Investigative Roadmap & Teaser

Valve Profits from Stolen Accounts: The Trilogy

Our multi-part investigative series exposing Valve's systemic corruption, profitable blindness, and sanctions evasion.

Part I of III — Active 2026-08-14

Valve Profits from 578,000 Stolen Steam Accounts

897,000+ stolen accounts live on LZT Market across 16 platforms. 0M+ in criminal listings. 50M estimated victim liability. Five legal vectors. Interactive forensics. Live intelligence dashboard. Valve's decade of profitable blindness — documented.

40 min read
Read Part I
Part II of III — Pre-Release COMING SOON

Part II: Sanctions Evasion & The 30% Cut

Exposing how Valve blatantly bypasses international sanctions to secure their 30% cut. We have evidence of over 00 Million in sanctions evasion facilitated by one platform in just two years. Direct top-ups from DNR, LNR, and Crimea functioning continuously.

00
Days
00
Hrs
00
Mins
00
Secs
Release: October 14, 2026 (12:00 UTC)
Official Announcement

This manifesto is published directly in response to Valve's corporate threats, intimidation tactics, and continuous negligence.

Let's set the record straight. PhishDestroy isn't a traditional "community" — we are a domain, and we are a deep understanding of how things actually work. There is nothing to infiltrate, no membership to revoke, no moderator to lean on.

When Gabe Newell spins fairy tales about baseball cards to a "community" that has no voice, no comments, and no open discussion, it's honestly laughable.

Look at how that actually worked. A state Attorney General files suit. Valve responds — publicly, at length, to its "community." No comments enabled. No replies. No questions taken. One direction only. A discussion, as seen by Valve.

And underneath the statement sits the thing nobody addressed: items taken from children, held, and never returned. Answering a prosecutor that way isn't disrespect toward us. It's contempt for everyone reading.

We don't play "threat games," we don't play doctor, and we certainly don't find it amusing when a platform provokes dangerous situations and knowingly leaks the data of minors.

Banning a Bot is Not Policing

This is the part US regulators need to see clearly, because it is presented as the opposite of what it is.

When Valve bans a bot account holding stolen items, nothing is returned to anyone. The victim gets nothing. The items stay frozen on the banned account, the inventory is hidden from public view, and the supply is removed from the market — which raises the price of everything comparable and increases Valve's commission on every subsequent sale.

That is not law enforcement. Steam is not the police. It is confiscation at industrial scale, performed under the language of anti-fraud, by the only party that profits from it.

Valve's "Masterpieces" & Fake Philanthropy

Oh, we are massive fans of Valve. Absolute masterpieces like Half-Life 3, Aperture Desk Job, Dota Underlords, and Artifact.

We deeply appreciate Steam's forced "volunteerism" — handing out free games (because otherwise, who would buy them?), using players for unpaid anti-cheat testing, and completely ignoring massive bot farms just to artificially inflate your "real" online statistics.

We aren't registered on your platform. We didn't accept your agreements. We only touched your two "brilliant" tools (speedtest.valve.net and speedtest1-sea1.valve.net), realized they were garbage, and moved on.

It seems your highly-paid mega-coders — who supposedly bring in more profit than Apple employees — operate with zero management oversight. Great job, but that doesn't make us your clients. Your Subscriber Agreement does not reach us.

Incompetence, Ignored Bugs & The GrapheneOS Joke

Is this a conflict? No. Who are we to conflict with anyone? We are simply analysts who process massive arrays of public data and actually care about the scams you breed.

While looking for standard contact emails — which you apparently don't have, no legal@ and no privacy@ — we stumbled upon gems like developer.valvesoftware.com/wiki/User:Pee. Thanks for the useful wiki. We will definitely showcase the reality of your employee interactions in our upcoming articles.

Speaking of your wiki (Template:Userbox_os/doc), it's fascinating that your "professionals" list GrapheneOS as a separate operating system on par with iOS.

We respect Daniel Micay and his privacy work, but maybe your experts should have asked him how to fix your API MITM proxy vulnerability — the one that took you 7 years to patch.

If your team is so incompetent that they couldn't protect kids from MITM espionage and parallel sessions for nearly a decade, why do they even need a GrapheneOS phone? Preparing for a panic HARD RESET?

Maybe add Tails, Whonix, Tor, CalyxOS and LineageOS to your list too, since your platform has successfully raised an entire generation of cybercriminals.

Part 1 Already Happened

We published it. Your own counsel handed us the corroboration — 830 pages they couldn't black out, produced by a firm billing by the hour to prevent exactly that.

Not one line of it has been refuted. Your lawyers didn't dispute the facts. They called our notification "entertaining." That reply is an exhibit now.

Twelve jurisdictions have the packages. Cover letters, statement of facts, exhibits, access logs, SHA-256 hashes. Sent. Not threatened, not planned — sent.

Our Stance: No Apologies

We don't volunteer for you. We protect consumers and regulators from your blatant lies. All our data and findings are released under the MIT license — free to use, distribute, and analyze.

We are not acting in anyone's interest except your deceived clients and the regulators you lie to. We know we are rude and inconvenient, but we don't apologize for exposing billions in stolen funds, the Lolzteam connections, and the reality of your operations.

And let's be honest about scale: we couldn't oppose a corporation if we wanted to. A registrar pocketing someone's Monero, maybe. A company moving billions with a law firm on retainer — obviously not.

We don't have to. We file. Authorities with powers we don't have make the decisions. We waived every right in the material, so any of them can publish it as their own findings, and we couldn't withdraw it if we tried.

There is nothing here to buy and nothing to negotiate. No demands, no deadline, no price. We don't blackmail — that's your lawyers' department, and they're better at it than they are at redaction.

Read This Part Twice:

ANYTHING YOU DO TO INFLUENCE WHAT GETS PUBLISHED ONLY DEMONSTRATES THAT YOU ARE AFRAID OF IT.

Pressure, takedowns, letters, an account quietly restored to someone — every one of those is an admission, and every one becomes a dated line in a file twelve authorities are already holding.

The Archive, and an Honest Word About the Domain

The dataset is around 100GB now, cumulative. We reported roughly 75 in Part 1. It has not stopped growing.

If your expensive, incompetent lawyers want to silence us by taking down phishdestroy.io — go ahead. We'll say this plainly: at this point you would be doing us a favour. The arrays are enormous, the work is tedious, and we are sick of looking of it. Nobody here is enjoying this.

The only thing still driving it is getting US regulators to see what actually happens on your platform — that a ban is not policing, that nothing is ever returned, and that the money keeps moving in exactly one direction.

Unlike you, we won't leak the private identities of children — we aren't monsters who watch kids from one country get reported by another just for fun. Any attempt to shut down our site will be treated as a direct attack on independent researchers.

And understand the default, because it isn't a threat, it's just what happens. If we stop, everything processed goes to IPFS and every regulator holding a referral gets the complete raw set. No decision required from us. It requires nothing from us at all.

Killing the domain removes a URL. It removes no files, and it un-sends no packages.

Ten months on, those people still haven't been told anything happened — not by you, not by your lawyers, not by anyone.

Roadmap: Part II — October 14th

Prepare for the second part of our investigation:

  • We will be directly contacting game developers to expose how Valve blatantly bypasses international sanctions just to secure their 30% cut.
  • We have evidence of over 00 million in sanctions evasion facilitated by one platform in just two years.
  • We will hand this data over to game developers who refuse to sponsor terrorism, as well as payment aggregators, so they can finally put a check on Valve's greed.

We have no obligations to you. We just have the truth.

— PhishDestroy

Read the first part of the investigation:
Part I: My Dog vs. Elite GDPR Lawyers