Research Blog, Reference Library, Data Repository

CyberLeek GTA 6 Leak: New Video, Crypto Money Trail and Rockstar’s Investigation

CyberLeek is back with a major GTA 6 video leak. Our evidence-based briefing reconstructs the cryptocurrency transactions, court subpoenas, second token launch and security threats—while separating what is proven from what remains unknown.
A video game controller beside a network map and a stack of redacted documents, suggesting a GTA 6 leak and investigation.
Contents

CyberLeek, the pseudonym associated with a series of unauthorized Grand Theft Auto VI disclosures, returned on October 8 with nearly 25 minutes of alleged gameplay. Video Games Chronicle (VGC) reviewed the material and said it appeared authentic. Rockstar Games has not publicly authenticated this particular video.

But the footage is only the visible part of the story. Public blockchain investigations connect the August leak campaign to a Solana cryptocurrency that had been prepared before the footage circulated widely. Another CyberLeek-branded token appeared later in August. Meanwhile, Grand Theft Auto publisher Take-Two Interactive obtained federal court orders for subpoenas seeking identifying information, and unrelated criminals exploited the GTA 6 publicity to distribute password-stealing malware.

The central finding: The evidence supports a deliberate, financially structured publicity operation surrounding the leaks. It does not establish who originally obtained the game material, whether the same person controlled every CyberLeek-branded account and token, or how much money any identifiable individual ultimately received.

CyberLeek GTA 6 Leak: What Happened on October 8?

On October 8, a video published under the CyberLeek name showed roughly 25 minutes of apparent GTA VI gameplay. VGC’s Chris Scullion, who reviewed the footage directly, described scenes involving the game’s protagonists Jason and Lucia, an event at the Thrillbilly Mud Club, dirt-bike racing, vehicle customization and street racing. Kotaku also reviewed the newly circulating material.

The video contains substantial nudity. More important than the spectacle is an unresolved technical point: VGC also observed an apparently spawned tank, raising the possibility that some scenes reflect commands or modifications available to whoever was operating the build. A feature shown in leaked footage is not automatically a feature confirmed for the retail game. That applies to character appearance, scripted sequences, vehicle systems and apparent cheat or developer commands.

The footage ends with a message claiming CyberLeek is seeking resources for an expensive, long-running gaming-related project that is not associated with Rockstar. No independently verified project budget, technical plan, operator identity or spending record accompanied that claim in the material reviewed. The message therefore establishes what the publisher says it intends, not where money has gone or whether the proposed project exists.

Rockstar previously acknowledged the August GTA VI leaks, describing the unauthorized disclosures as distressing for its team. That earlier acknowledgment should not be treated as a statement authenticating each subsequent upload. The October 8 video is apparently authentic according to independent eyewitness reporting, not an officially confirmed preview.

Who Is CyberLeek? Is the GTA 6 Leaker Identified?

CyberLeek is a public-facing pseudonym, not a verified legal identity. The initial August campaign paired alleged game footage with messages criticizing practices such as digital preorders, restrictions on offline play and the monetization of games. At the same time, the releases directed attention toward a cryptocurrency. PC Gamer’s account of the original campaign describes this mix of consumer-rights rhetoric, leaked material and token promotion.

For attribution, four roles must be kept separate:

Role What public evidence supports What remains unknown
Original source of GTA 6 material Someone obtained access to or possession of nonpublic game material. The access method, person, employer relationship and whether any new network intrusion occurred.
CyberLeek-branded publisher An account or group distributed material and fundraising messages under the name. Whether the publisher personally acquired the material.
August $CYBERLEEK token operators Public blockchain records identify deployment, liquidity and subsequent transaction paths. The real-world controllers of the relevant wallets and their connection to the original source.
Later $CYBER token operators A second on-chain token and fee-distribution structure are documented in a separate research report. Whether the same people operated both tokens, or whether brand access was transferred, imitated or compromised.

These roles could overlap. They could also involve different people. A wallet transfer cannot, by itself, establish the identity of a leaker. Nor should the current operation be conflated with the separate, widely reported GTA VI security incident of 2022 without evidence linking the actors.

Did CyberLeek hack Rockstar Games?

