mt logoMyToken
ETH Gas
عربى

Fake GTA 6 Leak Uses Multi-Chain Crypto Wallet Drainer

يجمعcollect
شاركshare
malware-virus-hack

Malwarebytes said on September 1 that a website posing as a seller of a leaked Grand Theft Auto VI copy contains code designed to drain connected cryptocurrency wallets. The firm’s technical analysis found one component aimed at Solana and a separate, larger script configured for seven additional networks. The campaign is a wallet-permission threat rather than a simple payment scam.

The page advertises the supposed leak for $50 or one SOL and borrows plausible release details to appear credible. Malwarebytes said the inline Solana code ignores that advertised price: it checks a wallet balance, leaves a small amount for transaction fees, and prepares the remainder for transfer. That behavior makes the requested purchase price a lure rather than a limit on potential loss.

Drainer Targets Assets Across Multiple Networks

According to the researchers, a separate script of roughly 2.4 MB incorporates legitimate wallet-connection software alongside malicious functions. It can inventory holdings, estimate their value, send wallet and visitor details to the operator, and retrieve transactions for approval. The configured networks are Ethereum, Polygon, BNB Smart Chain, Avalanche, Arbitrum, Base, and Fantom; the code can also identify stablecoins and request access to tokens or NFT collections.

The distinction between a transfer and an approval matters. A transfer can move assets immediately, while a token or NFT approval may leave the attacker able to move them later. Similar wallet-drainer campaigns have exploited deceptive permission requests , making the signing screen—not the marketing page—the decisive security checkpoint.

Researchers See Signs of Rented Infrastructure

Malwarebytes said the larger script downloads an operator identifier and settings from a remote server, while its destination address differs from the Solana address embedded in the page. The researchers said that structure resembles a hosted service used by multiple customers, though they could not identify a specific product. Remote configuration would let an operator change where stolen funds are sent without editing the fake GTA page itself.

The code also profiles wallets before seeking approval and includes measures intended to frustrate automated scanners and browser developer tools. An optional country filter blocks visitors from ten countries in the Commonwealth of Independent States region. Malwarebytes cautioned that the list alone does not establish who built or operates the campaign.

Wallet Approval Screen Is the Last Defense

Simply connecting a wallet does not transfer assets, the report stressed; the danger arises when a user signs the transaction or permission request that follows. Users should reject requests that move nearly an entire balance or grant a game seller control over tokens or NFTs. Broader crypto wallet security practices also include using trusted download sources and separating valuable holdings from wallets used for unfamiliar applications.

Anyone who approved access should review and revoke active permissions, while a user who entered a recovery phrase should treat the wallet as separately compromised and move remaining assets to a newly created wallet. The incident extends a pattern of phishing campaigns targeting crypto holders , in which recognizable brands create urgency before a deceptive request.

إخلاء المسؤولية: تعود حقوق نشر هذه المقالة إلى المؤلف الأصلي ولا تمثل MyToken(www.mytokencap.com)الآراء والمواقف ؛ يرجى الاتصال بنا إذا كانت لديك أسئلة حول المحتوى وحقوق التأليف والنشر وما إلى ذلك.
community_x_prefix
X(https://x.com/MyTokencap)
community_tg_prefixcommunity_tg_name
https://t.me/mytokenGroup
القراءة ذات الصلة