On-chain investigationSolanaOSINTGTA VI

A follow-up: the Cyberleek deployer tried to vanish. The money and the clock didn't.

Our first investigation showed the GTA VI leak was a token launch and that automated traders, not the operation, took the money out of the pump. This follow-up turns to the wallet behind the launch itself: who funded it, how the funding was hidden, and what the money and the social account leak about the person. The launch SOL was layered through a six-hop chain, held for nineteen hours, then released in a tight launch-day burst. Two independent community traces — one to a KuCoin withdrawal, one to a phishing-linked service wallet — turn out to be the same chain, which we reproduced hop by hop. Every hop was salted with look-alike decoy transfers fired within seconds by a bot. And the wallet's own timestamps, corroborated independently by the leak account's posting hours, draw a clean Central-European working day. None of this names a person, but it narrows the ground considerably.

Part I of this investigation: The GTA VI Leak Was a Token Launch. The Bots Took the Money Anyway →

At a glance
This is a follow-up to our first Cyberleek investigation, which showed the GTA VI leak was a Solana token launch dressed as a hack, and that the five wallets that took the most out of the pump were automated traders with no link to the operation. That left the real question open: the deployer. This follow-up traces the wallet that minted the coin — Hok9nbV89yBSKCttxe3goqajwbiqQa9mtHvQBsbJH3Np — back through the money that funded it, the decoys planted to stop anyone following that money, and the working hours its own transactions keep. Every on-chain figure comes from Bitquery MCP.
6 hops
From the deployer up to the exchange layer
19 hrs
The launch capital sat parked before launch day
UTC+1/+2
Timezone both the wallet and the account point to
0
Labels on any of the 15 wallets in the chain

01 — The deployerThe wallet that launched the coin

Everything in the first article happened downstream of one address. Hok9nbV89yBSKCttxe3goqajwbiqQa9mtHvQBsbJH3Np is the wallet that created the CYBERLEEK mint on August 15, seeded the Raydium pool that afternoon, and has sat at the center of the operation ever since. It is the fee payer on the oldest transaction that touches the token, roughly seven hours before the first trade.

The deployer was fed by a single wallet, Ec2qmcpCCD9hjahAcquiQf5JkZWCK68BUahCje1izYC7, with the profile of a purpose-built funnel: 57 inbound transfers from 21 different wallets, and only two outbound transfers, both to the deployer. It sent the deployer 10 SOL at 14:07 UTC, thirteen minutes before the mint, then 311.42 SOL at 20:47, twenty minutes before the pool went live. The round "330 SOL" the launch was advertised with is those two transfers plus change.

One funnel in, one deployer outthe shape that says 'don't look at where this came from'
21 source wallets
57 transfers
cross-funded Aug 13–15
Ec2qmc…
funnel wallet
deployer Hok9nb…
2 transfers
10 + 311.42 SOL, Aug 15
14:07
seed 10 SOL to deployer
14:20
CYBERLEEK mint created
20:47
main 311.42 SOL funding
21:07
Raydium pool live
A wallet that receives from many and pays only one recipient exists to break the link between a source and a destination. Everything above the funnel is what the operator did not want traced.

The deployer was not careful after launch, either. On-chain trails surfaced by traders show the same wallet funding the deployers of further tokens — two pump.fun mints via MDBLoJyK6WuymugTKojo9Sg3K3ap9e6xR1jFrjYQo4j and a coin called "Rockstar Gays" via FYzoZbGvPsHqXSe8czHgpJPiHXnFUBXoX1z8EBQKSEpA. An operator claiming to be unfindable kept reusing the one wallet that ties those projects together.

02 — A → FSix hops, one exchange, nineteen hours of patience

We walked the funnel upstream, one hop at a time, and the money resolves into a clean chain. Below the funnel sit roughly six feeder wallets that cross-funded each other on August 13–15. Above them, a single thread runs up through a set of relay wallets to a high-volume hub and, community sleuths say, to a centralized exchange. We label the wallets A through F to keep the chain readable; the full addresses are in the table.