The public evidence reviewed does not establish how the current material was obtained. A playable-looking build can suggest access to game assets or a running environment, but it does not prove the operator compromised Rockstar’s current production network. Other explanations—including receipt of files from another party—cannot responsibly be excluded on the evidence presently available.

The correct distinction is between unauthorized possession or distribution, which the apparent leak concerns, and a proven method of intrusion, which has not been publicly demonstrated for this campaign.

CyberLeek Timeline: From Token Preparation to the October 8 Leak

A reconstructed chronology is useful because it shows that the cryptocurrency activity was not simply an afterthought once the campaign became widely known. The date and nature of each event matter.

Date in 2026 What the record shows Evidence basis
August 13–15 Funding transfers moved through wallets later connected by researchers to the first token’s deployer. Reproducible funding analysis
August 15 $CYBERLEEK was minted; a Raydium liquidity pool was created and liquidity was locked. On-chain transaction chronology
August 18 Unauthorized GTA VI material began circulating widely under the CyberLeek name. Malwarebytes’ contemporaneous account
August 21–24 Take-Two secured orders related to records from Discord, Microsoft and X. Federal court records and TorrentFreak’s legal reporting
August 27 The original token’s deployer moved approximately 2,705 SOL to new addresses after a large creator-fee token sale. Corrected transaction report
August 29 A second token, $CYBER, appeared using the name “Grand Theft Leek” and branding linked at the website level to the original campaign. Separate round-two blockchain report
August 31 A federal judge authorized a further Discord subpoena; Take-Two separately withdrew its proposed YouTube request. August 31 court order and TorrentFreak
October 8 A new, nearly 25-minute video surfaced with an appeal connected to an unspecified gaming project. VGC’s direct review

The chronology shows advance token infrastructure and subsequent monetization activity. It does not establish that revenue was the sole motive for obtaining the game files, nor that one individual performed every stage.

How Much Money Did CyberLeek Make? The Crypto Trail Explained

Financial coverage of CyberLeek has included large dollar figures, but several different events are often collapsed into one supposed payday: launching a token, supplying liquidity, receiving trading fees, selling accumulated fee tokens and transferring SOL to other wallets. These are not interchangeable.

An independent, transaction-based investigation published by xorextrace provides the clearest reproducible breakdown of the original $CYBERLEEK token. It identifies the token mint as ApZuxdpzMrbEYTGEzeY9afh5pj9d6qPRJCTgQYiipbKg and the relevant deployer wallet as Hok9nbV89yBSKCttxe3goqajwbiqQa9mtHvQBsbJH3Np.

First: 331.66 SOL funded liquidity, not a cash-out

The deployer received three notable transfers on August 15 totaling approximately 331.66 SOL. The investigation traces roughly 330.19 SOL into the creation of the initial Raydium liquidity pool. That was capital used to establish the market in which the token could trade. Describing those inbound funds as money the operator immediately withdrew reverses what the transaction shows.

The same investigation found that liquidity-provider tokens were subsequently locked. A liquidity lock can prevent the simple removal of that initial pool position; it does not prevent fees or token sales from generating income through other mechanisms.

Bitquery’s separate examination of the deployer’s funding trail corroborates that a multistep funding structure existed before the public campaign. It does not, however, independently establish who controlled the accounts or reproduce the later August 27 exit totals, which occurred after its stated analysis date.

Next: the August 27 creator-fee conversion

Two credible accounts describe the proceeds using different transaction categories. CoinDesk’s August 27 report, linking directly to contemporary transaction records, distinguishes the claim of approximately 1,442.43 wrapped SOL from the sale of roughly 15.4 million fee-derived $CYBERLEEK tokens, reportedly producing another 1,234.23 SOL. The later xorextrace report groups approximately 2,676.67 SOL as fee-token conversion proceeds. Those descriptions differ as to the precise mix of claimed wrapped SOL and token swaps, even though they converge on the combined amount.

Without independently decoding every underlying transaction, the defensible headline is the aggregate movement, not an assertion that all 2,676.67 SOL came from the same kind of swap. Four transfers from the deployer subsequently sent out approximately 2,705.07 SOL. The difference of roughly 28.4 SOL is consistent with a pre-existing wallet balance, subject to rounding and network fees.

