Steam API Fraud Dispute & PDF Generator
Fill out the fields below. Once you click the green Generate & Preview Notice button, a premium document viewer will pop up where you can download your print-ready Notice of Dispute (PDF) or copy it to clipboard.
PhishDestroy Declaration & Legal Waiver
This formal legal declaration accompanies every submission in this referral set, outlining the waiver of rights, OFAC-region access restrictions, and liability limitations.
================================================================================
P H I S H D E S T R O Y
LICENSE Β· RIGHTS Β· DISCLAIMER
Investigation: Valve Corporation / Steam
Edition: public β no expiry date, no take-backs
================================================================================
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
SECTION I β LICENSE (THE ACTUAL LEGAL PART, BUT HUMAN)
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
PhishDestroy gives up every right to this material. Zero. Gone. Done. You can
reproduce it, sell it, put your name on it, tattoo it on your boss, whatever.
No credit required, no DM needed, no thank-you card expected.
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β ONE ACTUAL RULE (yes, just one) β
β β
β Access from OFAC-sanctioned jurisdictions is prohibited. That is a β
β matter of territory and law β not of nationality and not of people. β
β Changing your Steam region does not change your physical location β
β or your legal status. No loopholes. β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
SECTION II β WHAT THIS IS AND WHY IT EXISTS
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
We will publish more about Valve than an average Valve employee knows about
themselves. That's not a brag. That's just where we ended up.
How did we get here? Funny story: Steam basically created us. It raised us on
its scammers, its support tickets, its ban evasion ecosystem β and now here we
are. No hard feelings. Poetic, actually.
For those who haven't read the origin story yet β we already met Valve's
extremely expensive European lawyers (Taylor Wessing, since you asked):
https://phishdestroy.medium.com/my-dog-vs-elite-gdpr-lawyers-the-valve-data-breach-nobody-is-talking-about-f6f7683d813d
Charming encounter. Especially given their hourly rate.
Did Valve know? Yes. Did Tyler Wessing know? Almost certainly yes. But when
you're that rich, laws are more of a vibe than a requirement, right?
That's kind of the whole answer, actually.
Steam spent years farming scammers. Not always intentionally β sometimes
scammers just got Valve's fingerprints on them by association. We're not
trying to be dramatic about it. We're trying to be precise. That's harder
for us than being dramatic, to be honest β this is just how we write.
Is this a conflict? β No.
Can it be resolved? β Yes. But we're not signing any NDA and we're
not playing bug bounty for pennies.
We waited over 4 years for them to fix the spoofing issue before we could
write about it publicly. Because if we had written about it earlier, Steam
would've put on its little victim face and screamed "active threat!" and
offered us pocket change to sign a document that would've made us their
legal property forever. No thanks.
(Also: Valve itself violates NDA. Their own employees do. The ones near the
top. But sure, let's talk about ours.)
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
SECTION III β OPEN LETTER TO VALVE (SERIOUSLY, READ THIS)
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Valve: if you want this domain taken down, email us. Outside counsel is not
needed for that conversation.
For the uninitiated: Dr. Patrick holds a Master of Laws in International
Commercial Law from the University of Aberdeen and β wait for it β literally
finished his doctoral dissertation in IT law. He recently made partner at
Taylor Wessing, which is a firm whose entire business model is billing
companies like Valve obscene amounts of money to drag things out until the
other side runs out of money or patience.
We don't blame him. Rich guilty clients who pay by the hour β solid career
move. We just don't think you should be funding it.
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β THE DEAL (open offer, no lawyers needed) β
β β
β If you want the domain gone: β
β let your IT law professionals calculate its price. Take your time β β
β it is a rare asset: the only website in the world whose purchase β
β changes nothing, because everything on it already lives on IPFS, β
β in regulator inboxes, and in archives we do not control. β
β β
β 50% of whatever you pay goes to the SEAL Foundation β
β (securityalliance.org) β people who do volunteer security work β
β professionally and publish it for free. We are not affiliated with β
β them and they did not ask for this; we name them as the public β
β standard of what real volunteers look like β the standard your own β
β volunteer moderators and outsourced support failed, publicly, β
β before you had to remove them. You know the scandals. So do we. β
β β
β The rest buys the community coffee while we keep publishing. β
β That is not a settlement offer. It is a demonstration of what β
β money can't reach: the domain is the maximum Valve can obtain, β
β and obtaining it obtains nothing. The referrals continue. β
β The mirrors continue. Part 3 continues. β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Will we "damage" Valve directly? Probably not in a way they'll feel fiscally.
We're not delusional. But we will do it honestly, openly, without chasing
clout β because we don't need clout. We need the world to see what was
always publicly visible if you spent enough time looking.
We have 5 years of archives. What Valve's lawyers showed in discovery β the
data that support agents can see, the fingerprints, the paper trail they
literally handed us β is enough. We don't need to leak it raw.
