A new cyber threat exploiting the anticipation for Grand Theft Auto VI has been identified, targeting cryptocurrency users. Malwarebytes, a cybersecurity firm, discovered a fake website claiming to offer an “exclusive” version of the unreleased game, which instead distributes malicious software designed to empty visitors’ crypto wallets.
What are the tactics used?
The bogus website masquerades as a countdown page for GTA 6 fans while deceptively providing a download link for a purported “leaked” version of the game. To complete the transaction, it demands users connect their crypto wallets, which leads to unforeseen consequences.
How are different blockchain networks targeted?
Two distinct malicious codes were found on the payment page by Malwarebytes. The first code specifically exploits Solana wallets by transferring funds elsewhere, leaving only a minimal amount to cover transaction fees. The second code extends its reach even further, posing a risk to digital wallets on blockchain networks like Ethereum, Polygon, BNB Smart Chain, Avalanche, Arbitrum, Base, and Fantom.
Despite appearances, the site ingeniously utilizes genuine GTA 6 promotional materials to gain credibility. It accurately claims the game will launch on PlayStation 5 and Xbox Series X|S but erroneously suggests a PC version, which Rockstar Games has not announced. Discrepancies arise in its claims, such as offering downloads only upon payment, conflicting with its disclaimer of no purchase availability.
- The site falsely presented payment options as a path to unreleased gaming content.
- A failed transaction could lead to losing more than the intended payment.
- Mistakes in text and mislabeling, such as referring to the game as GTA IV, raise skepticism.
Fake early access sites for GTA 6, purported demo pages, and scams dubbed “Extended Look” have also been tracked by Malwarebytes. Furthermore, an undisclosed identity linked to another GTA VI leak moved crypto assets valued at $350,000 under the name CYBERLEEK. Despite ongoing blockchain analyses, the person behind this remains unidentified.


