VYPR
scamPublished Sep 1, 2026· 1 source

Fake GTA 6 Leaks Used to Distribute Crypto-Stealing Wallet Drainers

Scam websites impersonating Grand Theft Auto VI leaks are tricking users into connecting their cryptocurrency wallets, leading to the theft of digital assets.

Scam operations are once again leveraging the hype surrounding Grand Theft Auto VI (GTA 6) to defraud unsuspecting users, this time by presenting fake "leaked" copies of the game that are, in reality, sophisticated cryptocurrency wallet drainers. This follows previous scams that attempted to sell "early access" or distribute infostealers under the guise of GTA 6 demos.

The latest iteration of these scams involves websites that meticulously mimic legitimate fan pages, complete with countdown timers to the official release date, maps of the game's setting, and detailed gameplay information. This convincing facade is designed to lure users into clicking on offers to purchase a "leaked" copy of the game, often for a price in cryptocurrency.

Upon interacting with these malicious sites, users are prompted to connect their cryptocurrency wallets. The scam employs two distinct types of malicious code. The first, embedded directly into the page, targets Solana wallets, attempting to transfer all available assets after leaving a minimal amount for transaction fees. The second, a more potent and versatile script, integrates with a legitimate wallet connection tool but adds malicious functionality.

This advanced script inventories the contents of a connected wallet across multiple blockchain networks, including Ethereum, Polygon, BNB Smart Chain, Avalanche, Arbitrum, Base, and Fantom. It identifies valuable assets like stablecoins, tokens, and NFTs, and can request various levels of approval from the user. Depending on the permissions granted, attackers can either immediately transfer funds or gain the ability to move tokens and entire NFT collections at a later time.

Adding another layer of evasion, the scam script first checks the visitor's IP address to determine their country. If the visitor is located in specific CIS countries (Armenia, Azerbaijan, Belarus, Kazakhstan, Kyrgyzstan, Moldova, Russia, Tajikistan, Turkmenistan, Uzbekistan), they are redirected to a blank page, a common tactic to avoid local law enforcement.

Before any transaction is requested, the script profiles the visitor by collecting details about their wallet holdings, their estimated dollar value, IP address, country, and connection history, sending this information to the attacker. The script also incorporates anti-analysis features, designed to evade security scanners and automated browsers, and conceals its server addresses.

Several indicators suggest this wallet drainer is a rented service rather than a custom-built tool. The use of a remote server to download settings and operator IDs, and the ability to change the destination of stolen funds without altering the website, are characteristic of a Software-as-a-Service (SaaS) model for cybercriminals.

While the scam's footer may claim no purchases or downloads are offered, the presence of payment buttons and the underlying malicious code tell a different story. The conflicting information and errors within the sales copy suggest a hastily assembled scam that preys on the immense anticipation for GTA 6, highlighting the persistent threat of crypto-draining scams.

Synthesized by Vypr AI