My investigation on the GTA 6 Leaker is done and I have emailed all the evidence to TAKE2 and Rockstar Games legal team
As much as I wanted and loved to actually reveal who we are dealing with here, full identity and all, I believe that would be doxxing. Since the way I got to this guy was through a mix of OSINT and some people familiar with the matter via TG, I don’t want anyone to get into trouble, so for now I’ll leave out personal details and how I obtained the information
One of the stronger findings links to what appears to be this guy’s personal bank account, the bank is located in Europe. It’s obviously not out of the question that the bank account in question might be stolen, but given the circumstances and some other correlations I saw, I believe we have him
Going forward, I’ll refer to him as Leeker
With the data I have provided to T2, I believe it will make their job easier when cooperating with law enforcement and help pin down the people involved (it’s not just one). Given the nature of the data I found, revealing it publicly could give the guys time to cover their tracks or alter evidence
But I don’t want to leave people hanging so I’ll share some stuff below and answer as much as I can in the comments without it being damaging
Stuff I have learned that can be shared:
-> The leeker is actually a threat actor who has previous malicious activity under a different alias
It also seems that there is genuine hatred toward this guy from the people around him. Much of my current information comes from his peers snitching after my first post
-> This leak was apparently due to a breach or an insider. Nature of how is still unknown to me, But I’ve received two different stories about this so I'll share them anyway:
1. One story I got is that leeker bought a backdoor access or some sort from someone
2. Another person told me this is somewhat related to some incident inside Rockstar a while ago
Keep in mind it’s pretty common for these crypto bros to boast and lie about their “gains” to each other, so I honestly don’t know which to believe here
-> Not related at all to the ‘Mafia 808’ group
-> I haven’t heard anything about Rockstar India being hacked unlike some other people are claiming
-> This build we are seeing here is apparently from a year ago (as confirmed in ResetEra forums), but the theft I believe happened in April 2026 and the leeker has been preparing since then
-> From what I can tell, and as I explained in one of the earlier posts, I don’t think they possess a live build. Most likely pre-recorded footage, but this is just my assumption
The voting thing they did initially was to make people want to get the coin so the market cap can grow
I highly recommend staying away from the coin. This is a literal pump and dump, don't buy into their "Fighting for gamers" bullshit. I won’t be surprised if they at some point start threatening to leak the story unless people donate to them in the poll. Even if that happens, don’t do it
That’s all I can responsibly share right now. Questions that don’t risk the investigation or the people involved are welcome in the replies
显示更多
If there were backdoors and biases hidden in open-weight models, you could count on closed-weight labs to find and reveal them.
Chelsea Gray, this is just unfair 🥶
Gray hits the SMOOTH behind the back pass to Young off the backdoor cut
LVA-TOR | NBCSN | Peacock
Tap to watch:
🚨 Threat Intelligence | On-Chain Backdoor in a Malicious TRAE Extension
Following
@Will42W’s warning about TRAE IDE extension supply chain risks, SlowMist investigated the malicious extension juannegro.solidity.
Although removed from Open VSX, the extension was still available through the TRAE marketplace as of July 18, 2026. It impersonated a legitimate Solidity plugin and acted as a cross-platform malware dropper.
Our analysis found that it:
🔹 Impersonates a legitimate Solidity extension and uses the marketplace as the initial malware delivery channel
🔹 Automatically executes after IDE startup and establishes persistence across platforms
🔹 Uses an Ethereum smart contract to store and retrieve dynamic C2 configurations
🔹 Allows attackers to update C2 endpoints and payload delivery without republishing the extension
This incident highlights how extension marketplaces can become initial infection vectors, while blockchain infrastructure can be abused for dynamic C2 management.
Users who installed juannegro.solidity should remove the extension and check their systems for potential compromise.
Full analysis👇
显示更多
Some observations on Kimi:
1. It's a very good model! I don't think its performance can be explained away by distillation or anything like that. In agentic coding sessions, it seems pretty much on par with the best public models of Q1 2026. In my fairly limited use, it also seemed very token hungry. It's not obvious to me that this model is actually that cheap to run.