How the launch capital movedA → F · June reservoir, August layering, launch-day release · UTC
Jun 11 · 15:03
A → B · the reservoir
BS9f2jet… sends 303 SOL up through E97saCE… into the hub J4zo…. Six seconds later, the first decoy dust transfer lands (see §03).
Aug 13 · 09:23
B → C → D · layering starts
The hub feeds 26sZ…, which forwards 156 SOL to EjsB….
Aug 13 · 11:04 → 18:47
D → E · test, then commit
EjsB… sends 2ZdU… a 10 SOL probe, then the real 146 SOL seven hours later.
Aug 13 · 18:50
E → F · into the feeder layer
2ZdU… pushes 33.5 SOL into feeder 2KxnXd…, three minutes after receiving it.
Aug 13 18:50 → Aug 15 14:07
The nineteen-hour park
The capital lands in the feeder layer and sits. Nothing moves for almost a full day. The launch was scheduled, not reactive.
Aug 15 · 14:07 → 21:07
F → deployer · launch day
Feeders consolidate into the funnel through the afternoon; the funnel seeds the deployer, the mint is created, and the pool goes live at 21:07 — twenty minutes after the main funding.
Fast automated layering on August 13, a deliberate overnight hold, then a tight launch-day burst. The gap between "money arrives" and "pool is live" is twenty minutes: the deployer was ready and waiting.

Two community investigators had reached parts of this independently, and the useful finding is that their two traces are the same chain. A GTAForums user, Vice Cit, published a route running KuCoin → FWbi → J4zo → 26sZ → EjsB → 2ZdU → funding, with amounts we reproduced hop for hop: 156 SOL into EjsB, 10 then 146 SOL out of it, the forward into the feeder. Separately, an OSINT analyst flagged BS9f2jetmcwafD2AVrZMvdSf5qrsNNqdgVRifsRHWhci as a service wallet that had also received proceeds from a June 24 phishing theft. That wallet turns out to fund E97saCE…, which funds the same hub J4zo…. One trace approached from the exchange side, the other from the phishing side, and they meet at the hub.

HopWallet
ABS9f2jetmcwafD2AVrZMvdSf5qrsNNqdgVRifsRHWhci — service/hub, 4,021 in / 1,481 out. Community-flagged phishing link.
BJ4zoc1rFgpP2Mrknb48BRRoQW9P5GiVtPyuemkKMpAnV — high-volume hub, fed in 200–380 SOL blocks. Vice Cit's KuCoin route runs through here.
C26sZDubW854zGAasvrUaRAgY54MiC97CEHWZKPRMPMQ9 — relay, forwarded 156 SOL.
DEjsB4qhcQv3zwXWqMbD739VA7nFc85f2egwTnkr3KGB2 — relay, 10 SOL test then 146 SOL.
E2ZdUUvrr7ANY2rzpbyBcZHp1hTZ5uTY8JZ4vFnYnvJhD — relay into the feeder layer.
FFeeder 2KxnXd… plus ~5 siblings → funnel Ec2qmc… → deployer Hok9nb….

We ran all fifteen wallets in the chain through the label directory in Bitquery MCP. None carry a label: no exchange tag, no known entity, no scam flag. Two limits on that. We reproduced the middle of the chain and the phishing-wallet junction ourselves, but the KuCoin terminus carries no label in the directory, because Solana exchange coverage is sparse. So "traces to KuCoin" is corroborated up to the hub and rests from there on Vice Cit's exchange-side evidence rather than ours. And an unlabeled wallet on Solana means "not labeled," not "clean."

03 — The decoysEvery hop was booby-trapped

Following this chain by hand is harder than it should be, because someone salted it with decoys. The technique is called address poisoning, and it works by exploiting one habit every analyst and every wallet user has: nobody reads a full Solana address. A real address is 44 characters of case-sensitive base58, so explorers, wallets and tools all show it truncated — the first four characters, an ellipsis, the last four. 2ZdUUvrr…vJhD. You recognize a wallet by those eight characters and trust the middle.

The attacker weaponizes that. Using a vanity-address generator, they grind out a brand-new keypair whose address happens to start and end with the same characters as a wallet you actually transact with. Then they send a near-zero "dust" transfer, a fraction of a cent, from that look-alike into the target wallet. The fake address now sits in the target's transaction history, one line away from the real counterparty and near-identical in truncated form. The next time anyone copies "the address this wallet sent to" out of that history, whether an analyst tracing funds or the wallet owner paying the same person again, there is a real chance they copy the decoy.

