Looking into this campaign, and I’d say proper research by victims could have prevented many of these losses. There were several red flags, but the promise of easy profits may have caused people to overlook them.
The threat actor(s) behind this campaign have drained $500K+ and appear to still be active.
I found a few of the YouTube videos used in the campaign, identified some of the theft addresses, and looked into how victims were being tricked.
One interesting part of the setup: the attackers registered ENS names containing “Uniswap,” making the addresses appear connected to legitimate DeFi activity:
0x331314385625D9912f8a5ee1bF86b837DCB42990
: uniswap-v3-router.eth
0x6E0CD1C8e1Df611E53E23B7900Ed8A830f4C871C
: uniswap-defi.eth
0x0E111ba687517937F08B189b84FbD02d86cbd739: uniswap-v2-pool.eth
These addresses were shown as sources of incoming transactions, making it look like contract were receiving profits from their deployed arbitrage trading bots via Uniswap.
But that wasn’t what was actually happening.
The attackers provided victims with a tutorial and code for creating the supposed arbitrage bot. The source code itself wasn’t the main trap.
The real trick was the development interface.
Victims were directed to an interface designed to look like Remix and instructed to use it to compile and deploy the contract.
After victims deployed the contract and funded it with their own assets, the attacker was able to drain the funds.
The attacker still appears to hold a significant portion of the stolen funds at these addresses:
0xcf27FAFb41e183C567E23786bB1f3E80a44b8Ef3
0x8d3736f31de511ad19c168973190a2e0c75f776a
Stay smart.
LATEST: 🚨 TRM Labs says 9 fake YouTube tutorials on building a crypto arbitrage bot with Claude tricked 224 victims into deploying self-draining smart contracts, netting scammers 274.60 ETH over 6 months.