Component Amount Correct interpretation
Wrapped SOL reportedly claimed About 1,442.43 WSOL CoinDesk’s classification of fee-related receipts; see discrepancy noted above.
Creator-fee token sale About 15.49 million $CYBERLEEK, reportedly sold for 1,234.23 SOL CoinDesk reports this separately from wrapped-SOL claims.
Combined fee-related amount, according to the reports About 2,676.67 SOL Rounded, source-attributed aggregate, not proven net profit.
Four outgoing transfers, combined About 2,705.07 SOL SOL moved from the deployer into further wallet chains.
Additional balance required to reconcile the figures About 28.4 SOL Pre-existing SOL, plus rounding and fee considerations; not an additional new revenue stream.
Transfers cleanly traced to addresses labeled CCE.Cash About 1,336.67 SOL Attribution to publicly labeled deposit infrastructure; not identification of its customer.
Transfers cleanly traced to an address labeled KuCoin deposit About 543.90 SOL Attribution to a publicly labeled deposit address; not identification of its customer.
Remaining outgoing SOL without equally clean end attribution About 824.50 SOL Cannot responsibly be assigned to a named exchange on the same evidentiary basis.

These are reported movements of cryptocurrency, not audited personal income. Depositing SOL into a wallet labeled as belonging to an exchange does not establish who held the relevant exchange account, whether fiat currency was withdrawn, what taxes or costs applied, or whether the original GTA 6 source received a payment.

Some coverage has described the sum as roughly $270,000 at a contemporaneous SOL price. Such a valuation depends on which transfers are counted and the exchange rate used. It should not be presented as a verified dollar profit or an amount held today.

An important correction: 3,210 SOL was an overcount

This record also contains a documented correction that could easily be lost when headlines are repeated. An earlier version of the xorextrace analysis put the August 27 outflow at approximately 3,210.80 SOL. The researcher subsequently found that a transfer of about 505.68 SOL had been counted twice while following it through an intermediary wallet.

The September 2 correction within the same research report reduced the figure to 2,705.07 SOL, allowing the reported fee-related inflows, existing wallet balance and outgoing transfers to reconcile. Any article retaining 3,210 SOL without explaining that correction is using an obsolete calculation.

Did the funds reach KuCoin or CCE.Cash?

The corrected tracing identifies approximately 1,881 SOL, or about 70%, of the deployer’s August 27 outgoing amount as reaching addresses publicly labeled as CCE.Cash or KuCoin deposit infrastructure. Another branch passed into a shared aggregation wallet later connected to exchange-related activity, but funds pooled with other users cannot be individually separated simply by looking at a larger outgoing transfer.

This is why analyses may produce different destination percentages. Assigning every SOL leaving a shared aggregator to the original CyberLeek wallet would risk counting unrelated funds. Neither an exchange label nor a wallet graph reveals a named person or verified exchange account holder.

Was the CyberLeek token a rug pull?

The answer depends on the conduct being alleged. The initial Raydium liquidity was reportedly locked, so this is not adequately described as the classic scenario of an operator simply removing all original pool liquidity. The creator-fee arrangement and subsequent sales nevertheless provided a way for token-linked activity to generate substantial proceeds.

Whether a transaction amounted to fraud, misleading promotion, lawful fee collection or another violation requires evidence about representations, intent and applicable law. A plunging token price alone does not resolve those questions. Investors could still suffer losses even if the specific mechanism was not a conventional liquidity withdrawal.

There Was Also a Second CyberLeek-Branded Token: $CYBER

A distinct round-two blockchain investigation documents a second token that appeared on August 29, under the name “Grand Theft Leek” and ticker $CYBER. Its mint address was GPx5APBduaoYaG1jrqYNM81GDGgLyLWev9My4mmipump—not the mint used for the August 15 $CYBERLEEK token.

The researcher found that the website used by the initial campaign displayed the new token, establishing continuity at the branding or website level. But that is not the same as cryptographic proof of common ownership. The examined round-two wallet data showed no reuse of the tested round-one wallets. That leaves the relationship between the two operations unresolved.

In seven initial fee distributions analyzed in the report, approximately 107.98 SOL was split among three recipient wallets. The distribution was close to 47.5% / 50% / 2.5%. These are observed distributions during the study’s limited window, not a complete lifetime earnings figure and not proven income of the unidentified original leaker. The round-two report is also labeled a draft, warranting greater caution than a fully independently replicated ledger.

