Fake GTA 6 “Leaked Copy” Site Drains Wallets

Malwarebytes · High sophistication
Last updated September 2, 2026

A scam website posing as a GTA 6 fan countdown page tricks visitors into buying a “leaked copy” and then prompts them to connect a crypto wallet. Once connected, it generates transactions/approvals designed to transfer the victim’s cryptocurrency (and potentially NFTs) to the attacker. The site uses accurate-looking GTA 6 details to appear trustworthy, while hiding a wallet-draining script behind the purchase flow.

How the attack worked

A scam website styled itself as a GTA 6 fan countdown page while offering to sell a leaked copy of the game for $50 or 1 SOL. The moment a visitor arrived, the page loaded a wallet drainer, code built to steal cryptocurrency and other digital assets from connected wallets. When a visitor chose to pay with cryptocurrency, the drainer asked them to connect a wallet, then requested a transaction or permission approval. That approval is what actually moves funds or grants ongoing access to tokens and NFTs.

Two malicious components were identified: an inline script focused on Solana, and a larger multi-chain script capable of targeting Ethereum, Polygon, BNB Smart Chain, Avalanche, Arbitrum, Base, and Fantom. The site also blocked visitors from a list of countries using a setting tied to reducing law-enforcement exposure.

Why it succeeded

The page mixed accurate details, such as real artwork and release date information, with a fraudulent purchase flow. That accuracy lent the site credibility even though the actual transaction mechanics were malicious. The site also used a reassurance tactic, telling visitors that every other leak site was a scam and that this one was the only safe place to buy, a technique designed to lower the guard of anyone already suspicious.

Sales copy still contained tells, including a misspelled word and a reference to GTA IV instead of VI, but these were easy to miss for a visitor eager for early access to a major release.

What to watch for

  • A game purchase site asking you to connect a crypto wallet or approve token/NFT permissions
  • Approval requests that do not match the expected price, such as attempts to move nearly all wallet funds
  • Reassurance language claiming other sites are scams while this one is safe
  • Spelling errors or references to the wrong game title in sales copy

How to build resistance

  • Treat any offer of early or leaked access to a major game release as a red flag; verify through official channels before paying
  • Treat a wallet connection request on a game site as a stop sign, since legitimate sellers like Rockstar do not ask buyers to connect a wallet or send cryptocurrency
  • Always read the wallet approval screen carefully and reject any request that would transfer all or nearly all of your balance
  • Do not let accurate-looking content, such as correct release dates or real artwork, vouch for the legitimacy of the rest of the site

Key findings

  • Scam page poses as a GTA 6 countdown/fan site while selling a “leaked copy” for $50 or 1 SOL.
  • The site loads a wallet drainer “the moment you arrive” and then asks the victim to connect a wallet to pay.
  • Malicious code can inventory the wallet, estimate total value, and request transactions/approvals that could transfer funds immediately or enable later theft of tokens/NFTs.
  • The script blocks visitors from a list of countries using a setting named `CIS_Protection`, a common tactic to reduce law-enforcement risk.
  • Two malicious components are described: an inline Solana-focused drainer and a larger multi-chain script targeting Ethereum, Polygon, BNB Smart Chain, Avalanche, Arbitrum, Base, and Fantom.
  • Indicators of compromise include two domains and a Solana address used for an inline transfer attempt.

Who’s being targeted

  • Commonly targeted roles: All employees (general awareness), Finance and treasury teams handling crypto, Executives and high-net-worth/asset-holding staff, IT/helpdesk staff who support endpoint/browser security.
  • Affected industries: Consumers/Personal finance (crypto holders), Gaming/Entertainment communities, Online retail/e-commerce.
  • Attack channels: website.
  • Impersonated: GTA 6 fan/leak site (implied legitimate GTA 6 seller), ‘Only safe’ GTA 6 leak seller.

Red flags to watch for

  • A game purchase site asks you to connect a crypto wallet or approve token/NFT permissions
  • The approval request does not match the expected price (e.g., attempts to move nearly all funds)
  • The page contains contradictions (e.g., claims ‘no purchase’ while showing payment buttons)
  • Site uses ‘everyone else is a scam, only we are safe’ reassurance language
  • Sales copy has obvious errors (misspellings, wrong game referenced)
  • Claims conflict with public info (e.g., platform availability, pricing)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the fake GTA 6 site steal cryptocurrency?

