Working Draft It's not October 14 yet — but we're already publishing. Consider this a draft. Full version with translations and regulatory submissions publishes 14 Oct 2026. — until final release Read manifesto ▾

We are not publishing one investigation. We are dividing our large-scale work into three separate vectors — three distinct tracks, each with its own form, audience, and evidentiary standard. What you are reading now is one of them. This is a working draft. Some of the facts here we will contest ourselves and prove otherwise — including the events of 2023 and certain connections we intend to document in full. We leave the material as-is so you can verify it and draw your own conclusions.

On 14 October 2026, the finished version — with translations — will be submitted simultaneously to up to ten regulatory bodies. We believe they will find our work, built entirely from public sources with a documented evidence base, worth their time.

We assert

Steam's Terms of Service are not a user agreement. They are a legal fortress built to protect Valve — against regulators, against users it locks out unlawfully, against victims of theft who were told there is no appeal and no process.

We assert

Steam believes laws can be purchased with lawyers expensive enough to falsify evidence. We have documented what those lawyers did with the evidence.

We assert

Steam did not merely tolerate automation. It published the libraries, the APIs, the session infrastructure — the complete technical toolkit required to run a bot farm at scale. The automation ecosystem is built on Valve's own engineering, distributed under a different name.

We assert

Steam's own Subscriber Agreement explicitly bans commercial automation and third-party marketplaces. Every skin market and gambling operation ran throughout Steam's entire history — using Valve's APIs, Valve's session system, Valve's OpenID relay. Steam is not the victim of this ecosystem. Steam is its architect.

We assert

Every theft, every inventory hijack, every API-enabled fraud on the platform — the root cause is Steam's own architecture, and a deliberate strategy of cultivating third-party dependency. This is not negligence. This is design.

We assert

The shutdown of OPSkins and other targeted actions against "illegal" platforms were not enforcement. They were competitive operations conducted through Valve's legal apparatus — for the benefit of other "illegal" platforms that remain untouched.

We assert

Steam's business model — zero advertising, no direct secondary-market revenue — is structurally dependent on the platforms its own TOS declares illegal. We approach this as data analysts working with large datasets. We do not follow a predetermined trail. We verify the claims of others. The dependency is in the numbers.

We assert

Every offer-substitution fraud, every API scam documented through January 2026 — full responsibility belongs to Valve. Third-party tools built for Steam implemented trade-verification protections that Valve, with vastly greater resources, chose not to ship. Gambling was suppressed when regulators noticed. Scams were not — because fixing them required Valve to admit the vulnerability was architectural and was always theirs. Users were blamed instead.

We assert

Steam built a browser inside its own client — motivated by telemetry collection, not user security. Antivirus software cannot operate inside it. Chrome's malware protections cannot reach it. Steam's own Link Filter — the blocklist Valve controls — we tested it against a public phishing dataset. Almost no active Steam phishing domain appears on that list. A Steam phishing campaign survives for as long as the domain survives.

We assert

Settling this with lawyers who share a golf schedule will perhaps succeed in one jurisdiction. We are not speaking about one country. We are speaking about every country where Steam operates and where Valve placed its financial interests above — and in practice, in place of — the safety of its users and their assets.

We assert

We see what Steam and its lawyers are doing — arguing baseball-card semantics to an audience they expect not to understand. We have made that understanding available. It is built entirely from public sources, with a documented evidence chain — and it can be used by regulators against a corporation that is lying openly.

We assert

CS2. Dota 2. Esports at scale. None of it reaches its current audience without the skin economy — and the skin economy cannot function without the third-party commercial markets that Steam's TOS explicitly prohibits. Remove the content ecosystem, the case-opening culture, the sponsored teams, the secondary-market liquidity: Valve's two most valuable franchises lose the audience that sustains them. The economy Valve calls illegal is the economy Valve is built on.

We assert

Valve complies with requests from Russian state authorities. Valve complies with requests from Chinese state authorities. This is their own admission. Support agents with internal access can read, export, and transfer detailed account data without external oversight. High-value account compromises documented in 2023 involved compromised support access funneling assets to outside actors. Valve continues to assert its legal rights within the Russian Federation and files pre-trial notices on Russian territory.

We assert

We know most of the identities behind the major commercial platforms operating in Steam's orbit. We know their citizenship. The full picture is assembling. We do not expect it to take seven years.

IACADEMIC INVESTIGATION

Taylor Wessing & Dr. Patrick

We did not start this fight — their lawyers did. A dedicated academic paper, backed by experts, will dissect Taylor Wessing’s documented handling of evidence, with sources.

IIDOCUMENTED FACTS

Dry. Sourced. No conclusions added.

Public data only, no opinion. Every claim is tied to a dated document or observation; anything unsourced has been removed. Built for regulatory review.

IIIINTELLIGENCE

What we know but cannot prove yet.

Unverified, uncleaned, clearly flagged — published so others can investigate it with us.

In any case — as we promised: we will knock on every door. The world will learn the truth about Valve, or about a Trojan horse with an address in the USA and interests elsewhere. That is precisely why we separate these tracks — so regulators can work with each one cleanly.
OSINT RESEARCH PIPELINE ACTIVE
PLATFORMS AUDITED: 189 · 178 RETAINED
SEPARATE-DOMAIN AUTH ROUTES: 44
WHOIS/RDAP DATES: VERIFIED
SUPPORT RECORDS: 354 DE-DUPLICATED
EVIDENCE PROVENANCE: 100% PUBLIC
The Steam Dossier II: Third-Party Authentication, Enforcement and Data Access Public evidence file · updated

Prepared for data-protection, consumer and gambling regulators. Public sources only.

Price-cap register Market Mechanics Scandals Master Registry

THE STEAM DOSSIER / II

Third-Party Authentication,
Enforcement & Data Access

The definitive forensic study of the structural gaps, proxy-bypass mechanisms, selective enforcement, and regulatory challenges surrounding the Steam Web API ecosystem.

Part II exhibit — account access & accountability: investigation_part2.html →

Section 1 — Case briefing

The rule. The record. The unanswered questions.

Six findings. Each connects a written rule to a dated record and a question the evidence can test.

Context & source limits

Six findings, each tied to a dated public record. The detailed sections follow the same order: technical record (Part A), rules and enforcement record (Part B), legal frameworks (Part C), then the appendices with the primary exhibits.

1. Separate-domain auth hosts — 44 routes · 26 split pairs

The live register records 44 platforms authenticating through a separate registrable domain. Five further routes sit in pending verification awaiting an RDAP date; promoting them would take the total to 47. They are excluded from 44 and from the age chart. — 27 with a published per-route evidence file and 17 added from manual collection, listed apart. In 26 filter-split pairs the main domain is BLOCKED in the Steam Link Filter while the proxy carrying its login is not. These are not burner domains: csgogem.com is blocked while api.csgem.com, the host carrying its Steam login, has been registered since March 2014 — 12 years 6 months. Valve receives that hostname in every OpenID request, and renders it back to the user on its own login page. Full table, per-route ages and sourcing in Section 3. Follow the route →

2. 2016: the mechanism was named, the deadline set

On 13 July 2016 Valve publicly described how gambling sites used Steam OpenID and automated trading accounts, and its counsel's notices of 20 July 2016 set a ten-day deadline. No per-operator enforcement record has been published since. Ten years after that deadline was issued, the same named mechanism is in use on separate-domain auth hosts that returned no Link Filter block on 2026-09-21. Read the open letter to the WSGC →

3. Device correlation, on counsel's letterhead

In the correspondence reproduced here, Valve's counsel described device-level correlation linking one device to multiple accounts — a capability Steam Support had previously told users was not technically possible. The open question is which device-level records Valve holds and on what basis account holders are refused access to them. Read the memorandum →

4. Two access responses. One withheld the data, one leaked it.

October 2025: Valve's counsel answered an Art. 15 request with an 830-page appendix whose redactions are painted over the text instead of removing it — 902,270 characters come back out with a standard extraction tool, including the third-party identifiers the bars were there to withhold. Art. 15(4) is the reason those bars exist. September 2026: ticket HT-2YBP-F7JP-D4VB was closed after three days with a link to the self-service Account Data page — no data, no stated legal basis. The one-month period under Art. 12(3) had not expired at publication; the objection is to the substance. Read the redaction check → · Read the ticket record →

5. The market above Steam's ceiling

Steam caps a Market listing at about $1,800. Across five marketplaces in a dated snapshot (23 Sep 2026), 248 CS2 item categories are priced above that cap by two or more of them independently, and all 248 are absent from Steam; a Factory New Dragon Lore starts at $10,941 across 389 copies listed on all five (the CSFloat-only figure in Section 13, from the 20 Sep snapshot, is $10,623.95 across 62 offers). Selling at those prices requires an outside venue, while item transfer still runs through Steam. Follow the price and transfer →