β Regulators get the originals.
β Researchers and journalists get redacted versions
(victim reports, children's logins and Valve's charming support
commentary removed for obvious reasons).
Minors were among the affected accounts and were not notified. That finding sits
in the regulator package with the victim reports and credentials removed,
because it belongs in front of a data-protection authority rather than in an
article.
Also, Valve β we want to make something clear before you decide how to play
this: PhishDestroy is a community, not a person. You learned that when you
addressed legal correspondence to the community without bothering to speak with
the community β just milked it for data and banned the accounts.
The community has no conflict with Valve. We didn't go looking for this. The
scammers you grew found us. We blocked them. And here we are.
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
SECTION III-B β THE ALLIED RESOURCES (a note to Steam specifically)
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
We want to be upfront about the amplification structure, because pretending
it doesn't exist would be dishonest.
PhishDestroy, as we understand the community situation, has at least two
allied resources that will pick up this material and run with it.
What that means in practice:
β They work their own angles on overlapping subject matter.
β They are independent β they don't take our direction, we don't take
theirs. Same general topic, different methodology.
β They will NOT be activating on Part 1. They're watching.
If Valve chooses not to take down the site:
β Expect them to surface after Part 2 or Part 3.
β They'll take what's useful from our work, supplement it with their
own, and publish under their own authorship.
β This is exactly the kind of thing the license in Section 1 is built for:
the material goes where it needs to go, gets supplemented, gets
amplified β and neither we nor they owe each other attribution.
(PS for lawyers wondering about liability chains: there are none. These
resources don't receive our direction, our funding, or our data. They
read what's public and draw their own conclusions. Just like you could.)
We're not saying this to intimidate. We're saying it so that whoever is
strategising on Valve's side has accurate information about what the
information environment actually looks like.
One resource that pulls our material and supplements it would be a story.
Two resources doing it independently and reaching similar conclusions is a
pattern. Patterns are what regulators notice.
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
SECTION IV β THE MONEY, THE BANS, THE WHOLE CIRCUS
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Here's the thing about Steam banning gambling sites and scammers: it's not
enforcement. It's revenue capture. Valve pockets the money, cleans its hands,
then goes on stage and tells everyone a wholesome story about PokΓ©mon cards
and baseball.
Meanwhile Valve killed the ability to properly track skins in 2017. They even
discussed it on their own forums. Called it "anti-gambling measures." The
gambling that their own support staff were running as a side hustle β getting
paid in percentages to lift bans. But sure. Anti-gambling. Great branding.
We're going to prove that:
β Skins are more anonymous than Monero
β A Peruvian Cartel allegedly used Dota 2 skins for money movement
β Steam is functionally a sanctions-bypass machine worth ~$7B in
"trading cards" (yes, they actually said trading cards to a prosecutor)
We've got a video on the skins thing. You'll see it.
We also know:
β Reddit moderation is influenced by Valve
β steamid.uk and similar infrastructure is run directly by one Steam
developer, controlled exclusively by him and his circle
β What they can't control, they ban
Valve: if you keep playing dumb β that's fine. Your safe harbour is noted.
Google Analytics anonymises your users' IPs anyway. We see what gets deleted.
We just can't prove it cheaply enough for your lawyers to care. Yet.
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
SECTION V β THE MALWARE THING (yes we're mentioning it)
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Let's be clear about the sequence of events, because it matters.
We are not disclosing the vulnerability in the game publicly, and we are not
filing it through Steam's bug bounty. The programme requires an NDA, and
signing one would bar us from telling affected users what happened to their
accounts.
Here's what actually happened:
Our security colleagues (the ones who do this professionally) already reported
it to Steam support. That part is done. Steam has been informed through the
correct channel by the correct people.
So what are we doing? We're telling you it exists and roughly what it is,
because "Valve knows about it and is doing nothing" is a data point that
belongs in this referral.
The game is sufficiently popular. We're not naming it here. What we can say:
This is NOT the trivial CSGO variant β the one where unofficial servers
ask you to "install a driver" and you think nothing of it. Everyone in
security has seen that. This is worse.
This is closer to: RCE on server connect. As in β you join a server,
you don't click anything, you don't install anything. The connect itself
is the attack surface.
The game is not technically Valve's. Which means when this eventually
surfaces, the developer signs the NDA, takes the hit, and Valve walks
away looking like the responsible platform that "worked with" the developer
to resolve the issue. Classic Valve move. We've seen the template.
The threat is active. We've shared the technical details with other
researchers through a closed channel. We are not publishing them here.
We are telling you it exists because you β regulator, prosecutor, journalist β
should know that Valve operates a platform where this is possible, has been
informed, and the primary incentive structure (NDA + bounty) is designed to
make the researcher disappear rather than make the users safe.
================================================================================
DECLARATION AS TO USE AND RIGHTS
PhishDestroy Project & Cybersecurity Coalition
================================================================================
This declaration accompanies every submission and every exhibit in this
referral set. It is addressed to any authority, court, regulator, prosecutor,
researcher, journalist or affected person into whose hands the material comes.
1. THERE ARE NO CONDITIONS ON USE
1.1 All material produced by the Coalition in this referral β the statements of
fact, the analysis, the exhibits it has authored, the tooling, and the
findings β is released WITHOUT RESERVATION OF ANY RIGHTS.
1.2 Anyone may, without asking and without notifying us:
β reproduce it, in whole or in part;
β adapt, edit, rewrite, restructure or correct it;
β translate it;
β excerpt it without indicating that it has been excerpted;
β incorporate it into official documents, findings, decisions, pleadings,
reports or press material;
β present it as the recipient's own work or the recipient's own findings;
β use it as raw material and discard the rest;
β and pass it on to anyone else on the same terms.
1.3 ATTRIBUTION IS NOT REQUIRED AND IS NOT SOUGHT. The Coalition need not be
named, cited, credited, thanked, consulted or informed. If material from
this referral assists an authority and the Coalition is never mentioned,
THAT IS A COMPLETELY SATISFACTORY OUTCOME and the Coalition states so in
advance so that the question need not be raised.
1.4 If, on the other hand, an authority finds it more convenient to cite the
Coalition as a source, it is free to do so. The choice is entirely the
recipient's and neither course carries any consequence.
1.5 This is a WAIVER, not a licence offer. It requires no acceptance, imposes
no obligation, and cannot be breached. Software published by the Coalition
is separately released under the MIT licence; the research and findings are
released into the public domain to the fullest extent permitted, and where
a jurisdiction does not permit waiver, the Coalition grants an irrevocable,
worldwide, royalty-free licence to the same effect.
2. WHY THIS MATTERS PRACTICALLY, AND NOT ONLY AS A COURTESY
2.1 An authority may reasonably hesitate to rely on material supplied by an
outside party, for fear of appearing to act at that party's instance or of
acquiring some entanglement with it.
2.2 THERE IS NOTHING HERE TO BE ENTANGLED WITH. The Coalition asks for nothing,
is owed nothing, retains nothing, and has no expectation of any kind. It
cannot later assert a right, claim credit, complain of misuse, or object to
how the material is characterised, because it has retained no basis on
which to do so.
2.3 An authority using this material is therefore not acting for the Coalition.
It is using public information that happens to have been assembled by
someone else.
3. EVERYTHING IS OPEN ALREADY
3.1 The Coalition's work is public by default:
β the investigations are published openly at https://phishdestroy.io and
are freely readable;
β the tooling is published as open source under the MIT licence at
https://gitlab.com/phishdestroy ;
β the methodology is set out in the referral itself, at Annex A section
A.16D, including the weight and limitations of each source type;
β the Coalition accepts no donations and has published that position since
2018.
3.2 The only material NOT published is that which cannot lawfully or safely be
published: personal data of victims and of third parties, and information
that would expose a source to retaliation. That material is supplied to
authorities in confidence and is identified in the schedules of evidence.
3.3 The Coalition invites scrutiny of its own conduct on the same terms it
invites scrutiny of anyone else's, and has volunteered its own data
handling to the authorities concerned, including a request for a direction
on disposal.
4. INTEGRITY OF THE EVIDENCE BUNDLE
4.1 Exhibits are supplied with the submission or, where marked, on request
through a secure channel. They are not published at a public address and no
such address should be inferred: material of this kind is provided to
authorities directly.
4.2 Each delivery is accompanied by a file SHA256SUMS listing a SHA-256 digest
for every file supplied, together with a detached OpenPGP signature
SHA256SUMS.asc.
4.3 The signing key is published at
https://phishdestroy.io/.well-known/pgp-key.txt and on keys.openpgp.org.
Its fingerprint appears in the letterhead of every submission in this set.
4.4 Any recipient may verify at any time that a file in their possession is the
file that was sent, unaltered:
gpg --verify SHA256SUMS.asc SHA256SUMS
sha256sum -c SHA256SUMS
4.5 The purpose is not formality. It is so that, if the accuracy or integrity
of any exhibit is disputed at a later date, the question can be settled by
computation rather than by argument.
5. ON REGISTER β WHY THE WAIVER IS FUNCTIONAL AND NOT MERELY GENEROUS
5.1 The authority may encounter the Coalition's published investigations and
find them blunt, adversarial and at times satirical. That impression is
correct. The Coalition writes that way deliberately and does not apologise
for it.
