Community Investigation

The Fake GTA 6 Wallet Drainer: What the Published Solana Address Proves — and What It Does Not

REPORT
REPORT

September 02, 2026

Malwarebytes reported a fake “GTA 6 leaked copy” site that placed a 1 SOL checkout in front of a download and loaded a remote multi-chain drainer script. The page exposed a Solana recipient address: 21iWU6FJWJ9FKKz4Jek2CyTh2x1fqs5jawjrNgE3nHjN.

ChainBounty traced that address with SentinelTX. The result is useful precisely because it separates a public campaign indicator from proof of stolen funds. The address has real, transaction-anchored activity, but this investigation did not establish a victim-to-address transfer, an exchange cash-out, or an operator identity.

WHAT THE SOURCE ESTABLISHES

The Malwarebytes analysis establishes the off-chain threat context: the fraudulent site presented a fake game purchase, calculated a near-total Solana balance transfer, and loaded code capable of targeting wallets on several EVM networks. It also published the Solana recipient and two infrastructure domains.

Those findings do not automatically make every historical transaction involving the published address a theft transaction. That link must be proved separately on-chain.

WHAT SENTINELTX OBSERVED ON-CHAIN

SentinelTX reconstructed a nine-address Solana cluster around the published seed. Four origin wallets supplied tokens or SOL to the seed, which then performed a batch token fan-out and several small USDC and SOL transfers.

TRANSACTION ANCHORS

Token collection:

• 200,000 ELN and 51,227.499584 ELPEPE — 4aPGZvywmCZMeDqpKTfUiQjeHZYEDXJHRRLk4Vmq6YCBAwkWde7U3DimT6SamroZdwM4HKcgNWSceFgkoXY33KPn

• 16,365.777142 HOTDOGE — eTFwnkombV3AvMmd9ucWeZ6LMbN9KuWnoSB8nQbJm9JsFAYAoUFAHxzy87R33JurAnAFFBrSWJF8awpyWcKSpZC

SOL funding:

• 6 SOL in six transfers — 2BAtZ1NUPqQnxM4vrvLDdN9fg5hy1Fh255nytZiUsG2Mhy61Y2YiVBc1UhiP2UrzydofBpCbzTHFpZkW62huhc96

• A separate 1 SOL transfer — 2n9suUMLocSKpEvprh2g5EPecxKpZgEvCsiSFnn2DW5BJAAr6BJQcbm1EarFFZFyGq2Aj43efNTGiGYJZXCniJEV

Batch fan-out:

• Three tokens processed in seven transfers each — 3mEMGzxpcv3hvitz2N59TkiQesuYT4RVuNAbTrXteHdssZpCavaM8JN1z8fupRNwaiLTxmG52WK61fucduq72TNH

Small outputs:

• 20.815272 USDC total and 0.623665 SOL total to four downstream wallets — 24PoJ2K27zjSrko4GkP49fP67XTC25xHYgX2aaSKcKcF3AwnNifrWXrqUGR12zEaMuqiP7BeVQ4JMCjkWME4E2zX; 549nFiAFvKU4sA9zUcTYKeZhS1SsJLpWeVfZ5X7XAa26RNm2DhYARTijor6sW9zqAupWfaCHEkDxK6SA3wz1mWuj; 4BXrF2MFbt7U6BshdLY12qQAK5kBV7VGEroaPLZZnVgBAZ2S1qX2qxMZq21fMapHsCAPZ4C41ZxLAKFCsJHQg9AJ

The equal seven-way treatment of three tokens is consistent with scripted batch activity. The split SOL funding may be operational gas funding. Those are analytical interpretations, not proof that the cluster belongs to the drainer operator.

THE KEY FORENSIC BOUNDARY

None of the nine addresses returned a reliable exchange, mixer, bridge, or named-service attribution. The four observed downstream wallets had no further movement within the traced scope. No confirmed cash-out leg was found.

This means the investigation cannot defensibly claim:

• that the observed tokens or SOL came from victims of the fake GTA 6 site;

• that the batch fan-out was laundering rather than token distribution or spam;

• that any specific person or organization controls the cluster;

• a campaign-wide loss amount; or

• a recovery target at a centralized exchange.

The low-value outputs—about 20.8 USDC and 0.62 SOL—could represent settlement or account costs, but that remains inference. The on-chain evidence does not yet support calling them stolen proceeds.

ADDRESSES WORTH MONITORING

• 21iWU6FJWJ9FKKz4Jek2CyTh2x1fqs5jawjrNgE3nHjN — published seed; collection and redistribution; unattributed.

• HMiD3578xUqodjNfLrFFTUwZww6aou6AKiX2NU33JXrM — six-part SOL supplier; unattributed.

• 3TwWg4vVnVLBnwpJa8ZK3FrAbNucX8L3BtWtuwt7uVoC — ELN and ELPEPE supplier; unattributed.

• 8ekCy2jHHUbW2yeNGFWYJT9Hm9FW7SvZcZK66dSZCDiF — largest USDC output and bidirectional counterparty; unattributed.

The strongest next step is backward tracing of the four origin wallets and instruction-level decomposition of the seven fan-out recipients. Downstream monitoring should prioritize 8ekCy2jH…, because it is both the largest USDC recipient and a bidirectional counterparty.

CONCLUSION

The fake GTA 6 site is a credible wallet-drainer threat. The published Solana address is a valid indicator of compromise and has a structured on-chain history. But an indicator is not the same as an attribution.

The defensible conclusion today is narrower: SentinelTX confirmed a nine-address collection-and-redistribution cluster, but did not prove that the observed funds were victim proceeds or identify a cash-out endpoint. That boundary should guide monitoring, exchange notices, and any future public claims.

Source: Malwarebytes, “Fake GTA 6 ‘leaked copy’ drains your crypto wallet” (1 September 2026)

https://www.malwarebytes.com/blog/scams/2026/09/fake-gta-6-leaked-copy-drains-your-crypto-wallet

post_like_sub0
post_total_comment_sub0

3 reads

0/500 bytes