These are the real wallets in our chain, next to the decoys dusted in to impersonate them, with the truncated form each one displays as:

Real wallet in the chainDecoy look-alike dusted in
2ZdUUvrr7ANY2rzpbyBcZHp1hTZ5uTY8JZ4vFnYnvJhDhop E · reads 2ZdU…vJhD2ZdUMU9dsXWBtv8re3jBqw5k2SYsEhaaHgC4KTyUCJhDreads 2ZdU…CJhD — identical first four, same last three · dust tx
EjsB4qhcQv3zwXWqMbD739VA7nFc85f2egwTnkr3KGB2hop D · reads EjsB…KGB2Ejs1KFSZp3R7QNdFgRNKK3p3CwvHrTKZtRjbHhVZ5cB2reads Ejs1…5cB2 — three-char prefix, same last two · dust tx
2ZdUUvrr7ANY2rzpbyBcZHp1hTZ5uTY8JZ4vFnYnvJhDhop E, second decoy against it2Z13DB21Uw8J4gC9rdjAkYvmVGemnV4yCdW7T7o4PJhDreads 2Z13…PJhD — same last three characters · dust tx
BS9f2jetmcwafD2AVrZMvdSf5qrsNNqdgVRifsRHWhcihop A · reads BS9f…WhciBS9Fn9i1sMhF7SsLEzLriG7L4n5AgizychjwDRHFWhcireads BS9F…Whci — case-flipped prefix, identical last four · dust tx
BS9f2jetmcwafD2AVrZMvdSf5qrsNNqdgVRifsRHWhcihop A, second decoy against itBS11D9v9cDDKcp5RV2skFEMKFT8BKYs7QnHfD4Mi4hcireads BS11…4hci — same last three characters · dust tx
2KxnXdbED2btp36CZzouUiEXz5aPR38BvxZfhC3D1woZhop F feeder · reads 2Kxn…1woZ2Kx6iSb9HmqWL8ycUorSF4BDV6oZqxhc6a13L49t1woZreads 2Kx6…1woZ — three-char prefix, identical last four · dust tx
9Ve5Cgt5xzkdLnowxfFBk89R3mo5QmVrngDedqWdxxVgfeeder · reads 9Ve5…xxVg9Ve5hkrDipmrPMnEKbbErT9mDCdbsgBR7B4U5sLYyxVgreads 9Ve5…yxVg — identical first four, same last three · dust tx

Read the truncated forms in the sub-lines and the problem is obvious. The real hop E reads 2ZdU…vJhD; its decoys read 2ZdU…CJhD and 2Z13…PJhD — one matches the first four characters exactly, both match the last three. The real hop A reads BS9f…Whci; one decoy reads BS9F…Whci, differing only by the case of a single letter and reproducing the last four exactly. The feeder 2Kxn…1woZ is shadowed by 2Kx6…1woZ, again an identical tail. In a truncated display these pairs are visually interchangeable, and case-flipped characters are the hardest of all to catch by eye. An investigator scrolling the transfer list, or a script keying on prefix-and-suffix, can lift the wrong wallet and follow a dead branch that goes nowhere — while the real trail sits right beside it.

The timing shows this was botted, not hand-planted. The dust lands seconds to minutes after each genuine transfer — six seconds behind the June reservoir move, one to two minutes behind the August hops — and it reacted separately to the 10 SOL test and the 146 SOL commit, which means a watcher was triggering on the target wallet's activity in real time. Every burst uses the same template: a 0.00001 paired with a 0.000001, fired from two vanity addresses at once. And it is two-sided — into hop D the decoys imitate hop E, into hop E they imitate hop D — so whichever direction a tracer copies from, a look-alike is waiting.

⬢ Address poisoning · how the trap works
real 2ZdU…vJhD vs decoy 2ZdU…CJhD
44 chars
full address; only 8 are ever read
0.00001
dust sent so the fake lands in your history
+6 sec
fastest decoy, fired after a real transfer

Address-poisoning bots spray high-value wallets across Solana indiscriminately, so the presence of decoys does not by itself prove the operator ran the poisoner. What it does prove is that these specific hops were live, high-value targets being watched in real time, and that anyone tracing this chain by eye, as the community has been doing, was being actively misled. The effect on an investigation is the same whether the trap was deliberate or ambient: verify every address in full, never by its first and last four.

04 — The clockThe one thing they could not launder

Start with the wallets, not the social account, because the chain has a clock of its own.

Every transaction in this investigation carries a timestamp, and once you line them up, the operation only ever moves during one stretch of the day. The June reservoir transfer landed at 15:03 UTC. The August 13 layering ran 09:23 to 18:50. On launch day the seed hit at 14:07, the mint at 14:20, the 27% allocation split at 14:30, feeder consolidation between 14:22 and 16:41, the main funding at 20:47, and the pool went live at 21:07. Eleven timestamped actions across three separate days, and every one of them falls between 09:23 and 21:07 UTC. Not a single hop, mint or pool action lands between 02:00 and 08:00.

