Skip to content

Safety report / Sep 9, 2026

GTA 6 safety.GTA 6 Crypto Scam Used a Fake Leaked-Copy Offer

A fake GTA 6 leaked-copy offer used wallet-draining code. Learn the difference between connecting, approving, signing and exposing a recovery phrase.

Reputable reporting

Reader safety alert

Protect your accountAlertCheck first
Use official sources and avoid downloads, wallet requests and fake demo pages.
EvidenceReputable reporting
PublishedSep 9, 2026
Last verifiedSep 16, 2026
ByAJ · Independent news desk

Reader safety report

Check the claim.
Protect yourself.

Understand the reported risk, use official channels and act carefully if an account or device may be affected.
3D cartoon safety shield blocking a suspicious package and wallet prompt
Safety report visualOriginal safety illustration; it contains no actionable scam link.

Malwarebytes documented a fake GTA 6 “leaked copy” page that used wallet-draining code. The offer was not an authorized game release. It mixed accurate-looking launch information with payment prompts designed to lead visitors into connecting a crypto wallet and approving harmful requests.

There is no official GTA 6 PC release or leaked-copy download to buy in the first-party sources checked September 16, 2026. Rockstar directs buyers to normal platform stores and authorized retailers; a legitimate GTA 6 purchase does not require a crypto-wallet connection.

What Malwarebytes found on this page

The September 1 primary report describes a fan-site-style countdown and release-facts grid beside a false “leaked copy” offer. The page advertised a cash price and a crypto option, but the wallet code did not simply charge that advertised amount. Researchers found an inline Solana transfer path and a separate multi-chain script capable of requesting token or NFT permissions and preparing transfers across several networks.

This is the investigated page’s behavior, not a claim that every GTA 6 scam uses the same code. The visible game facts were part of the disguise; a correct date or map image did not make the purchase offer real.

Connection, approval and recovery phrase are different risks

What happened Main risk Immediate action
You only opened the page Tracking or exposure to the prompt; no wallet permission by itself Close it and do not return
You connected a wallet but approved nothing The site may see public wallet details; connection alone is not the same as a transfer Disconnect the site and review wallet activity
You approved a token or NFT permission The permission may allow assets to be moved later Revoke the approval through the wallet’s official tools
You signed a transfer Assets may have moved immediately Check every relevant chain and contact the wallet provider through an official channel
You entered a recovery or seed phrase The wallet itself must be treated as compromised From a clean device, create a new wallet and move remaining assets carefully

The primary report says simply connecting did not by itself let the page take assets. The danger came from the transaction or permission request that followed. That distinction should not create false comfort: a user who approved a request must act even if no loss is visible yet.

The researchers did not report that this code requested or exposed the wallet recovery phrase. The phrase row above is a separate worst-case response if someone entered it into any related prompt or contact channel. Do not infer a seed-phrase theft from connection alone.

If you connected or approved something

  1. Stop interacting with the page and open your wallet through its real app or bookmarked official site.
  2. Review and revoke permissions granted to the suspicious site. Disconnecting the site does not automatically cancel an approval.
  3. Check tokens, NFTs and transaction history across every network you use, not only the currently selected chain.
  4. If assets moved, report the receiving address and transaction to the wallet provider and an appropriate public scam-reporting service.
  5. If you exposed a recovery phrase, move any remaining value to a newly created wallet from a clean device. Do not reuse the exposed phrase.
  6. Ignore direct messages offering guaranteed recovery. Recovery scammers often target people who have already lost funds.

What recovery can and cannot do

Revoking a permission can stop a still-active approval from being used later. It cannot reverse a transfer that has already completed. A wallet provider may help identify the correct response or flag an address, but no one should promise that transferred cryptocurrency can be recovered.

Do not send more money to “unlock,” “verify” or recover funds. Do not share a seed phrase with support staff; legitimate wallet support does not need it.

Why the page looked believable

The reported page used real-looking release details and fan-site elements beside the false offer. Correct facts do not validate the payment request. Official artwork, countdowns and launch dates are easy to copy.

This incident also differs from the fake-demo malware campaign. That campaign used an executable to target passwords and browser sessions. This one centered on wallet permissions and signed transactions. Someone who both ran a file and connected a wallet should follow both response paths.

We do not publish the scam address, malicious domains or wallet destination. Malwarebytes’ linked report contains the technical evidence. For broader checks covering passwords, console accounts, fake beta invitations and preorder stores, read how to avoid GTA 6 scams.

Sources

We checked these sources before publishing. Official sources are used wherever possible.

  1. Fake GTA 6 leaked copy drains your crypto wallet — Malwarebytes, checked Sep 16, 2026
  2. Pre-Order Grand Theft Auto VI on June 25 — Rockstar Games, checked Sep 16, 2026