September 02, 2026
Malwarebytes reported a fake “GTA 6 leaked copy” site that placed a 1 SOL checkout in front of a download and loaded a remote multi-chain drainer script. The page exposed a Solana recipient address: 21iWU6FJWJ9FKKz4Jek2CyTh2x1fqs5jawjrNgE3nHjN.
ChainBounty traced that address with SentinelTX. The result is useful precisely because it separates a public campaign indicator from proof of stolen funds. The address has real, transaction-anchored activity, but this investigation did not establish a victim-to-address transfer, an exchange cash-out, or an operator identity.
WHAT THE SOURCE ESTABLISHES
The Malwarebytes analysis establishes the off-chain threat context: the fraudulent site presented a fake game purchase, calculated a near-total Solana balance transfer, and loaded code capable of targeting wallets on several EVM networks. It also published the Solana recipient and two infrastructure domains.
Those findings do not automatically make every historical transaction involving the published address a theft transaction. That link must be proved separately on-chain.
WHAT SENTINELTX OBSERVED ON-CHAIN
SentinelTX reconstructed a nine-address Solana cluster around the published seed. Four origin wallets supplied tokens or SOL to the seed, which then performed a batch token fan-out and several small USDC and SOL transfers.

TRANSACTION ANCHORS
Token collection:
• 200,000 ELN and 51,227.499584 ELPEPE — 4aPGZvywmCZMeDqpKTfUiQjeHZYEDXJHRRLk4Vmq6YCBAwkWde7U3DimT6SamroZdwM4HKcgNWSceFgkoXY33KPn
• 16,365.777142 HOTDOGE — eTFwnkombV3AvMmd9ucWeZ6LMbN9KuWnoSB8nQbJm9JsFAYAoUFAHxzy87R33JurAnAFFBrSWJF8awpyWcKSpZC
SOL funding:
• 6 SOL in six transfers — 2BAtZ1NUPqQnxM4vrvLDdN9fg5hy1Fh255nytZiUsG2Mhy61Y2YiVBc1UhiP2UrzydofBpCbzTHFpZkW62huhc96
• A separate 1 SOL transfer — 2n9suUMLocSKpEvprh2g5EPecxKpZgEvCsiSFnn2DW5BJAAr6BJQcbm1EarFFZFyGq2Aj43efNTGiGYJZXCniJEV
Batch fan-out:
• Three tokens processed in seven transfers each — 3mEMGzxpcv3hvitz2N59TkiQesuYT4RVuNAbTrXteHdssZpCavaM8JN1z8fupRNwaiLTxmG52WK61fucduq72TNH
Small outputs:
• 20.815272 USDC total and 0.623665 SOL total to four downstream wallets — 24PoJ2K27zjSrko4GkP49fP67XTC25xHYgX2aaSKcKcF3AwnNifrWXrqUGR12zEaMuqiP7BeVQ4JMCjkWME4E2zX; 549nFiAFvKU4sA9zUcTYKeZhS1SsJLpWeVfZ5X7XAa26RNm2DhYARTijor6sW9zqAupWfaCHEkDxK6SA3wz1mWuj; 4BXrF2MFbt7U6BshdLY12qQAK5kBV7VGEroaPLZZnVgBAZ2S1qX2qxMZq21fMapHsCAPZ4C41ZxLAKFCsJHQg9AJ
The equal seven-way treatment of three tokens is consistent with scripted batch activity. The split SOL funding may be operational gas funding. Those are analytical interpretations, not proof that the cluster belongs to the drainer operator.
THE KEY FORENSIC BOUNDARY
None of the nine addresses returned a reliable exchange, mixer, bridge, or named-service attribution. The four observed downstream wallets had no further movement within the traced scope. No confirmed cash-out leg was found.

This means the investigation cannot defensibly claim:
• that the observed tokens or SOL came from victims of the fake GTA 6 site;
• that the batch fan-out was laundering rather than token distribution or spam;
• that any specific person or organization controls the cluster;
• a campaign-wide loss amount; or
• a recovery target at a centralized exchange.
The low-value outputs—about 20.8 USDC and 0.62 SOL—could represent settlement or account costs, but that remains inference. The on-chain evidence does not yet support calling them stolen proceeds.
ADDRESSES WORTH MONITORING
• 21iWU6FJWJ9FKKz4Jek2CyTh2x1fqs5jawjrNgE3nHjN — published seed; collection and redistribution; unattributed.
• HMiD3578xUqodjNfLrFFTUwZww6aou6AKiX2NU33JXrM — six-part SOL supplier; unattributed.
• 3TwWg4vVnVLBnwpJa8ZK3FrAbNucX8L3BtWtuwt7uVoC — ELN and ELPEPE supplier; unattributed.
• 8ekCy2jHHUbW2yeNGFWYJT9Hm9FW7SvZcZK66dSZCDiF — largest USDC output and bidirectional counterparty; unattributed.
The strongest next step is backward tracing of the four origin wallets and instruction-level decomposition of the seven fan-out recipients. Downstream monitoring should prioritize 8ekCy2jH…, because it is both the largest USDC recipient and a bidirectional counterparty.
CONCLUSION
The fake GTA 6 site is a credible wallet-drainer threat. The published Solana address is a valid indicator of compromise and has a structured on-chain history. But an indicator is not the same as an attribution.
The defensible conclusion today is narrower: SentinelTX confirmed a nine-address collection-and-redistribution cluster, but did not prove that the observed funds were victim proceeds or identify a cash-out endpoint. That boundary should guide monitoring, exchange notices, and any future public claims.
Source: Malwarebytes, “Fake GTA 6 ‘leaked copy’ drains your crypto wallet” (1 September 2026)
https://www.malwarebytes.com/blog/scams/2026/09/fake-gta-6-leaked-copy-drains-your-crypto-wallet

3 reads