That window is the deployer's working day, derived from nothing but the chain. It is a small sample and we would not hang a conclusion on it alone. What makes it worth reporting is that a completely separate data source produces the same window.

The group's leak account posts exclusively from one device, "Twitter for Android" on every single post, and across 40 posts the hour-of-day pattern is a clean human rhythm.

When the leak account posts40 posts, all 'Twitter for Android' · counts by UTC window
22:00 – 01:00evening peak
10 posts
02:00 – 08:00silent · sleep
0 posts
09:00 – 12:00morning
9 posts
13:00 – 19:00afternoon
13 posts
21:00 – 22:00evening ramp
8 posts
A continuous seven-hour silence from 02:00 to 08:00 UTC is the sleep window. Convert it to local time and it only sits naturally in one band.

A silent block from 02:00 to 08:00 UTC, a first post around 09:00, and the heaviest activity in the late evening map to Central European time, UTC+1 or +2. Under summer time (UTC+2) the operator is asleep 04:00 to 10:00 local and posting hardest through the evening, an ordinary schedule. Push the same pattern to US Eastern and the "sleep" block lands mid-evening with a hard-posting overnight, which no ordinary rhythm fits.

Now put the two clocks side by side. The wallet chain operates 09:23 to 21:07 UTC and goes dark 02:00 to 08:00. The leak account posts 09:00 to 01:00 UTC and goes dark 02:00 to 08:00. The dead zone is identical, and the account's evening tail simply runs later than the money does, which is what you would expect from someone who stops moving funds before they stop posting.

We cannot prove from the chain that the account holder and the deployer are the same person, and we are not asserting it. Two things are true and worth stating separately. The deployer's own transaction history, on its own, describes an operator working Central European hours. The leak account, on its own, describes the same. Whether that is one person or a coordinated group, the operation runs on a Central European clock.

⬢ Behavioral fingerprint · leak account
@cyberleeeknet · created 22 July 2026
02:00–08:00
silent UTC block, 7 hours, every day
UTC+1/+2
the only timezone the pattern fits
3 weeks
account predates the domain registration

The signal is independent of everything else in this article. It comes only from timestamps, and it lands in the same place as separate claims circulating in German-language threads: that the operator is based in Germany, runs Hetzner hosting, is roughly 33 to 35, and left older blog posts and IP addresses behind. Two unrelated methods pointing at Central Europe is worth more than either alone. The account itself was created on July 22, three weeks before the domain went up, which pushes the preparation timeline back further than our first article could show.

05 — The pictureWhat the operation could not hide

Read together, the money and the clock describe an operator who worked hard at anonymity and left three anchors anyway.

Anchor 1A KYC exchange at the top
If Vice Cit's exchange-side evidence holds, the chain originates at a KuCoin withdrawal. KuCoin has required identity verification since August 2023 and has a law-enforcement request process. Layering below the exchange is moot if the source account is verified.
Anchor 2A reused deployer wallet
Hok9nb… did not stay clean. It keeps funding new token deployers, each with its own promoters and footprint — more accounts that interacted with the operator, not fewer.
Anchor 3Two clocks that agree
The wallet chain signs between 09:23 and 21:07 UTC. The leak account posts on the same schedule with the same 02:00–08:00 dead zone. Two independent sources, one Central European working day.
The catchThe trail stays live
That clock is not a one-off. Every hop, the mint and the pool creation fall inside it. As long as the operation keeps moving funds, the wallet keeps signing on the same working day.

We are deliberately not naming anyone. The German origin, the age range and the prior-identity claims are community allegations we have not verified, and this article does not publish a person, a face or a real name. What we have verified is narrower and more useful: the launch money was layered through a six-hop chain that two independent traces tie to a KYC exchange and a phishing-linked service, the chain was actively booby-trapped against anyone following it, and the operator's own account keeps a Central-European clock. The layering and the decoys defend against manual tracing; they do not touch a KYC record, a reused wallet, or a sleep schedule.

How this was done

Every on-chain query ran through Bitquery MCP

Signature history to reach the deployer's oldest transactions, full instruction traces to read individual transfers, inbound and outbound SOL transfers with time bounds to walk each hop, decoded DEX trades to confirm the pool seeding, DEX-venue and supply reads to place the token, and a batch label lookup across all fifteen chain addresses. Off-chain, post timestamps and the source-device field were read from the public account through a social data endpoint. No manual explorer clicking.

solana_signaturessolana_tx_transferssolana_transfers_intx_tradestoken_dex_venueslabels_for_addresses
Explore Bitquery MCP Data as of August 24, 2026, 13:00 UTC. On-chain hops reproduced against the amounts in the public GTAForums trace. Timezone inference is behavioral and drawn from public post timestamps.

06 — SourcesOff-chain sources

Everything about wallets, transfers and timing is on-chain data queried through Bitquery MCP. The community traces, the exchange claim and the identity chatter are public records, listed below and checked on August 24, 2026. As in Part I, this article does not link to the group's website, to any mirror of it, or to any leaked footage; the domain is not printed in resolvable form.

ClaimSource
The KuCoin funding routeKuCoin → FWbi → J4zo → 26sZ → EjsB → 2ZdU → fundingGTAForums user Vice Cit, as reported by Gameranx and Dexerto; summarized by @Okami13_, X and @StarPlatinum_, X
The phishing-linked service walletBS9f2… tied to a June 24 theft@osint_based, X, Aug 19 2026 (analyst's claim, unconfirmed)
The deployer wallet and LP mechanicsHok9nb…, 330 SOL + 730M tokens@stitchdegen, X, Aug 18 2026
Fee income and unsold supply estimates~$50K fees, ~$400K unsold at the time@Okami13_, X; @Naeven_, X
German-origin and prior-identity claimsHetzner hosting, age ~33–35, older blog posts/IPs; a prior handleCirculated in German-language posts on X (e.g. @DennisWerth_); King Julien's findings via Gameranx. Unverified.
Posting device and timestamps"Twitter for Android", 40 postsPublic timeline of the group's X account, read via a social data endpoint, Aug 22–24 2026

07 — Still openThreads we did not pull

Hok9nbV89yBSKCttxe3goqajwbiqQa9mtHvQBsbJH3Np
The exchange account behind the hub is the endpoint that matters. We reproduced the chain up to the hub and confirmed the phishing-wallet junction, but the KuCoin terminus rests on Vice Cit's exchange-side evidence, not on an on-chain label. Confirming which exchange, and which deposit, is the open question.
FYzoZbGvPsHqXSe8czHgpJPiHXnFUBXoX1z8EBQKSEpA
The deployer funded this and other side-token deployers. Each new project is a fresh set of promoters and counterparties — an untraced pivot surface.
BS9f2jetmcwafD2AVrZMvdSf5qrsNNqdgVRifsRHWhci
The look-alike decoys at every hop share a fixed dual-amount template. Whether they all originate from one poisoning-service wallet — which would separate targeted from ambient poisoning — is unresolved.

Run the next investigation in minutes

Ask any question of the blockchain. Bitquery's AI Investigations agent traces funds, attributes wallets, and writes auditable reports across every major chain.

Legal disclaimer

This article is provided for informational and educational purposes only and reflects analysis of publicly available on-chain data and public social-media records as of the dates indicated. It does not constitute legal, financial, compliance, or investment advice, nor an allegation of criminal conduct against any identified or identifiable person.

The findings describe patterns observed in Solana transaction data, in Bitquery's DEX trade index and address label directory, and in the public posting history of a social-media account. Wallet groupings and the labeling of the chain as A through F are inferences from transfer timing and amounts, not confirmed ownership. Blockchain addresses are pseudonymous. The presence of a transfer between two addresses does not by itself establish the identity, intent, or knowledge of any party.

The route to a centralized exchange, the association of a wallet with phishing proceeds, the characterization of any wallet as a laundering or poisoning service, and all claims regarding the operator's nationality, age, hosting provider, or prior identity are community allegations reported by third parties and are expressly not verified by the authors. The timezone conclusion is a behavioral inference drawn from a limited sample of public timestamps and could be affected by scheduling tools or deliberate obfuscation. This article does not name, depict, or identify any individual, and no leaked material, footage, imagery, or link to the group's website is reproduced or hosted here.

Nothing herein should be relied upon as a definitive determination of fact. Readers should conduct their own independent verification before taking any action. The authors and publisher accept no liability for any loss or damage arising from reliance on this material. All trademarks and company names are the property of their respective owners.