GTA Online has its own Dark Souls-style critical security vulnerability on PC

ski mask guys stealing money with a money print background
(Image credit: Rockstar Games)

Update: Rockstar has acknowledged "potential new exploits in GTA Online for PC" in a tweet from its support account, and says it will address them in a security-focused update.


Original story: The Rockstar Games-focused account Tez2 recently shared evidence of security vulnerabilities in Grand Theft Auto Online. A number of players have reported account progress being reversed, as well as being kicked or blocked from joining games on PC. There is a pinned post on the GTA Online subreddit dedicated to the issue and bringing it to Rockstar's attention, and the developer Speyedr, who created the custom GTA 5 firewall tool Guardian, warns that modders using the exploit are on the verge of achieving remote code execution through GTA Online, meaning that hackers could remotely activate malware on PCs running the game.

Tez2 has reported that Rockstar is aware of the issue and working on it, and we have reached out to Rockstar for comment.

The initial exploit as described by Tez2 allows a modder to take away another user's rank and in-game money, completely reset their account's progress, or even "corrupt" it in such a way that they are effectively banned from online play in a manner similar to the old Dark Souls item hacks

One user on Twitter, @Bulkiboy, demonstrated being immediately kicked from their own GTA Online session after unlocking their Guardian firewall. Another, @Fluuffball, showed off gameplay from a purportedly "corrupted" account. Whenever connecting to GTA Online, the camera would zoom up into the air and just stay there, never connecting to the game.

As a fix for corrupted accounts, Tez2 stated that deleting the Rockstar Games folder from My Documents, then launching GTA Online should refresh profile data. Of course, until there is an official response from Rockstar, it's probably best to avoid GTA Online altogether.

Tez2 describes the exploit as "partial remote code execution," with the potential for further security-compromising advancements from hackers. Guardian creator Speyedr, meanwhile, seems to believe that the development of full remote code execution through GTA Online is imminent. 

Speyedr's tool, Guardian, could potentially guard against the exploit, but the developer does not want users, especially those who may not know how to deploy it properly, taking the risk. Speydr has temporarily removed Guardian's files from GitHub, and encourages players to stay away from GTA Online until the issue is resolved.

The entire situation is highly reminiscent of the remote code execution vulnerability that led Bandai Namco to take down the Dark Souls series' multiplayer servers for over half a year. Similar to Speyedr and Guardian, Dark Souls has the Blue Sentinels security tool, and networking-savvy players discovering and reporting on the vulnerability is what spurred Bandai Namco to action. We will have further updates on the GTA Online story as it develops. 

Associate Editor

Ted has been thinking about PC games and bothering anyone who would listen with his thoughts on them ever since he booted up his sister's copy of Neverwinter Nights on the family computer. He is obsessed with all things CRPG and CRPG-adjacent, but has also covered esports, modding, and rare game collecting. When he's not playing or writing about games, you can find Ted lifting weights on his back porch.

Read more
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
GTA 5 characters
GTA 5 publisher takes legal aim at account-selling site for allegedly raking in 'millions in revenue', while recruiting hackers to keep its cogs turning
GTA 4 - Niko Bellic
GTA 5 mod recreating GTA 4's map nuked after 6 years of work because people noticed, and Rockstar insisted on a 'friendly takedown', if you know what I mean
Grand Theft Auto 5 Enhanced screen - Trevor setting fire to somebody's big dumb truck
Grand Theft Auto 5 Enhanced launch is going poorly or well depending on how you look at it: It's got a 'mixed' rating on Steam and is one of the most-played games
Michael sunbathing in GTA V
3 years later, GTA 5’s Enhanced edition finally comes to PC, and it’s somehow 22GB smaller than GTA 5 Cool Original flavour
Grand Theft Auto 5
GTA 5's next-gen update finally has a March PC release date a mere 3 years after it prettied-up the console versions
Latest in Grand Theft Auto
GTA 5 characters
GTA 5 publisher takes legal aim at account-selling site for allegedly raking in 'millions in revenue', while recruiting hackers to keep its cogs turning
GTA 5 Enhanced
Grand Theft Auto 5 Enhanced is a bitter-sweet return to Rockstar's money-making machine
Grand Theft Auto 5
How to transfer your GTA 5 save file to GTA 5 Enhanced and accept Rockstar's Online Policies if needed
Grand Theft Auto 5 Enhanced screen - Trevor setting fire to somebody's big dumb truck
Grand Theft Auto 5 Enhanced launch is going poorly or well depending on how you look at it: It's got a 'mixed' rating on Steam and is one of the most-played games
GTA 5 Enhanced Edition
What's the difference between Grand Theft Auto 5 Enhanced and Legacy?
GTA 5 money
The Grand Theft Auto series has now sold over 440 million copies, and say g'day to Rockstar Australia
Latest in News
spectre divide
Spectre Divide and its studio are shutting down after just six months: 'The industry is in a tough spot right now'
Naoe looking at the wrist blade in Assassin's Creed Shadows
Ubisoft backflips, says Assassin's Creed Shadows will support Steam Deck at launch, but I doubt I'll actually want to play it there
Henry from KCD2 wearing nice outfits
'Diversify your fashion endgame' with this Kingdom Come: Deliverance 2 mod that gives Henry fly new gambesons, pourpoints, and caftans
Masked Counter-Terrorist in helmet in forefront with sunglasses and beret-wearing CT in background touching headset
There's hope yet for Classic Offensive after its Steam rejection: The team behind the Counter-Strike 1.6 revival mod is in touch with Valve about its 'concerns'
Recently appointed Intel CEO Lip-Bu Tan.
Here comes Intel's new CEO: a semiconductor veteran that won the same prestigious award as Jensen Huang and Lisa Su
BURBANK, CALIFORNIA - AUGUST 15: Protestors attend the SAG-AFTRA Video Game Strike Picket on August 15, 2024 in Burbank, California. (Photo by Lila Seeley/Getty Images)
8 months into their strike, videogame voice actors say the industry's latest proposal is 'filled with alarming loopholes that will leave our members vulnerable to AI abuse'