GTA 6 Leaker Hunt: Subpoenas, Crypto and a Reddit Doorstep
Inside the GTA 6 leak fallout: CyberLeek's Solana crypto scheme, Take-Two's federal subpoenas to Discord and Microsoft, the Reddit doorstep investigation, and the full timeline.
This is a fast-moving story and parts of it — especially the last section — are single-source and unconfirmed as of publication. Treat anything dated today with more caution than anything dated last week.
Take-Two Spent Billions Gatekeeping GTA 6. Now They’re Sending Lawyers To Strangers’ Doors.
If you’ve been following the gaming internet this week, you already know the broad strokes: someone launched a Solana token four days before leaking a single video, pulled real money out of a fake consumer rights pitch, and Take-Two responded by filing federal subpoenas against Microsoft, Discord, and X. Then, this morning, a Reddit user posted video of two men showing up at his home claiming to represent Rockstar.
It’s been a chaotic week, and behind the headlines, the actual mechanics of how this is playing out say a lot about where corporate leak investigations actually go when the dust settles.
The Full Timeline
August 14 — An Arweave domain matching CyberLeek’s eventual branding gets registered. Nothing has leaked yet, and nobody in the community has heard the name.
August 15 — The $CYBERLEEK token starts trading on Solana with an initial fully diluted valuation of roughly $55,000.
August 16–17 — Two separate accounts post the contract address publicly. Almost nobody notices. Volume hovers between $4 and $2,500 an hour.
August 18 — The first leak drops on Dread: short gameplay clips of Jason and a map image of “Leonida.” Every clip carries a watermark QR code linking to the token. A manifesto goes up the same day arguing against digital preorders and paid DLC, followed by a funding pitch claiming the token isn’t a cash grab. The token runs 13x in the first hour of visibility, then does $5.47 million in trading volume over the next hour. Take-Two begins issuing DMCA takedown notices within hours.
August 19 — Additional clips circulate. Community analysts reviewing the files notice inconsistent build metadata — one clip features an audio stem from late 2024/early 2025, while another video file was encoded using older 2023 software. Take-Two’s IP team files a DMCA takedown against a GitHub repository that was cataloguing the file forensics.
August 20 — Take-Two files federal subpoenas in the Southern District of New York against Microsoft and Discord, targeting three servers by guild ID and several online handles (CYBERLEEK, CINEMATICROCKSTAR, Surfer24k), with a return date set for September 4. A “Hypercar” clip surfaces the same day. Australian streamer Matthew “DarkViperAU” Judge is named in the filing due to an associated server; he quickly posts that he has no connection to the group or the leaks.
August 21 — Take-Two’s share price drops from $248 to $231.60, erasing roughly $2.83 billion in market cap across 48 hours. X user KINGJulien claims to have traced CyberLeek’s real identity to a European account and states the findings were passed to legal counsel. On-chain analysis from Bitquery indicates that the five wallets capturing the bulk of early trading profits bought within a tight six-minute window, capturing roughly $158,000, with heavy participation from automated MEV bots rather than the token deployer’s primary wallet.
August 22 — CyberLeek’s primary site and Telegram channel go offline. A clip showing an interior club scene continues circulating via re-uploads. Rumors begin circulating about an alleged “dead man’s switch” that would release full development files if an arrest occurs.
August 23 — The outlet that originally reported the dead man’s switch story retracts it after confirming the screenshot originated from a copycat account. The token spikes again regardless. A separate claim about an internal Xbox build originating from a phishing attempt against Rockstar India is investigated and determined to be fabricated. Take-Two adds a subpoena targeting X accounts.
August 24 (today) — Reddit user PilotX1970, who had posted accurate timeline predictions roughly a month prior and claimed secondhand contact with the leaker, posts video of two individuals arriving at their residence. One introduces himself as “David,” stating he represents Rockstar. Mainstream outlets have not independently confirmed whether the visitors were corporate investigators, process servers, or something else.