2. I am personally surprised the Chinese state continues to allow the open sourcing of models this good, given potential risks. To be clear, I *myself* might be fine with models presenting this level of marginal risk being open weight, but I am surprised that China is fine with it. I suspect the reason they are is 75% explained by strategic blindness/lack of AGI-pilledness (the CCP is very Yann Lecun-y in its views of AI). The other 25% or so is their lack of compute for customer inference (making China's open-weight strategy an unintended byproduct of US export controls) and the normal Chinese strategy of aggressive exports. For the companies, as opposed to the government, the decision to open source is partially ideological and partially because they are behind, and they know that very few people would pay for sub-frontier models from China.
3. Open-weight models are inherently decelerationist, and I'm continually surprised to see the so-called "accelerationists" so excited about open-weight models. I suspect the reason they are is that they know open-weight models are effectively ungovernable, and they simply like the overall cloak of ungovernability open-weight models create over the whole of AI. It's not a bad strategy; it reminds me of James Scott's recounting of the hill people in "the art of not being governed." Still, in the end, open-weight models deter further AI capex.
4. One probable outcome of an open-weight-model-dominant world is full AI communism, which is precisely what China proposes: rather than a market product, AI is a "public good" which will ultimately be provided by the state as a kind of "digital public infrastructure." This future strikes me as a dystopian hellscape, but I've never met an open-weight models advocate who doesn't ultimately concede this is where things end. You'd be surprised how many 'accelerationists' lobbied me, while I was in government, to support an eleven or twelve-figure federally funded data center so that startups could train models at a subsidy and then give them away for free. There was no other way for AI to progress, they said. Perhaps this is the logical end state of things. Nonetheless, I find myself surprised to see supposed accelerationists excited about such an outcome. I think many of them just don't know what they're doing. Many accelerationists do not view the creation and serving of frontier models as a legitimate business.
5. I would guess that the Trump Administration will at some point realize that their best strategy here would be to create large amounts of regulatory risk around the use of open-weight Chinese models. You don't need to "ban open source" (one of the dumber motifs of AI policy discussion). You just need to direct every agency to issue soft law that creates FUD. "A Federal Reserve Advisory Bulletin found that there may be backdoors in Chinese AI models." It needn't be that well justified. You just create enough regulatory risk that every regulated enterprise backs off. You probably don't want to create so much regulatory risk that you scare off the hyperscalers from serving Chinese models; this will just drive startups to sketchier providers. There's a happy middle ground here. I'd assume they will do some version of this.
6. It's probably true that open-weight models of this capability make the world a bit more dangerous, but not so much more that you'll really notice. At some point the models will be capable enough that you will notice. "A nonliving, invisible, dangerous, and infinitely self-replicating agent escaped from a Chinese lab," you say? Color me shocked.
显示更多
I took a quick look at an undetected Linux #
backdoor# targeting #
iKuai# routers.
🐞ELF: 4e6276cc400b3b9e9616d04474b64a8fa0c35375b9673ab41a92a6d5bce72d8d
📡C2:
h/t
@malwrhunterteam
显示更多
A curious phenomenon: recently, people have been flocking to join Anthropic, while at the same time, a multitude of users are railing against the company (citing account bans, rate limiting, and built-in detection backdoors)...
显示更多
Droppin' dimes 🪙
Jess and Paige play off one another. Bueckers gets the clean pass off the backdoor cut!
Let me be clear: Candace Owens is a malignantly stupid stupid person who is a useful idiot, while some of the others are more in the greedy idiot category.
But Russia is being kinda overt about it now. I really thought they’d keep backdooring everything through their Islam/Palestine dick-riders and our local dissidents, at least until after the next election.
In case anyone isn’t aware of Russian doctrine and wants to know why there’s a rotating door of Dugin/Bannon simps taking their very best swings right now, here you go:
显示更多
Paige Bueckers 🤝 Azzi Fudd
Fudd scores on the backdoor cut courtesy of Bueckers
DAL-SEA | League Pass | WNBA Pride |
@Coach
Tap to watch: