Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency

A hacker calling themselves “CYBERLEEK” has been leaking gameplay footage from GTA 6 ahead of its official reveal this week – but they’re not asking Rockstar Games for a ransom. Instead, they’ve launched their own cryptocurrency, promising to release ever more juicy clips from a virtual strip club…
Meanwhile, your smart TV might be doing more than binge-watching Netflix while you sleep. We explore the shadowy world of “residential proxies” – how they end up inside home routers, smart TVs, and IoT devices, and why an entire criminal economy is quietly running through your internet connection.
All this and more in episode 482 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Paul Ducklin.
0:00
0:00
Show full transcript
▼
This transcript was generated automatically, probably contains mistakes, and has not been manually verified.
We’ll be hearing more about them later on in the podcast. This week on Smashing Security.
We’re not going to be talking about how Iranian hackers managed to shut down a UK power plant.
And we won’t even mention how the Toxic Panda Trojan is quietly taking over Android phones to steal banking PINs and passwords.
Now, Duck, what are you going to be talking about this week?
Well, ThreatLocker puts default deny and least privilege between the agent and its next action.
So application allowlisting controls execution, ring-fencing restricts what trusted applications can access or launch, and privileged access management removes unnecessary elevation.
It makes getting them right considerably more urgent.
It’s all about a life of crime. It has earned over $8 billion — billion with a B — since it launched in 2013. It’s made more cash than any Hollywood movie.
It’s still being played by millions of people more than a decade later. And that’s really a testament to how much people love this game.
And also, I think, it really underlines how desperate people are now, some 13 years later, for a sneak peek of its sequel, which is GTA 6.
It is gonna be finally released, they promise, this November.
Well, Thursday this week, actually the day that this episode airs at 3:00 PM Eastern time, amongst much hoopla, Netflix will be exclusively premiering a first look of GTA 6’s gameplay ahead of its official release.
So I think the preview will be up for about 24 hours or something.
Maybe younger listeners would be able to educate us as to whether that’s possible or not. At the very least, I’m sure there’ll be videos to watch of it.
And people are very excited about this ’cause it’ll be their first chance to see GTA 6. No, it won’t. No, it won’t, because someone has beaten them to it.
A hacker or a group, no one’s quite sure. A hacker called CyberLeak has started to drop—
So they’ve been putting out video clips of game characters driving around the streets of Grand Theft Auto.
They’ve been swimming, they’ve been visiting strip clubs, they’ve been tasering each other.
There’s a lot of very bad language.
Or is it someone who’s taken some other footage which may have leaked out in the past? Because there have been other leaks which have come from GTA and Rockstar Games before.
At one point, what CyberLeak actually does in this clip which he shows, he shows himself, or rather his in-game character, evading the police.
And then he takes his gun and he sort of shoots the word leak, L-E-A-K — I apologise to any English teachers who are listening to this — into a wall as if to prove it really is him playing it.
Now, this would normally be a story of a hacker breaking into a company and the company, you know, sort of saying, oh, that’s terribly embarrassing, and scrambling around to sort of fix the damage afterwards.
It appears that they also wanted cash, but not through extortion, which you would expect, you know, Grand Theft Auto and Rockstar Games wallowing around in cash.
So they created their own cryptocurrency called CyberLeak, and they announced that every time someone buys or sells some CyberLeak cryptocurrency, obviously CyberLeak, the hacker, they’re gonna get a cut of the trading fees because of how they’ve set it up, right?
So they’ve set it up on Solana, I think is where they’ve got it.
And to incentivise you to buy and sell CyberLeak cryptocurrency, they’ve said that if the market capital of the CyberLeaks cryptocurrency hits $3 million, they will release a clip from inside the Grand Theft Auto strip club.
And this was all to the hackers’ financial advantage because they’re getting some of the money.
They’re not only getting a cut of the trading fees, but apparently they also have something like 27% of all of the CyberLeak cryptocurrency themselves anyway.
So if the price of CyberLeak, the crypto, goes up, that’s more money in their pocket.
They’re subpoenaing, if I could say that, subpoenaing. Am I saying that correctly? It’s too difficult for me.
They’re trying to get this information taken down and they’re trying to grab the information as to who the hacker is as well, because there’s an Xbox link.