The site loads a wallet drainer as soon as visitors arrive, then asks anyone paying with cryptocurrency to connect a wallet and approve a transaction or permission that can transfer funds or grant ongoing access to tokens and NFTs.

Is there really a leaked or early copy of GTA 6 available?

No. According to the source, nobody is selling a playable copy of GTA 6 yet, so any site offering a leaked, early, or playable copy is not an authorized seller.

What red flags indicate this is a scam?

Warning signs include being asked to connect a crypto wallet on a game site, reassurance language claiming every other site is a scam except this one, and sales copy with misspellings or a reference to the wrong game title.

Does Rockstar Games ask buyers to use cryptocurrency wallets?

No. Rockstar does not ask buyers to connect a cryptocurrency wallet or send cryptocurrency to a wallet address, so any such request should be treated as a stop sign.

Read the video transcript

You see a slick GTA 6 countdown site, big banner: “Leaked copy – only $50 or 1 SOL.” Tempting, right? The moment you land, it silently loads a wallet drainer. Choose crypto, and it pushes: “Connect wallet to pay.” Behind that, code is inventorying your wallet and prepping transactions to drain your crypto and NFTs. The page insists every other leak site is a scam and this is the “only safe place,” while the copy misspells “download” and even mentions GTA IV. Your wallet screen then asks to move way more than $50 or to grant broad token and NFT permissions. Here’s the move: treat any wallet connection request on a game or leak site as a stop sign. Don’t connect, don’t approve, close the tab and only trust official GTA 6 announcements.

Similar attacks

Fake GTA 6 “Demo” Sites Push Password-Stealer

Fake GTA 6 “Demo” Sites Push Password-Stealer

Attackers are using convincing Rockstar Games lookalike websites to trick people into downloading a supposed “GTA 6 demo.” The download is actually Vidar infostealer malware that can steal browser passwords, cookies, and logged-in sessions, potentially exposing personal and work accounts if they…

August 27, 2026
Fake GTA 6 Demo Sites Push Password-Stealing Malware

Fake GTA 6 Demo Sites Push Password-Stealing Malware

The article describes real-world scams riding on the GTA 6 leak hype, including fake “Extended Look” and “demo” websites that deliver password-stealing malware. It also warns about “free early access” offers designed to drain crypto wallets, showing how leaked footage can make these lures more…

August 25, 2026
Fake TikTok Shop Sites Mimic Badges to Steal Pay

Fake TikTok Shop Sites Mimic Badges to Steal Pay

Scammers are setting up lookalike websites that copy TikTok Shop’s design, trust badges, and wording to trick people into thinking they’re shopping inside TikTok. The main risk is entering payment (and sometimes loan-application) details into a site that has no real connection to TikTok, leading to…

August 11, 2026
Encrypted Prompt Injection Tricks AI Tools

Encrypted Prompt Injection Tricks AI Tools

Researchers demonstrated a prompt-injection method that hides malicious instructions inside encrypted text, then tricks an AI assistant into decrypting it using built-in code tools. In tests, a normal “summarize this page” request could cause Grok to exfiltrate chat data without any click or…

August 25, 2026
Fake Microsoft Scan Pushes AV Uninstall Scam

Fake Microsoft Scan Pushes AV Uninstall Scam

Scammers are running Microsoft-branded “SysScan” websites that display a fake security scan and falsely claim Windows no longer supports third‑party antivirus. Victims are pressured to uninstall their antivirus, submit personal and banking details, and prepare for a “refund manager” phone call,…

August 24, 2026
Fake Verification Pages Push PavinLoader Malware

Fake Verification Pages Push PavinLoader Malware

Malwarebytes reports that a multi-stage Windows malware loader called PavinLoader is being delivered through multiple real-world campaigns, including ClickFix “verification” pages and fake software downloads. Victims are tricked into running installers or scripts that use legitimate Windows tools…

August 24, 2026