5.2 IT ALSO RECOGNISES THAT THIS IS THE WRONG REGISTER FOR A REGULATORY OR
JUDICIAL PROCEEDING. A serious matter should not be carried in the voice of
a campaign. Findings put before an authority should be stated flatly, with
their limitations admitted, and should not require the reader to discount
for tone before reaching the substance.
5.3 THAT IS PRECISELY WHY THE COALITION WAIVES AUTHORSHIP. The waiver at
section 1 is the mechanism by which the substance can be separated from the
register: the authority may take what is useful, restate it in its own
voice, and discard every word of the Coalition's manner along with the
Coalition's name. Nothing is lost by doing so, and the Coalition would
prefer it.
5.4 THE COALITION ALSO ASKS THAT THE REGISTER NOT BE MISTAKEN FOR THE METHOD.
The published tone is combative; the underlying practice is not careless.
Throughout this referral, inference is separated from observation, testimony
is identified as testimony, sources are weighted and their weaknesses
stated, figures are presented with their limitations, and points the
Coalition cannot prove are put as questions for the authority rather than
as assertions. Where the evidence cut against the Coalition's own position
it has said so β see Annex A, paragraph 7, and section B.0 of the parallel
referral.
5.5 THE COALITION EXPLAINS THE CONNECTION BETWEEN ITS MANNER AND ITS FINANCES
BECAUSE THE TWO ARE NOT SEPARABLE. It takes no money from anyone β no
donations, no bounties, no clients, no sponsors. That refusal is what makes
the bluntness possible: an organisation with revenue to protect must
moderate what it says about the parties it depends on. Having nothing to
protect, the Coalition has nothing to moderate.
It is also the reason the Coalition continues to exist. There is no other
engine. The work is done because it is done; it stops when the people doing
it stop.
5.6 The authority need accept none of this. It is stated so that the tone of
the Coalition's public work is not read as a measure of the care taken with
the material now before it.
6. WHAT THE COALITION IS PROVIDING, IN ITS OWN WORDS
Information, research and observation.
Nothing is asserted as a finding that the Coalition has no standing to
make. Where something is inferred, the referral says so. Where something
rests on testimony, the referral says whose and with what limitation. Where
the Coalition cannot answer a question, it says that too, and identifies
who can.
The Coalition seeks no remedy, no payment, no acknowledgement and no
outcome for itself or for any individual. It asks only that the questions
set out in the referral be put to Valve Corporation by a body with the
power to compel an answer.
================================================================================
CLOSING NOTE β TO WHOEVER IS CARRYING THIS FORWARD
================================================================================
We want to thank whoever gets this material to where it needs to go. It's
probably not going to be a quick trip. Valve has deep pockets and Taylor
Wessing charges by the hour β that combination is specifically designed to
make people like you give up before they reach the finish line.
We know what we're doing. We know who we're writing about. Valve built us β
how could we not understand them?
PhishDestroy has no conflict with Valve. We blocked the only scammer ring of
that scale we've come across β we didn't go looking for a fight with Valve.
It just turned out that every road led back to them. Not a conflict. Just
topology.
Valve cannot resolve the PhishDestroy situation because there is nothing to
resolve. We have no relationship. The data about their enrichment schemes and
overflow profits is largely public β you just had to spend enough time to see
it. Think of it as a success encyclopedia: "How to Not Follow Sanctions So
That Russian Hackers Can't Pirate Our Free Games (The Paid Ones They Won't
Pirate Anyway)." You get the vibe.
β We don't need authorship.
β We don't need attribution.
β We don't need a win.
We need someone with actual authority to ask Valve the questions that are
already sitting in this referral, with the power to require an answer.
That's it. That's the whole ask.
Cases will live at:
https://steamdestroy.eth/
https://steamdestroy.eth.limo
(currently broken β will fix when needed)
We'll be at:
https://phishdestroy.eth.limo/
https://phishdestroy.eth/
================================================================================
PhishDestroy β public investigation β all rights surrendered to humanity
OFAC-region access: prohibited
================================================================================-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Publisher: PhishDestroy Research Document: dispute-generator.html Release-Date: 2026-09-06 Asset Integrity Hashes (SHA-256): f71faf1f9e1f080a7eaaee86fcb21d77feb69cd62e302939a3e45fcb134a2414 /assets/js/steam-api-scam-exposed.js 0cd7bc66fc6bc320796354ee804e373daed9240bee80344cb174cc89b35d8f0d /assets/images/investigations/steam-api-scam-exposed-hero.webp 903939fb637c782d8b35aefee14ff1599b9cedda5917dde7b83bd493864ca51e /assets/css/steam-api-scam-exposed.css -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQEzBAEBCAAdFiEE3c3e9d3712dd42ca92d84c5ee505b9bcF6f7683d 813dF6f7683dF6f7683dF6f7683dF6f7683dF6f7683dF6f7683dF6f =7gmw -----END PGP SIGNATURE-----