I think there’s also been some email addresses. There’s been setting up of websites as well.
The hacker claims, they said, look, ’cause some people online, you can imagine what a fervent community there is who are really into Grand Theft Auto.
Well, I mean, for goodness’ sake, they could have done it more cheap than that, but also the cryptocurrency in the first place.
And they said that within a couple of days they made about $50,000 just from the trading fees. So they have been making money.
It appears, although the value of their stash was being pumped up by all these other transactions, they’ve actually destroyed their entire stake.
And many people are speculating that they’ve done this because the heat was rising in the community and maybe from law enforcement as well.
And they’re sort of worried that, hang on, maybe what I did wasn’t quite as cool and groovy as I imagined.
These videos, by the way, they all contain the QR code, which will take you to CyberLeak’s website where you can go and get the cryptocurrency.
So they appear to have destroyed — that’s their word, at least — their entire stake worth something like $1.4 million of CyberLeak crypto.
I mean, frankly, is there anything legitimate which is ever happening with cryptocurrency? It does appear that the default is either crime or just some extreme shadiness.
This was all about boosting the price of the cryptocurrency. According to the hacker, they weren’t in it for the money.
And instead what they said was they were trying to lobby for Rockstar Games to release GTA on a physical disc rather than making it only available via download.
Now also put it on a CD where I can take it away and study it infinitely at my leisure. That seems to be more specious than I didn’t intend to make money.
I mean, okay, apart from the fact that they’ve done the breach.
I’m not saying I got it illegally. If you like it, pay me a fee.
I mean, I don’t like the sound of it, but is it actually as devious as selling someone a VPN they don’t need that won’t work? Yeah, it’s an open question, isn’t it?
And inevitably you’ve got to wonder, I don’t think this is the case, but you have to wonder, is this to the benefit of Grand Theft Auto overall because it gives them even more headlines?
I’m sure they’d want to manage properly their launch, but—
And certainly they were launching and they were promoting the cryptocurrency before they released any of the images, before they started talking about the physical disc, which they wanted Rockstar Games to distribute the game on.
And you could also request specific clips of gameplay footage.
They were saying, for instance, if you pay them 400 Monero, for instance, which is a type of cryptocurrency worth about $160,000, you would have, I don’t know, images of the submarines or strippers on the submarines or whatever it is that would be your particular niche.
We’re offering to sell it to you privately.
Advertising on their site, that’s one thing, but hey, we’ll sell you somebody else’s intellectual property is, well, you’re going up against Rockstar North, right?
They said, look, they’re perfectly happy with gambling ads and they’re perfectly happy with adult content, but they didn’t want any scam ads.
So if you were a scammer, you weren’t allowed to advertise on their site. He’s got some standards. I think you’ll agree with that. Clearly Rockstar Games aren’t happy.
They are asking for information from some internet companies, trying to identify who may be responsible. And also there’s the cryptocurrency lead as well.
So to set up his cryptocurrency little operation, CyberLeaks had to use a vendor that requested a government-issued ID.
But it does mean that sometimes law enforcement can be successful. They don’t necessarily need to break encryption.
They don’t need to necessarily deanonymise a cryptocurrency wallet in order to get information about you. They may just have to go to a company and get your ID.
It’s sort of put a little bit of a blemish on the announcement which they’re making this week with their trailer launch on Netflix.
It’s not the first time, of course, they’ve had trouble with the Grand Theft Auto games.
It’s almost as though they can’t lose.
But yeah, back in 2022, a teenager who was a member of the Lapsus$ hacking group broke into Rockstar Games, leaked 90 videos of Grand Theft Auto 6, obviously an early development version of the game.
He was caught by the cops and they obviously didn’t want him to do any hacking while he was on bail.
They shoved him into a hotel and said, look, you’re not allowed to go on the internet.
It later turned out that he did manage to get on the internet, and even though he didn’t have a computer or anything like that, he managed to exploit the Amazon Fire TV stick plugged into the back of a TV in order to get online.
In that particular breach, Rockstar claimed that they had lost $5 million to that particular individual, who I think is still being held.
But it’s a company which doesn’t seem to really know how people are breaking in. I mean, that’s actually the most important thing of all, isn’t it?
