Scammers have found a way to drain crypto wallets by tricking them into building the tool that ends up stealing from them. This particular case involves stealing Ethereum, but it doesn't matter which asset was stolen or how much of it. It could have also been targeting bitcoin or been created to do a different type of damage to a victim's system.
"Necessity is the mother of invention."An attacker is always more interested in the victim's wallet than the victim themselves is. That is why victims let their guard down.
I am sharing this to show how dangerous it is to run code you don't understand and how trusting unknown people on the internet can be dangerous, especially those who claim they want to help you make money.
Amidst the "programming boom", everyone wants to feel like a programmer - especially given how easily accessible AI is.
It’s risky to trust strangers

- especially those "helping" make money.
Back to the drainer.
This case involves a scammer making YouTube tutorials, showing people how to build crypto trading bots with Claude. They provide the viewers with the code they need to use and explain what to do. The scammers explain how to fund the wallet of the "trading bot." The unsuspecting victims deploy a smart contract themselves, on their own computer, and approve transactions without knowing it. While it's true that Bitcoin's smart contract capabilities are much more limited than Ethereum's, a different type of attack could also trick bitcoin holders and make them lose money or infect their systems.
When I read the details of this story, I found the simplicity and ingenuity of the scam (on one hand) rather amusing. After all, why should a scammers complicate the task by "breaking into" a victim's system when they can simply nudge the victim into creating the malicious program themselves? From a technical standpoint, it is quite inventive. I hope my admiration for the execution isn't mistaken for approval of the perpetrator's actions; it is, after all, a regrettable incident that could have affected almost anyone.
What the victims didn't know is that the "trading bot" isn't a bot at all. It was created to empty your wallet of all ETH and send it to a scammer. It's reported that over 200 wallets were drained in this way and over $500,000 was stolen.
During a
gold BTC-rush, the best way to make money is by selling shovels. Now, fake "shovels" are being sold.
The lesson here is: don't copy and run unknown code. Don't open unknown files. Don't trust people you don't know who want to help you get rich. They might be looking for a way to get rich off of you. Keep both eyes open at all times.
It seems the world is sliding into an era of paranoia. Now, anything related to currencies is at risk of "attack" by malicious actors - even "custom-written code" can be turned against the user themselves.
In reality, nothing has changed. The victims simply wanted to make easy money by creating a trading bot that would earn them millions. The scammers brilliantly exploited the victim's greed. They shouldn't have sought an easy path to riches.
The sad part of this story is that the victims made and deployed the drainers that stole money from themselves.
So, who is ultimately to blame? The users themselves for their "blind trust"? What stopped them from checking the code in other AI tools and figuring out its (hidden) purpose?
An interesting detail:
"Some victims even got an error after getting drained telling them to deposit another 50% to fix the bot." -Like I said, this scam is brilliant.

They also conned people out of money for fixing the bot.