How the Legal Hunt Actually Works
If you set aside the social media noise, Take-Two’s actual legal filing is standard corporate discovery: DMCA notices to clean up public indexing, followed by targeted 512(h) subpoenas to identify account owners.
The filings ask Microsoft and Discord for account IDs, registration emails, IP login logs, phone numbers, connected accounts, and hardware identifiers. The Microsoft subpoena specifically targets MachineGuids and OneDrive file logs associated with GTA or CyberLeek keywords.
That detail is revealing. When a subpoena specifically asks for OneDrive synchronization logs and MachineGuids, it usually means investigators suspect assets were pulled from a shared contractor drive, a QA environment, or an employee’s synced local workstation rather than an external network penetration.
The PilotX1970 doorstep visit, if verified, sits outside the formal subpoena process. Sending private investigators to interview someone based on Reddit comments usually suggests that digital leads are still being processed and investigators are chasing whatever public breadcrumbs exist in the interim.
The Enforcement Disconnect
Take-Two has spent years maintaining one of the strictest IP protection strategies in the industry. Over the past decade, that approach has included:
- DMCA takedowns against fan-made map projects built entirely from publicly released trailer footage.
- Legal notices against modders porting older game maps into GTA 5.
- Cease-and-desist actions against parody videos and independent utilities.
The irony that many in the community have pointed out is the contrast between that level of proactive public enforcement and the reality of how these leaks occur. In 2022, a teenager gained access to internal Slack and Confluence systems. In 2026, footage surfaced with a cryptocurrency contract attached. The heavy legal apparatus functions well at policing public fan projects, but once internal files leave the perimeter, legal tools can only react after the fact.
At the same time, treating CyberLeek as a principled consumer advocate doesn’t hold up under scrutiny. The on-chain timeline shows an Arweave domain and a liquidity pool set up days prior to any leak. The anti-DLC manifesto functioned as marketing for a speculative token, and the trading data shows standard decentralized exchange dynamics: early buyers and automated arbitrage bots taking liquidity from retail buyers following the viral clip.
The Open Questions Around the Leak
Looking at the technical evidence available so far, several questions remain unanswered:
- Where did the footage originate? The gap in build ages across the clips — some showing 2023 metadata, others containing audio elements from late 2024 — points away from a single, live repository dump. It looks more consistent with localized QA packages, localization files, or vendor review reels that accumulated over time.
- Why was DarkViperAU included in the subpoena? The inclusion of a prominent GTA creator appears to stem from Discord server naming or public association rather than verified involvement. Third-party discovery subpoenas often cast a wide net across related community hubs to preserve logs before accounts can be deleted.
- How will the financial trail be handled? Unlike Discord handles or disposable email addresses, crypto wallets that interact with centralized exchanges create a KYC paper trail. Bitquery’s tracking identified initial funding transactions originating from exchange hot wallets. If those accounts went through standard identity verification, exchange subpoenas will provide far more concrete identification than chat logs.
What to Watch Next
The immediate focus moves to two key milestones:
- September 4: The response deadline for the Microsoft and Discord subpoenas. If the log data links back to identifiable accounts or IP ranges, the investigation will likely move into formal legal proceedings without much public fanfare.
- The Launch Timeline: As long as development remains on track and core story assets remain secure, the incident remains an embarrassing news cycle rather than a structural delay. If unreleased code or narrative details appear, the implications for Rockstar’s marketing rollout become much more complicated.
For now, the story sits between two parallel tracks: a very standard federal discovery process moving through SDNY, and a noisy social media cycle of copycat accounts, trading bots, and unverified doorstep videos.
Sources: Kotaku, Tom’s Hardware, Dexerto, PC Gamer, Bitquery on-chain analysis, Insider Gaming (report and retraction), SDNY court filings (Take-Two Interactive v. John Does), public statements from @KINGJulien15x and @DarkViperAU (Aug 14–24, 2026).