This distinction matters particularly now: a new appeal for money on October 8 does not, by itself, prove another newly minted cryptocurrency or establish which operator controls it. Readers should not assume that similarly named tokens, donation addresses or accounts are genuine simply because they use the CyberLeek brand.

Take-Two’s Legal Investigation: What the Court Actually Authorized

Take-Two Interactive has pursued records that might help identify people involved in circulating its copyrighted material. Under 17 U.S.C. § 512(h), copyright owners may seek certain subpoenas directed to service providers for information identifying alleged infringers. The process can produce identifying records, but the request or authorization is not a criminal conviction or a finding that a particular person obtained the game files.

Public federal court records and TorrentFreak’s detailed review of the filings show an investigation involving Discord, Microsoft and X, alongside a YouTube-related request that was later withdrawn.

The most useful procedural distinction is this:

Procedural event What it establishes What it does not establish
Court authorizes a DMCA subpoena A court permitted legal process seeking specified records. That the target committed an offense or that the records were produced.
Company says a subpoena was served The company asserts delivery of legal process. That the provider received it at the stated time or supplied information.
Provider responds or objects A further legal step occurred, if documented. That every account belongs to the original source of the leak.
Name appears in a request Someone or an account is being investigated. That the real-world person is the leaker.

The August 31 order in In re Take-Two Interactive Software, Inc., No. 1:26-mc-00422, signed by U.S. District Judge Andrew L. Carter Jr., directed the court clerk to issue a subpoena to Discord. The order concerns information about persons or entities believed to be infringing Take-Two’s copyrights. It does not publicly identify CyberLeek.

An earlier, broader Discord request raised questions about records potentially belonging to people who were not the source of the leak. TorrentFreak reported that a later request was more specifically targeted, including an additional Discord user and more information about an earlier target. It also reported an unresolved discrepancy over when the first request was actually served: Take-Two characterized service as prompt, while a Discord representative said on August 24 that the company had not yet been served.

One important correction to simplified accounts of the investigation: Take-Two withdrew its proposed Google/YouTube subpoena request after a judge requested further explanation of the connection between named YouTube accounts and the material. That does not mean the wider investigation was dropped. Nor does it mean every originally sought subpoena remained active.

Has CyberLeek been caught or arrested?

No arrest or confirmed real-world identification was established by the public records reviewed for this article as of October 8, 2026. The publicly accessible Justia docket for the Discord matter displays the August 21 and August 31 orders, not a later public finding of identity. That is a limited statement about accessible records: additional PACER entries, sealed documents, private responses or investigative developments may not appear in this public mirror.

Are CyberLeek GTA 6 Downloads Safe? The Malware Warning

No purported playable GTA 6 demo or leaked PC installer should be treated as legitimate. Rockstar’s official release information lists Grand Theft Auto VI for PlayStation 5 and Xbox Series X|S on November 19, 2026; it has not announced a public PC demo or pre-release download. See Rockstar’s release announcement.

In August, Malwarebytes documented fake GTA 6 sites advertising a demo or extended-look download. Some directed visitors toward gta6_installer.exe, a small executable identified by its researchers as a Vidar information stealer. The malware could steal credentials, browser cookies and authenticated sessions, sometimes making compromised accounts vulnerable even when two-factor authentication is enabled.

This was a documented secondary criminal campaign exploiting GTA 6 attention. Malwarebytes’ findings do not establish that the malware distributors were the original CyberLeek operator.

If you downloaded or ran a suspicious GTA 6 installer:

  1. Stop using the file and disconnect the potentially affected computer from the network while you assess it.
  2. Run a reputable, updated security scan; consider professional assistance or a clean reinstall for a confirmed infostealer infection.
  3. From a different, trusted device, change important passwords, beginning with email and password-manager access, and revoke active sessions where supported.
  4. Review account recovery methods, payment accounts and suspicious logins; enable or reconfigure multi-factor authentication after securing the device.

Avoid websites promising leaked playable builds, account access, token rewards or prerelease unlocks. An alleged gameplay video is not proof that its publisher can safely distribute a functioning game.

