Wallets associated with the CYBERLEEK memecoin reportedly moved about $350,000 in liquidity provider fees after unauthorised footage from GTA VI attracted attention to the token, according to onchain analyst Conor Grogan.
Grogan said on 1 September that the funds had passed through several over-the-counter (OTC) providers. He linked the wallets to the person or group behind the GTA VI leaks, although the identity of whoever controlled them has not been publicly confirmed.
The analyst said the money appeared to have been generated entirely through liquidity fees, rather than by the operator selling a large holding of CYBERLEEK directly on the market.
Take-Two Interactive, the parent company of GTA VI developer Rockstar Games, is separately seeking information through federal court subpoenas in an attempt to identify accounts involved in publishing and distributing the leaked material.
CYBERLEEK launched on the Solana blockchain on 15 August, according to publicly reported blockchain data. The token gained attention after an online account using the CyberLeek name posted previously unseen footage from GTA VI.
A liquidity provider places token pairs into a pool on a decentralised exchange. Traders can then use that pool to buy or sell an asset, with transaction fees shared among liquidity providers according to the rules of the platform.
Grogan said the operator of CYBERLEEK benefited from that arrangement. Each new release of unauthorised GTA VI footage attracted more attention, while the resulting increase in trading generated additional fees for the wallet supplying liquidity.
That method meant the operator did not have to sell most of its original liquidity position. Instead, the wallet could continue collecting fees as traders exchanged CYBERLEEK through the pool.
Grogan described the case as the first he had observed in which a suspected hacker earned money solely from providing liquidity, rather than making a profit by dumping a token on the market. His conclusion is based on his analysis of wallet activity and is not a finding by a court or law enforcement agency.
Blockchain records can show transfers, liquidity positions and fee withdrawals. They cannot independently prove who controlled the wallets, or whether the same person obtained and released Rockstar’s copyrighted files.
The individual or group behind the CyberLeek account remains unidentified. No court document, police statement or announcement from Rockstar has publicly connected a named person with the wallets examined by Grogan.
For that reason, describing the wallet controller as the “GTA VI hacker” goes beyond what has been established. The available evidence shows that the CyberLeek alias distributed unauthorised footage and promoted a token with the same name.
Grogan said the $350,000 was routed through several OTC providers. Such services can allow two parties to trade assets directly without sending the entire transaction through a public exchange.
The use of an OTC provider does not, by itself, prove money laundering. Grogan used the word “washed” to describe the movement of the funds, but no regulator or court has ruled that the money represented criminal proceeds or that any provider knowingly processed illegal transactions.
That distinction is important because blockchain investigations often depend on transaction patterns, address labels and links between wallets. Those techniques can suggest probable relationships, but may not identify the ultimate beneficial owner.
The alleged arrangement is similar to other memecoin models in which locked or retained liquidity continues to generate income for a token creator. A pool can remain available for trading while the operator withdraws accumulated fees, meaning it is not necessarily necessary to remove the liquidity or sell a substantial allocation in order to profit.
Take-Two seeks information
Take-Two filed requests for Digital Millennium Copyright Act subpoenas in the U.S. District Court for the Southern District of New York on 20 August.
One case, listed as In re Take-Two Interactive Software, Inc., case number 1:26-mc-00421, sought information from Microsoft. The court docket identifies GitHub as the Microsoft service that allegedly hosted copyrighted GTA VI material.
Take-Two said the disputed content included proprietary software, audiovisual material, artwork, images and dialogue from GTA VI. The company requested information that could help identify the alleged infringer or infringers.
Separate requests made to Microsoft and Discord sought account identifiers, registration details, IP addresses, telephone numbers and some device information linked to accounts that may have distributed or discussed the leaked footage.
The orders required the companies to provide the requested records by 4 September. Microsoft said it was working with Take-Two and Rockstar to protect their intellectual property.
Discord said it would assess the validity and scope of any subpoena before responding. On 25 August, the company said it had not yet been served.
The release of account information would not prove that an account holder hacked Rockstar, infringed copyright or committed another offence. The records could help Take-Two establish who operated an account, but further evidence would be required to show who obtained the footage.
Rockstar addressed the latest leaks publicly on 26 August, calling the unauthorised release “heartbreaking” for the developers who had worked on the game.
The company said the footage was not the way it wanted the public to see GTA VI after years of development. Rockstar nevertheless went ahead with its planned extended presentation on 27 August and did not change its marketing schedule.
CyberLeek had posted clips showing driving, combat and interactions involving GTA VI character Jason. The material appeared to have come from an unfinished version of the game, although Take-Two has not publicly explained how the files were obtained.
The incident is separate from Rockstar’s 2022 security breach, during which development footage from an earlier version of GTA VI was published online. The person convicted in connection with that breach has not been publicly linked to the current CyberLeek operation.
Rockstar has not said that the latest leaks affected the development timetable for GTA VI. Its official newswire lists the extended presentation released after the unauthorised clips appeared.
Grogan’s analysis illustrates how interest in leaked material can be turned into trading revenue without the creator carrying out a conventional token sale.
Memecoin prices can move sharply when an online event draws traders. Liquidity providers benefit from increased transaction volumes because each swap can generate a fee, regardless of whether the people buying or selling ultimately make or lose money.
The structure can also create an incentive for a token operator to maintain controversy. Further footage may generate more attention, and greater attention can increase trading activity and the fees collected by the wallet providing liquidity.
Locked liquidity does not remove that incentive. A pool can continue operating while its creator claims the fees that build up over time.
Grogan has not published evidence showing that the entire $350,000 was converted into fiat currency. His analysis showed funds moving through OTC providers and described the activity as a cash-out.
The next confirmed development may follow the 4 September subpoena deadline. Records from Microsoft or Discord could help Take-Two identify people connected with the accounts, although the information may remain confidential while the company investigates.
For now, the blockchain evidence supports the conclusion that wallets linked to CYBERLEEK collected and moved substantial liquidity fees. It does not establish the legal identity of the person controlling those wallets or prove who obtained the GTA VI footage.