6. The rule is explicit; the audit trail is not

The Subscriber Agreement reserves Steam for personal, non-commercial use, bars commercial exploitation except as expressly permitted, prohibits scripts and bots, and allows account termination. Valve applied that language to gambling operators in 2016. Separately, according to CSFloat's engineering account, Valve closed IEconItems_730/GetPlayerItems in 2017, removing public access to original item IDs (no Valve changelog located). Put the rule beside the network →

2016 / Written demand 10 days
Deadline in Valve counsel's July 2016 notices to gambling sites. Open letter to the WSGC: Section 2.
2017 / Public audit trail ID access closed
CSFloat records the loss of original item IDs.
Counsel correspondence Device correlation
One device linked to dozens of stolen accounts.
Route register Blocked, and still logging in
The rule: Valve's 2016 statement prohibits running a gambling business on Steam OpenID. The record: 26 main domains sit on the Link Filter while the host carrying each one's Steam login runs on — csgogem.com's has run 12 years 6 months.
Part A — Technical record · Section 4

An endpoint closed. Public tracing lost a key.

The rule Valve applies: Steam Support does not restore items that left your account, and the burden of showing what happened is yours. The record: in 2017 Valve closed the endpoint that carried original item IDs. Before it, anyone could follow a stolen skin from the victim's account into a marketplace bot. After it, nobody outside Valve can. The proof the victim is asked for is the proof that was switched off — and it still exists, inside Valve.

Context & source limits

Steam shipped changes that removed public visibility of item Asset IDs and restricted API inventory access. The effect: tracing a specific item by its original Asset ID became impossible from public data. What follows is what was possible before, what stopped being possible after, and what that costs a victim trying to prove where their property went. The date is 2017 according to CSFloat's engineering account; no Valve changelog has been located. The sequence — roughly a year after the July 2016 gambling statement — is the investigative question, not a finding. The item records themselves remain inside Valve's systems; outside investigators lost access to the original-ID chain, while float, seed and paint identifiers allow only partial matching.

The Pre-Blackout Era

Historically, every virtual item generated on Steam possessed a globally unique, immutable Asset ID. Third-party OSINT databases could index these IDs. If a user had an item hijacked, investigators could trace the lineage of that specific asset as it moved from the hijacker's intermediate account into the storage accounts of a marketplace or gambling site.

BEFORE: an item could be followed from the victim's account through intermediate accounts and into a marketplace or casino storage bot, by anyone, using public data.

After the change

According to CSFloat's engineering account, Valve closed the endpoint in 2017 and original item IDs stopped being available to outside parties. No Valve statement of the reason for the change has been located. In the same period, no published action against the commercial bot accounts that moved items at scale has been located either.

Whatever the reason for it, the change severed the public chain of custody. A victim can no longer reproduce the original-ID chain from public data to show that a specific stolen item was liquidated through a specific marketplace or casino. The item records still exist inside Valve's systems; the public, researchers and law enforcement working from public data cannot reach them.

AFTER: tracing a specific item by its original Asset ID is no longer possible from public data. The original-ID chain of custody for an item moved after 2017 exists only inside Valve's infrastructure; no such record has been produced publicly. Float, seed and paint identifiers allow only partial, probabilistic matching.
IEconItems_730
GET /IEconItems_730/GetPlayerItems/v1/
Traceable Payload (Pre-Patch)
"id": "14892281934",
"original_id": "11829910211",
Status: Victim can track item lineage across bot accounts.
Obfuscated Payload (Post-Patch)
Current
"id": "HIDDEN_BY_PRIVACY_SETTINGS",
"original_id": "NULL",
Status: outside parties can no longer trace item lineage by original Asset ID from public data.
Effect on evidence: after the change, the public data needed to follow a specific item by its original Asset ID from a victim's account into a marketplace or casino bot was no longer available. The internal records still exist at Valve; a victim, researcher or investigator working from public data cannot reproduce the original-ID chain (float, seed and paint identifiers allow only partial matching).

Source: CSFloat engineering account of the 2017 closure of IEconItems_730/GetPlayerItems — blog.csfloat.com/how-floatdb-tracks-items (archived 2026-09-21) · the payloads shown are an illustration of the field shape, not captured responses · no Valve changelog for the closure has been located.