CyberLeek Intelligence Assessment: Verified, Inferred and Unknown

The investigation becomes clearer when its conclusions are graded rather than treated as equally certain.

Assessment Current conclusion
Directly documented Federal judges authorized relevant Take-Two subpoenas; the August 31 Discord order exists.
Independently witnessed reporting Multiple gaming publications reviewed new October 8 footage that appears to depict GTA VI; Rockstar has not authenticated that specific release.
Transaction-based published research The original token’s August 15 setup and August 27 transfers can be reconstructed from the researcher-provided chronology and signatures. The author’s corrected outflow is approximately 2,705 SOL; separate contemporaneous reporting categorizes part of the proceeds as wrapped-SOL claims.
Preliminary published research A separate $CYBER token launched August 29 and had a distinct analyzed creator-fee split; common wallet control with the first token has not been shown.
Reasonable inference Token infrastructure built before major public circulation, followed by fee extraction and repeated fundraising, is consistent with a planned monetization component.
Unverified The original acquisition method; identity of the file source; whether all operators are one person; ultimate owner of the traced exchange accounts; total net profit; the existence of the latest promised project.

Our assessment: CyberLeek is best understood publicly as a leak-distribution and publicity campaign with a documented cryptocurrency component, not as a single identified hacker with a confirmed personal fortune. The evidence supports a financial motive or incentive; it does not establish exclusive motive, common ownership across all entities or a specific criminal identity.

Frequently asked questions

Is the October 8 CyberLeek GTA 6 video real?
VGC says it directly viewed the approximately 25-minute recording and that it appears authentic. Rockstar has not confirmed that specific video. Some scenes may reflect development or modified behavior, so they cannot be taken as final-game guarantees.

Who is CyberLeek?
An unidentified person or group publishing alleged GTA VI material and related messages under a pseudonym. The available wallet and court records do not reveal a verified real-world identity.

Did CyberLeek make $270,000 from GTA 6 leaks?
A public blockchain investigation documents roughly 2,705 SOL leaving the original token’s deployer wallet on August 27 following creator-fee claims and the sale of fee-derived tokens. This comprises different forms of fee-related proceeds and transfers; converting it into a round-dollar headline depends on historical prices. It is not proof of individual net profit, a fiat withdrawal or payment to the original source.

Are $CYBERLEEK and $CYBER the same cryptocurrency?
No. They have distinct Solana mint addresses and appeared on different dates, August 15 and August 29. The second reused campaign branding at the website level, but the investigated wallets did not establish that both tokens were controlled by the same people.

Has Rockstar identified or arrested CyberLeek?
No such identification or arrest was established in the accessible public records reviewed as of October 8. Court orders authorizing subpoenas are not equivalent to identification or arrest announcements.

Is there a legitimate GTA 6 demo or PC leak to download?
Rockstar has not announced a public GTA VI demo or PC release. Security researchers have documented fake GTA 6 download pages spreading credential-stealing malware.

Methodology and Evidence Limits

This briefing was compiled from first-hand reporting on the October 8 footage, publicly accessible federal court records, Rockstar’s release information, original malware research and independently published transaction-based Solana investigations. We reviewed the published researchers’ methods, corrections and attribution limits and reconciled the reported headline arithmetic. We did not independently retrieve and replay a complete raw Solana RPC history, access sealed court materials or obtain private exchange account data. Numbers from the blockchain investigations are consequently attributed to their researchers rather than presented as an independent sherafy.com blockchain audit.

We have not downloaded or republished unauthorized gameplay footage. That choice does not prevent analysis of what independent journalists observed and what the documentary record establishes.

References and Further Reading

Court Records and Official Materials

Blockchain Investigations

Eyewitness Reporting, Legal Coverage and Security Research

Editorial currency note (October 8, 2026): This is a time-sensitive investigation. Court proceedings, security indicators, token balances, authenticity assessments and Rockstar’s release plans may change. The evidence classifications above reflect material publicly accessible by the stated review date, not a claim that private or sealed investigations have concluded.

Cite this article

Published October 8, 2026

Think something here is wrong, incomplete, outdated, or insufficiently supported? You can challenge a factual claim, source, interpretation, missing context, or privacy issue.

Learn How the challenge process works


More to think on...