What is being done to prevent these hacks from happening and to make sure that it doesn’t happen again?
And oh my goodness, they’ve been looking into ransomware attacks across Europe for the last year and a half or so.
And this report from Black Kite breaks down exactly where the attacks are hitting hardest and which hacking groups are responsible.
Instead, they’re being caught in the blast radius of an attack on one of their suppliers.
They got hit and that ended up causing huge problems at hundreds of organisations, exposing the data of over a million people.
And it seems that we’ve adopted that word even though it sounds fairly neutral and it’s not actually clear what it means.
And therefore it can’t possibly be clear how you’d know whether you had one of these. And if you did, was it good, bad, or indifferent?
And if it was bad, what on earth would you do about it?
So in network terms, that term was borrowed as a metaphor to refer to a computer service, like say a web server, that instead of actually being the web server you want to visit, you visit the proxy and you tell the proxy what you want to access.
And the proxy goes and fetches the content and gives it back to you.
And originally the idea of that was all supposed to be a great idea to have a gateway proxy or a company proxy, because it means that firstly, the company can limit the sites that you go to, if they’re legally obliged to protect you from gambling sites or porn sites in work hours by forcing you to use a proxy, it means the proxy can go, no, you can’t go there.
You can’t go there. Oh, that site’s got malware on it. You can’t go there.
So obviously you could use it for bad.
If you had a proxy that you snuck onto a company network that people didn’t know was there, they might go to one search engine and end up being fed results from another.
So you can use proxies for bad as well. But in general, as a term, it’s neutral. So that leads us to the point, well, what do we mean by a residential proxy?
And then that leads to the question, why on earth would anyone install one of those? Well, I have what I would call a residential proxy at home.
And the idea is then when I’m on the road, whether I’m out of the country or just in the coffee shop, let’s say I want to do something like online banking or I want to pay an electricity bill and I want them to see that I’m coming from my usual location.
I can connect securely using SSH back to my home network and then I can go out on the internet.
And in fact, in browsers like Firefox and Chromium, you can go in and say, use a proxy, and you can explicitly say, I want to use this particular proxy.
So obviously Google and Firefox think it’s a good idea to have proxies.
And that, Graham, is where the story gets both devious and interesting at the same time.
But what if you could be lured into installing exactly the same sort of software, not on your laptop, where if it goes rogue, your antivirus or your EDR software might detect it and block it.
So it may be constantly connected to the internet, whereas your laptop, you know, you shut it, you turn it off, and it can’t be abused in that way.
And you’d expect it to go online to download updates and security patches and notifications for the TV programs coming up that you’re interested in.
So you kind of expect your smart TV to be online.
And especially if we move away from smart TVs for a moment, the thing that really is on all the time and in theory has all the bandwidth it can possibly have is your home router.
The thing that sits between you and the internet.
You can’t run your own software. Even if there were such a thing, you would not be allowed to install an antivirus on it to scan for rogue software.
And the one thing you can be sure with your router, it has all the bandwidth at its disposal all the time because that is its job.
For their customer service department.
They want to try and make it resilient to things like rogue, unexpected residential proxies and other malware being injected onto it.
And they want it to stop you messing with it and authorising access in ways that they don’t like. So you’re right.
Not only is it difficult to meddle with it, the idea is that you cannot. And even if you were to find a way to hack it, it’s probably against the terms and conditions of service.
And if they find that out, A, they can cut you off, or B, they’ll just push out a firmware update and undo all your changes.
If you were a regular homeowner, what would be the thinking behind that?
One is that there is allegedly a legitimate market for these so-called residential proxies where you agree to install this software, maybe in return for free content, maybe in return for some modest discount against some other service.
Maybe even in return for money that gets paid to you in some way for installing this on your smart TV.
But you don’t get to choose who those people are, and you don’t necessarily know that much about the company you’ve entered into this agreement with for installing the software.
You’re getting some nebulous benefit. Oh, you get free games or you get access to some TV channel or other.
I know people who have got these dodgy sticks plugged into their TVs, which give them, for instance, access to Premier Football matches or something without paying a subscription.
Or maybe it gives them access, I don’t know, to some of the streaming services.
