Malwarebytes documented a fake GTA 6 “leaked copy” page that used wallet-draining code. The offer was not an authorized game release. It mixed accurate-looking launch information with payment prompts designed to lead visitors into connecting a crypto wallet and approving harmful requests.
There is no official GTA 6 PC release or leaked-copy download to buy in the first-party sources checked September 16, 2026. Rockstar directs buyers to normal platform stores and authorized retailers; a legitimate GTA 6 purchase does not require a crypto-wallet connection.
What Malwarebytes found on this page
The September 1 primary report describes a fan-site-style countdown and release-facts grid beside a false “leaked copy” offer. The page advertised a cash price and a crypto option, but the wallet code did not simply charge that advertised amount. Researchers found an inline Solana transfer path and a separate multi-chain script capable of requesting token or NFT permissions and preparing transfers across several networks.
This is the investigated page’s behavior, not a claim that every GTA 6 scam uses the same code. The visible game facts were part of the disguise; a correct date or map image did not make the purchase offer real.
Connection, approval and recovery phrase are different risks
| What happened | Main risk | Immediate action |
|---|---|---|
| You only opened the page | Tracking or exposure to the prompt; no wallet permission by itself | Close it and do not return |
| You connected a wallet but approved nothing | The site may see public wallet details; connection alone is not the same as a transfer | Disconnect the site and review wallet activity |
| You approved a token or NFT permission | The permission may allow assets to be moved later | Revoke the approval through the wallet’s official tools |
| You signed a transfer | Assets may have moved immediately | Check every relevant chain and contact the wallet provider through an official channel |
| You entered a recovery or seed phrase | The wallet itself must be treated as compromised | From a clean device, create a new wallet and move remaining assets carefully |
The primary report says simply connecting did not by itself let the page take assets. The danger came from the transaction or permission request that followed. That distinction should not create false comfort: a user who approved a request must act even if no loss is visible yet.
The researchers did not report that this code requested or exposed the wallet recovery phrase. The phrase row above is a separate worst-case response if someone entered it into any related prompt or contact channel. Do not infer a seed-phrase theft from connection alone.
If you connected or approved something
- Stop interacting with the page and open your wallet through its real app or bookmarked official site.
- Review and revoke permissions granted to the suspicious site. Disconnecting the site does not automatically cancel an approval.
- Check tokens, NFTs and transaction history across every network you use, not only the currently selected chain.
- If assets moved, report the receiving address and transaction to the wallet provider and an appropriate public scam-reporting service.
- If you exposed a recovery phrase, move any remaining value to a newly created wallet from a clean device. Do not reuse the exposed phrase.
- Ignore direct messages offering guaranteed recovery. Recovery scammers often target people who have already lost funds.
What recovery can and cannot do
Revoking a permission can stop a still-active approval from being used later. It cannot reverse a transfer that has already completed. A wallet provider may help identify the correct response or flag an address, but no one should promise that transferred cryptocurrency can be recovered.
Do not send more money to “unlock,” “verify” or recover funds. Do not share a seed phrase with support staff; legitimate wallet support does not need it.
Why the page looked believable
The reported page used real-looking release details and fan-site elements beside the false offer. Correct facts do not validate the payment request. Official artwork, countdowns and launch dates are easy to copy.
This incident also differs from the fake-demo malware campaign. That campaign used an executable to target passwords and browser sessions. This one centered on wallet permissions and signed transactions. Someone who both ran a file and connected a wallet should follow both response paths.
We do not publish the scam address, malicious domains or wallet destination. Malwarebytes’ linked report contains the technical evidence. For broader checks covering passwords, console accounts, fake beta invitations and preorder stores, read how to avoid GTA 6 scams.