Part A — Technical record · Section 6

Interactive Exploit & Hijack Simulator

Step through the reconstructed hijack. Each phase shows what the account holder sees and, beside it, the call Steam receives at the same moment. Every one of those calls is correctly authenticated. Nothing in the sequence needs Steam's authentication to fail — it needs the key it issues to carry no scope (OWASP A01:2021).

Context & source limits

A reconstruction of the path from the phishing message to the server-side key registration and the trade swap. Before 2023, a Web API key registered on an account could read its inventory, cancel a pending trade offer and create a new one, and no trade-confirmation screen was shown to the account holder for any of those actions. That is the absence of least privilege (OWASP A01:2021). The timings in this simulation are illustrative and are not live measurements of the current platform.

What the player sees. What changes behind it.WALKTHROUGH SIMULATOR
01 / THE CHAT LUREA friend asks to voteVictim receives a message with a link.
02 / THE LOGINA lookalike portalVictim enters sign-in credentials.
03 / THE ACCESSSilent Web API creationAttacker registers a developer key.
04 / THE SWITCHLegitimate trade swappedClone bot duplicates target recipient.
05 / CONFIRMATIONCounterfeit approvedWrong offer approved on mobile.

The Exploit Completed. Expecting a mobile prompt for their original trade, the victim approves the replacement trade. This is an integrated forensic walkthrough showing how the absence of Least Privilege (OWASP A01:2021) enables automated, sub-second asset hijacking.

The same step, seen from the networkReconstruction of the pre-2023 pattern · illustrative call shapes
VictimApproves the mobile prompt that was expected for the original trade.
AttackerReceives the items at the clone account.
Steam seesA transfer confirmed by the account holder on a registered device.
Confirmation genuine — made by the account holder
Recipient the clone bot, not the intended counterparty
The confirmation is authentic. The offer it confirms is not the one the user initiated.

The record left behind: a trade the user approved. That is the record Steam Support reads when the complaint arrives, and the reason the archived complaints were closed as user error. The complaints are in the enforcement archive.

Part A — Technical record · Section 7

The endpoints behind the sequence.

Four documented endpoints do the whole job. None of them is a flaw, none needed exploiting — a valid key calls them and Steam answers. The key is the only thing the attacker had to steal.

Context & source limits

These are the Steam Web API endpoints that the reported hijack scripts used to intercept trades without passing through the browser-side confirmation steps.

IEconService / GetTradeOffers / v1 POLLING

Used to monitor the account's trade offers. Scripts poll this endpoint repeatedly with the compromised API key; it returns the details of newly created, pending or modified trade offers. Polling intervals are not measured here.

Threat vector: Discloses pending trade offer IDs and the recipient's profile details.
IEconService / CancelTradeOffer / v1 INTERACTION

Used to programmatically invalidate the user's legitimate trade offer. Before 2023 no step-up authentication protected the key, so an automated server could cancel an offer as soon as it was detected, without any prompt to the account holder.

Threat vector: Voids the trade before the account holder completes the mobile confirmation.
ISteamUser / GetPlayerSummaries / v2 RECON

Queried to retrieve the profile name, avatar image URL and level of the legitimate trade recipient. This lets the script dress a prepared clone account to match. No timing is measured here.

Threat vector: Supplies the data needed to impersonate the intended recipient.
/dev/ajaxregisterkey CREATION

Steam's registration endpoint for keys. Historically, any active browser cookie session (`steamLoginSecure`) could register a key without a Steam Guard confirmation on the mobile device, and without any notification to the account holder.

Threat vector: A persistent credential created by a script, unseen by the account holder.
Forensic Autopsy · The Trade Substitution Vector

How Valve Finally Neutralized "Trade Substitution" — And Why It Took 7 Years of Workarounds

For nearly a decade, the "API Key Trade Substitution" (or API MitM Scam) was the most lucrative account theft model on Steam, siphoning hundreds of millions of dollars in skins from unsuspecting players. Valve did not eradicate the exploit by fixing the vulnerable API architecture; instead, Valve spent seven years layering four platform-wide friction barriers that crippled community trade liquidity while leaving the root cause unaddressed.