And even Apple’s much-vaunted App Store and Google’s Google Play, if you have an Android-based smart TV, even they get poisoned by malware, even though they’re supposed to have protection on.
Right?
Basically, you just install our app and it will provide fun games that your kids can play free, or it’s got these fantastic games that your kids can play. It’s $3 a month.
But if you turn on this super special option that allows us to share your internet connection when you are not using it, unquote, then you won’t have to pay the $3 a month, something like that.
Maybe this is mentioned in the terms and conditions, maybe it’s not.
It could be that you are buying from some dodgy website, something to circumvent Netflix or Apple TV in order to give you access to the latest streaming TV shows.
And you may be unknowingly opening a residential proxy. So who wants to use a residential proxy?
I can understand that people may have them, may even not know that they are operating inside their home, but who are the people actually exploiting it and using it?
What are they doing with them?
And they really do list 24 of them. It’s not just clickbait. Well, it is clickbait, but they list all these services.
And one of the things that I think that supposedly legitimate companies claim they want to do with this is things like online surveys, web scraping.
So they want to maybe look through competitors’ websites, and maybe they want to be able to do it from 20 different people in a night and see if they get different results.
Maybe they want to see, hey, this competitor of mine, what are their special offers of the day in England, Scotland, Wales, Ireland, Netherlands, Belgium, etc., etc.
So there are all sorts of quasi-legitimate reasons why you might just want to buy service from somebody else, right? In the same way that you buy a VPN service. Yes.
Which we can come back to in a minute. Yes. Because that’s the dodgy side of how you might get one of these.
Where a botnet, which is launching maybe a distributed denial of service attack—
But suddenly this is happening from lots and lots of people’s home addresses. Absolutely.
And some of these residential proxy networks apparently number into the millions.
So as far as the person receiving the ad click, it couldn’t look more legit.
It’s basically just, hey, look at this.
And you could time the clicks so that they seem legitimate and you could follow them up with visits that look as though the person then clicked through from the ad to further action and all sorts of stuff.
And that’s before you’ve actually stolen anything.
And you paid a fee so they actually earned money and it did actually work.
And irony of ironies, if you use this VPN on all of the computers on your home network, all of your traffic, wherever you did, whether you were a crook or not, would appear to come from somewhere else.
And the only traffic that did come from your home network would be traffic that had come from crooks who’d bought the service the other way around.
And from the person who sold you the VPN in the first place, if you don’t mind. Put that in your pipe of irony and smoke it. Absolutely crazy.
I mean, from the legal point of view, if they’ve got a TV and if they install an app and it happens to have a residential proxy on it, which is used by people to commit ad fraud, it’s not the owner of the TV who’s committed the ad fraud.
I guess you could argue that they’ve somehow abetted the act of ad fraud, for instance? Yes.
And I imagine it would be somewhat hard to prove that the user’s intention was to aid and abet cybercriminality.
And so you should be running a tight ship inside your home.
Like you should do it because you don’t want other people in your neighbourhood, in your country, on the internet, in your online TV community to get screwed over by people who are using your device to commit crimes.
But at the same time, you don’t want to be in the firing line on behalf of that crook.
Because after all, if somebody is criminal enough to want to sneak a residential proxy into an app you install and then sell it to other people for cybercrime purposes, it would be foolish not to assume that they might want also to spy on you, to stalk you, to do creepy things to you, to steal your cryptocurrency wallets, to monitor your browsing habits, et cetera.
So it’s almost as though the residential proxy thing is a kind of warning.
And the whole thing involves chasing down evidence, filling in questionnaires and forms, updating the same spreadsheet cells over and over again.
So no more staring at the ceiling at 2 AM wondering whether you’ve got the right controls in place or whether one of your suppliers has been breached.
But this Vanta solution uses AI as well, and it’s the useful kind, flagging risks, collecting evidence, slotting into the tools your team already uses.
So you move faster, scale without the headaches, and perhaps actually get some sleep. Go to vanta.com/smashing to find out more.
Doesn’t have to be security related necessarily. Well, my pick of the week this week is not security related.
My pick of the week this week is a little website which my darling wife found and she pointed me towards and she said, this is a bit of fun.
