Cybersecurity company Malwarebytes revealed that a website impersonating the download page for " GTA 6" is inducing users to connect to encrypted wallets, thereby transferring assets on the blockchain. While the page appears to be a countdown for a game and a download link for a "leaked version," it actually embeds wallet theft scripts targeting multiple public blockchains.
Pretending to be a game leak page
These pages contain seemingly authentic materials labeled “GTA 6”, and use bait such as “early access” or “leaked version” to lure visitors into making payments or connecting their wallets. Malwarebytes indicates that there are two types of payment methods on these pages: one requires a payment of 50 US dollars, and the other demands a payment of 1 SOL.
The operators also attempted to create credibility by “reminding users that other leaked websites are scams.” However, researchers still found multiple errors in the page copy, including spelling issues, as well as the mistake of writing GTA VI as GTA IV.
Capable of attacking multiple public chains simultaneously.
According to Malwarebytes, malicious code mainly appears in the payment option area, which contains two sets of independent components:
- A set designed for the Solana wallet
- A set of wallets compatible with Ethereum-based chains
Among them, the scripts related to Solana will calculate the transfer amount, leaving only a small balance sufficient for the payment of handling fees in the victim's account. Another set of larger-scale scripts disguise themselves as normal wallet connection tools, but they add malicious functions on top of the original code.
According to Malwarebytes, the latter can launch attacks against multiple wallets on various networks, including:
- Ethereum
- Polygon
- BNB Smart Chain
- Avalanche, Arbitrum, Base, and Fantom
GTA Six themes have been repeatedly used in crypto scams.
Malwarebytes There have also been numerous cases of fraud taking advantage of the popularity of GTA 6 before, including so-called "early access experiences," fake demonstration pages, and pages related to Extended Look. Such websites typically mix real game information with forged transaction processes to lower users' vigilance.
U.Today also mentioned that just a few days ago, another wave of crypto-related activities related to the GTA VI leaks was tracked by blockchain analysis institutions for unusual fund movements. Reports show that wallets associated with CYBERLEEK transferred approximately $350,000, but the identities of the relevant operators have not yet been made public.
Such incidents demonstrate that popular games, airdrops, and exclusive content are still common methods used in crypto phishing. For users, any page that requires payment before downloading, or that asks for connection to a wallet to claim "exclusive content," constitutes a high-risk scenario.