1. The Mimicry Death

Avatar & Name Cooldown (Feb 2024)

The exploit required sub-second mimicry: the scam bot intercepted an outgoing trade, scraped the recipient's avatar/name via ISteamUser, and cloned the profile in 200ms. On 14 February 2024, Valve quietly implemented a mandatory 2-to-4 hour trade cooldown (Error 34) immediately following any profile name or avatar change. A bot can no longer clone a recipient on the fly without locking itself out of trading.

2. The Economic Death

7-Day CS2 Trade Reversal (Jul 2025)

Valve introduced unilateral Trade Reversals for Counter-Strike items. Any traded skin is tagged "Trade Protected" for seven days. If a victim discovers a substitution, they click "Reverse Trade" in Steam Support, and the skin is instantly returned to their inventory while freezing the recipient. Because the 7-day trade lock prevents scammers from moving the item to a cashout site, the theft is rendered unprofitable.

3. The Silent Key Death

Mandatory Mobile Push for API (Dec 2023)

Historically, a stolen session cookie allowed malicious scripts to execute a headless background POST to /dev/ajaxregisterkey without notifying the victim. On 4 December 2023, Valve mandated an explicit push confirmation on the Steam Mobile App to generate a Web API key, eliminating silent background key provisioning.

4. In-App Mobile Warnings

Account Age & Name Banners (2022–2024)

Valve revamped the mobile confirmation modal to display the trade partner's Steam account tenure (creation date), Steam level, and an explicit amber warning: "This user has recently changed their profile name", breaking the visual illusion for attentive victims.

The Three Flaws in Valve's Patchwork: Why Scammers Simply Shifted Targets
1. The Game Exclusion Loophole (Dota 2 & TF2)

Trade Reversals were deployed exclusively for Counter-Strike 2. Dota 2 and Team Fortress 2 items remain completely unprotected due to crafting and socketing complexities. High-tier items worth thousands of dollars (Dragonclaw Hooks, Golden Baby Roshans, Unusual TF2 burning flames) carry zero reversal window. Scammers simply redirected automated API interception onto Dota 2 and TF2 traders, where Steam Support strictly enforces its 2016 "no item restoration" policy.

2. The "Zombie Key" Reservoir (Zero Expiration)

While Valve added mobile push 2FA to generate new keys in December 2023, Valve never revoked, expired, or purged existing legacy API keys. Millions of active accounts that generated keys (or had keys silently created by phishing/malware prior to Dec 2023) still carry active credentials with zero expiration (no TTL) and zero inactivity timeout. Threat actors maintain massive historical databases of these persistent keys, continuing to poll IEconService undisturbed.

3. The Victim Penalty: 30-Day Trading Lockdown

Even in CS2, Valve penalizes the scammed player: clicking "Reverse Trade" in Steam Support automatically inflicts a mandatory 30-day trade and Community Market ban on the victim's account. Valve punishes the user with a month-long platform exile as a deterrent against "frivolous" reversals, discouraging victims from reversing trades on lower-value liquid items.

The Core Regulatory Scandal: Seven Years of Workarounds vs. One API Scope

Why did Valve spend seven years inventing trade holds, account cooldowns, and reversible trade locks—disrupting the entire gaming economy and wiping out $104M in market capitalization—instead of implementing the industry-standard fix?

As proven by Valve's official Steamworks release on 16 January 2026 (Announcement #493839547938902179 ↗), Valve already built Granular Permission Groups (General, Microtransactions, Economy, Sales Data) and IP Whitelisting for corporate Publisher Keys. Valve had the engineering solution in hand for years. A single user-facing checkbox—"Prevent this Web API key from accessing IEconService (Trade Management)" or a home IP whitelist—would have eradicated the trade substitution scam in 2018 with zero economic collateral damage. Valve refused to give regular players the protection it engineered for corporate partners.

Part B — Rules and enforcement record · Section 10

An automation API. A rule against automation.

The rule (SSA § 4.C): no scripts, no bots, no non-human systems on Steam. The record: Valve ships a headless REST API whose entire purpose is server-to-server automation, and hands the key to any account. Users are banned for automation; the automation interface is Valve's own product. Which commercial uses are authorised has never been published.

Context & source limits

The question this section puts is how the two are reconciled: which uses of the API are authorised, by whom, and on what published criteria. No count of authorised commercial API users is estimated here, and none is implied by the absence of a published list — the absence is the finding, not a number behind it. The Steam Support messages quoted above are reproduced by the ArchiSteamFarm project in its own FAQ (verified verbatim 2026-09-22); they are not Valve publications, and the accounts they were sent to are not identified.