Why don’t you go and have a play with this? It is a website called timeguesser.com.
That is timeguesser with 2 Es, one at the end of time, one sort of halfway through guesser, but not just before the other. Anyway, this is a site where you can play a little game.
What it will do is it will show you a historic photograph taken at some point in history, one can assume since the invention of the camera, and somewhere in the world.
So Duck was looking at a picture of some old cars in the flooded streets of Zagreb, which happened in 1964.
Duck, what’s your pick of the week?
And yeah, it was published about 20 years ago, but it’s dealing with stuff from ancient history until fairly recently.
And it is called Scientific Curiosity, by a chap called Cyril Aydon.
Obviously, there are scientists that everybody’s heard of. You know, there’s Aristotle and there’s Eratosthenes, and of course there’s Sir Isaac Newton.
But there are also lesser-known people like country vicars who just got into science during the Enlightenment, who came up with ideas that were way ahead of their time and were laughed at and then turned out to be correct, particularly on things like dinosaurs and stuff like that.
Is this something which you can sort of dip into and enjoy briefly? Is this something which is quite an accessible book with all its little tales?
So it’s called, as I said, Scientific Curiosity, but the subtitle is Everything you want to know about science but never had time to ask.
And then he has a little essay about what made him curious about science.
And it says, this book can be read straight through as an introduction to 2,000 years of scientific discovery, but readers who prefer to treat it as a lucky dip will, I hope, find interest wherever they open it.
The book does not assume any prior knowledge of science or of mathematics, and there is only one formula in the book. Can you guess what it is, Graham?
And that’s that a small amount of mass gets multiplied by a truly enormous — okay, so that’s Scientific Curiosity by Cyril Aden. Indeed.
I’m sure lots of our listeners would love to find out what you’re up to and follow you online. What’s the best way to do that?
So if you would like to hire me or just see some of the stuff I’ve done in the past, please find me at pducklin.com/about or go onto your favourite social media site, whether it’s Mastodon, Facebook, LinkedIn, and look for Paul Ducklin.
You will find me fairly easily.
Follow Smashing Security in your favourite podcast app such as Apple Podcasts, Spotify, and Pocket Casts.
For episode show notes, sponsorship info, guest lists, and the entire back catalogue of 482 episodes, check out smashingsecurity.com. Until next time, cheerio. Bye-bye.
And we should also thank those brilliant people who are patrons of the podcast. So enormous thanks to them, including brand new sign-up Paul Davis, the mysterious L.
More power to them. Dan H, who’s keeping things admirably concise with just a nibble of four characters there. Cheers to Alex Tasker and Sharon and to S.K.
Very special thank you to Sabahatin Gukalukoglu. Oh my goodness! A name of such enormous complexity that I am genuinely in awe.
And after reading it out, I feel like I really need to lie down. Big love to William Sabados and to Ask Leo, who arrives with their own exclamation mark.
And finally for this week, Louis, who is rounding things off with characteristic one-name efficiency.
Those are just a few members of Smashing Security Plus, which means they get their episodes ad-free earlier than the general public, and they can have their names pulled out at random to be mocked at the end of the show.
If you’d like to join Smashing Security Plus, just head over to smashingsecurity.com/plus for all of the details.
And even if you don’t do that, you can still do me a favour by leaving a five-star review, liking the podcast, subscribing to it, and tell your friends about it.
That really does help. Well, until next week, cheerio, bye bye.
Host:
Graham Cluley:
Guest:
Paul Ducklin:
Episode links:
Sponsored by:
- ThreatLocker – Book a demo today and start securing your organisation.
- Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
- Black Kite – Read Black Kite’s 2026 European Cyber Risk Report to explore the latest ransomware trends, top threat actors, and how supplier breaches are reshaping cyber risk across Europe.
Support the show:
You can help the podcast by telling your friends and colleagues about “Smashing Security”, and leaving us a review on Apple Podcasts or Podchaser.
Join Smashing Security PLUS for ad-free episodes and our early-release feed!
Follow us:
Follow the show on Bluesky, or join us on the Smashing Security subreddit, or visit our website for more episodes.
Thanks:
Theme tune: “Vinyl Memories” by Mikael Manvelyan.
Assorted sound effects: AudioBlocks.
