Fake GTA 6 Leak Site Demands 1 SOL to Drain Multi-Chain Crypto Wallets
Malwarebytes exposed a fake GTA 6 leak site charging 1 SOL or $50 while running a multi-chain drainer targeting Solana, Ethereum, Arbitrum and more wallets.
AI SummaryAI
- Fake GTA 6 leak site demands $50 or 1 SOL, about $102, for a nonexistent leaked copy.
- Malwarebytes found drainer code targeting Solana, Ethereum, Polygon, BNB Chain, Avalanche, Arbitrum, Base, Fantom.
- Fake Claude Opus 5 desktop app spreads RevStealer, covering over 50 crypto wallet types.
- RevStealer reads backup C2 server addresses from a Polygon smart contract on-chain.
Fake GTA 6 Leak Page Pushes 1 SOL “Copy”
A counterfeit website posing as a fan countdown for Grand Theft Auto VI is targeting crypto users with a wallet drainer hidden behind an alleged leaked copy of Rockstar Games’ title. The page, uncovered by cybersecurity firm Malwarebytes, blends genuine-looking promotional material — it correctly notes the game is coming to PlayStation 5 and Xbox Series X|S, and Rockstar has announced no PC version — with two payment offers for a supposedly leaked build. One offer asks for $50 in fiat; the other requests 1 Solana (SOL), worth roughly $102 when the site was analyzed. Visitors who approve a malicious transaction could lose far more than the advertised price, since the drainer is built to sweep entire wallets rather than process a purchase.
The technical setup confirms that intent. Analysts found two separate pieces of malicious code in the payment section. The first targets Solana wallets specifically, calculating a transfer designed to leave behind only enough funds to cover transaction fees. The second is a larger script disguised as a legitimate blockchain node-style wallet-connection tool, but with drainer code added on top, capable of hitting wallets across Ethereum, Polygon, BNB Smart Chain, Avalanche, Arbitrum, Base and Fantom. The operators even warn visitors that other GTA 6 leak sites are scams to build trust. The facade collapses under inspection: the footer claims the site sells nothing, the FAQ promises a PC download after payment despite the console-only framing, and the sales copy misspells “downloading” and references GTA IV instead of GTA VI. Malwarebytes had previously flagged supposed “early access” sales, a fake demo and an “Extended Look” page tied to the game. Separately, a figure linked to an earlier wave of GTA VI leaks moved roughly $350,000 out of the CYBERLEEK operation, per blockchain analysis; that individual remains unidentified.
RevStealer Masquerades as Claude Opus 5
In a parallel campaign, security researchers at Morphisec Threat Labs have disclosed a Windows application branded “Claude Opus 5 Free Desktop” that actually installs an infostealer named RevStealer. The real Claude Opus 5 is the AI model Anthropic launched on July 24, and attackers are exploiting its name recognition with a “use the paid model for free” pitch to lure victims into downloading a roughly 101 MB archive. Once installed, the program never shows a working Claude interface — it simply prepares and runs the malicious payload in the background.
RevStealer is built to evade analysis before it steals. It first checks memory, processor cores, username, hostname and graphics hardware to detect sandboxes or virtual machines used by researchers; only after passing those checks does it decrypt an AES-encrypted payload, write it to the Windows AppData directory and attempt to add that folder to Microsoft Defender’s exclusion list. Its collection scope covers more than 50 Anthropic-adjacent targets — crypto wallet types — plus around 12 password managers, Windows Credential Manager, browser databases, session cookies, VPN and remote-access tools, messaging apps, the clipboard, screenshots and specified documents. Morphisec stresses that “50+ wallets” means supported theft targets, not confirmed compromises. Notably, the malware reads backup command-and-control server addresses from a Polygon smart contract when its primary server is unreachable, and it sets no boot persistence: it deletes itself after exfiltrating data to shorten its footprint. As of September 2, no infection count or loss figure has been disclosed, and the research does not claim any Anthropic system was breached. Users who ran the installer should isolate the machine, run a full scan, rotate credentials from a clean device and consider moving hot-wallet assets, a habit long-term HODL practitioners should extend to every download: official channels only. Readers tracking the market in real time can follow live spot and futures prices on MEXC.
Hype Lures, Chain-Native Payloads
Our reading of both campaigns points to the same shift: crypto theft is no longer sold with crypto-branded lures, but piggybacks on mainstream hype — a blockbuster game launch and a flagship AI model release. The payloads, meanwhile, are chain-native by default, with multi-network drainers and on-chain fallback channels that outlast takedowns of a single server. The practical takeaway is narrow but strict: approve no unsolicited transaction, and treat any “free” premium software outside its official download page as hostile until proven otherwise.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


