

How does the scam work?

According to SentinelLABS, the scam begins with YouTube videos that appear to offer step-by-step tutorials on deploying profitable crypto trading bots. These videos, often produced using AI-generated visuals and narration, direct users to an external site containing smart contract code. 

Viewers are told to deploy the code on platforms like Remix, a popular Ethereum development environment, under the pretense of activating a so-called arbitrage or MEV (Maximal Extractable Value) bot.

However, the contract is deliberately designed to conceal an attacker-controlled wallet. In many cases, the code was found to be using various obfuscation techniques, such as XOR operations, string concatenation, or address derivation through hexadecimal conversion, to hide the scammer’s address from plain view.

Once the victim deploys the contract and funds it with Ether, the attacker can extract those funds using hidden failover mechanisms embedded in the contract logic.

SentinelLABS found that victims are encouraged to deposit a minimum of 0.5 ETH to cover supposed gas fees and increase potential profits. This initial deposit is critical to triggering the contract’s logic, which, once executed, allows the attacker’s address to siphon off the funds.

In some cases, even if users don’t explicitly activate the contract, built-in fallback mechanisms still allow the attacker to gain control of the assets.

Scammers are making big money

Delamottea’s investigation revealed multiple unique scammer-controlled addresses, though one wallet stood out. The address associated with the YouTube user “@Jazz_Braze” received 244.9 ETH—worth over $900,000—via these contracts. 

SentinelLABS traced the movement of these stolen funds across more than two dozen secondary addresses, concluding that the funds were being laundered.

Meanwhile, other scammer wallets were less successful but still notable, with inflows averaging over $10,000 in ETH.

All these wallets were tied to different YouTube videos or channels, many of which featured AI-generated narrators and heavily moderated comment sections that filtered out negative feedback while promoting fabricated testimonials of success.

Malicious crypto trading bots siphon over $900k via aged YouTube accounts - 1

SentinelLABS also noted that the YouTube accounts used in the scam were aged and previously hosted playlists or videos related to cryptocurrency or pop culture. 

According to the report, some of these accounts were possibly bought from online marketplaces, where aged YouTube channels are commonly sold through Telegram groups or search-indexed marketplaces.

Malicious crypto trading bots siphon over $900k via aged YouTube accounts - 2

This aging tactic helps boost visibility and trust, making it harder for viewers to identify the malicious intent in most cases.

What are crypto trading bots actually?

In legitimate settings, trading bots are algorithmic tools that execute buy or sell orders based on preset strategies. They are often capable of operating across multiple exchanges to take advantage of price inefficiencies or market trends, often aiming to execute trades faster than a human could.

With the advent of artificial intelligence, these applications have become more adaptive, efficient, and capable of executing complex strategies at scale, and when properly built and vetted, serve as automation tools for sophisticated traders and institutions, especially in high-frequency environments like crypto.

One well-known category of these tools includes MEV bots, which attempt to extract value from transaction ordering within blocks. MEV stands for Maximal Extractable Value, and these bots monitor blockchain mempools to strategically front-run, back-run, or sandwich legitimate user transactions. 

While MEV bots are technically legal, bad actors have also weaponized them. For instance, the MEV sandwich bot “arsc” leveraged automated strategies to extract nearly $30 million from unsuspecting Solana users by front-running transactions in real time.

A cautionary note for crypto traders

SentinelLABS stressed that while trading bots have legitimate uses, investors must exercise extreme caution, especially when the source code is coming from a social media video promising unrealistic gains.

“To defend against these types of scams, crypto traders are advised to avoid deploying code shilled through influencer videos or social media posts,” Delamottea warned, adding that “if an offering seems too good to be true, it usually is—especially in the cryptocurrency world.”

Piyasa Fırsatı
ALEX Lab Logosu
ALEX Lab Fiyatı(ALEX)
$0.00122
$0.00122$0.00122
+2.52%
USD
ALEX Lab (ALEX) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

The post CEO Sandeep Nailwal Shared Highlights About RWA on Polygon appeared on BitcoinEthereumNews.com. Polygon CEO Sandeep Nailwal highlighted Polygon’s lead in global bonds, Spiko US T-Bill, and Spiko Euro T-Bill. Polygon published an X post to share that its roadmap to GigaGas was still scaling. Sentiments around POL price were last seen to be bearish. Polygon CEO Sandeep Nailwal shared key pointers from the Dune and RWA.xyz report. These pertain to highlights about RWA on Polygon. Simultaneously, Polygon underlined its roadmap towards GigaGas. Sentiments around POL price were last seen fumbling under bearish emotions. Polygon CEO Sandeep Nailwal on Polygon RWA CEO Sandeep Nailwal highlighted three key points from the Dune and RWA.xyz report. The Chief Executive of Polygon maintained that Polygon PoS was hosting RWA TVL worth $1.13 billion across 269 assets plus 2,900 holders. Nailwal confirmed from the report that RWA was happening on Polygon. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 The X post published by Polygon CEO Sandeep Nailwal underlined that the ecosystem was leading in global bonds by holding a 62% share of tokenized global bonds. He further highlighted that Polygon was leading with Spiko US T-Bill at approximately 29% share of TVL along with Ethereum, adding that the ecosystem had more than 50% share in the number of holders. Finally, Sandeep highlighted from the report that there was a strong adoption for Spiko Euro T-Bill with 38% share of TVL. He added that 68% of returns were on Polygon across all the chains. Polygon Roadmap to GigaGas In a different update from Polygon, the community…
Paylaş
BitcoinEthereumNews2025/09/18 01:10
Why Are Disaster Recovery Services Essential for SMBs?

Why Are Disaster Recovery Services Essential for SMBs?

Small and medium-sized businesses operate in an environment where downtime, data loss, or system failure can quickly turn into an existential threat. Unlike large
Paylaş
Techbullion2026/01/14 01:16
The Android OS Architecture:  Part 1 — What an Operating System Actually Does

The Android OS Architecture: Part 1 — What an Operating System Actually Does

An operating system acts as the central coordinator between hardware and software, managing processes, memory, security, hardware access, and the user interface
Paylaş
Hackernoon2026/01/14 00:32