The "Game Developer" Fallacy

Steamworks SDK (Legitimate)

Used by legitimate game studios to integrate achievements, matchmaking, and leaderboards into their game clients. Requires complex C++ integration and official partner onboarding.

Steam Web API (The Loophole)

A headless JSON/REST architecture designed for external web servers. In the hijack pattern documented here it is used to read inventories and manipulate peer-to-peer trades from remote servers; its legitimate uses are not catalogued in this dossier.

Who the key is forAn ordinary Steam user has no in-client need for a Web API key; the key page lives under a developer URL and its documented purpose is external, server-side access. The archived hijack complaints describe victims who did not know the page existed until a key had been registered on their account.

The Automation Contradiction

SSA § 4.C provides: "You may not use any form of scripts, bots, macros, or other non-human-controlled systems ('Automation') to interact with Content and Services on Steam in any manner." Yet the Web API endpoints (like CancelTradeOffer) require no human UI and no captcha and bypass the Steam client entirely. The API is designed for server-to-server automation; the rule prohibits automation by users; the boundary between the two is not published.

A server-side position in the trade flow

A Web API key lets a third-party server act on the account's trades without the Steam client. In the hijack pattern, that server sits between the account holder and the trade server.

  • → No trade-confirmation screen is shown for the key's actions.
  • → Allows background polling (GetTradeOffers).
  • → Cancels and re-issues offers without user interaction.
Valve built the interface, prohibited user automation in its rules, and has published no criteria for which commercial uses are authorised.
Part B — Rules and enforcement record · Section 11

Ten days demanded. Ten years to account for.

Read the July 2016 notice beside the later observations. The outstanding demand is an operator-by-operator enforcement record.

Context & source limits

On 20 July 2016 Valve's general counsel gave gambling operators a 10-day deadline. Ten years later (as of the dossier snapshot, 2026-09-21) at least one platform named in press reports of that notice, CSGOFast, is still operational with a separate-domain auth host. The wording is reconstructed below from press reports of 21 July 2016; the reconstruction is not a scan. The enforcement record the notice implied has not been published. The open letter to the Commission is Section 2.

One week earlier — 13 July 2016, in public

On 13 July 2016 archived 2026-09-21 ↗, Valve described how gambling sites used Steam: OpenID for account identification and automated accounts for trading. Valve stated that using those mechanisms to run a gambling business violated its API and user agreements. Both the description of the mechanism and the prohibition are in Valve's own dated statement. On 2026-09-21 the separate-domain auth hosts tested returned no Link Filter block, and Valve has published no per-operator enforcement record.

VALVE CORPORATION

Bellevue, WA

"We are aware that you are operating one of the gambling sites listed below. You are using Steam accounts to conduct this business. Under the Steam Subscriber Agreement, Steam and Steam services are licensed for personal, non-commercial use only."

"You should immediately cease and desist further use of your Steam accounts for any commercial purposes. If you fail to do this within ten (10) days, Valve will pursue all available remedies including without limitation terminating your accounts."

Reconstruction of the July 2016 notice text, rendered by the authors from press reports of 21 July 2016
Karl Quackenbush
General Counsel, Valve Corp.
Timeline July 2016 – September 2026
Deadline in the notice:
10 Days
July 2016
Elapsed since the notice:
3,715 Days
Fixed count from 20 July 2016 to the dossier snapshot of 21 September 2026, not a live figure
Published enforcement record:
None
No per-operator account of terminations or blocks located

Ten years later, CSGOFast — named in press reports of the 2016 notices — is operational: csgofast.com returned a Link Filter block on 2026-09-19 and 2026-09-21, while its auth host steam-login.authtofast.com (registered 2026-06-30) did not.

Full dated record of Valve's security changes: Security Timeline → · The Washington record and the enforcement standard: below

What the record shows: the 2016 notice set a 10-day deadline; Valve already operated a domain list (the Link Filter) and received the auth hostnames in its own OpenID requests; no per-operator enforcement record has been published. Community reports describe a 2018 action against a marketplace (SkinJar), but those reports are unverified and are not relied on here.
PUBLIC RECORD / WASHINGTON · 2016 → 2026

Two deadlines. One unanswered enforcement standard.

20 JUL

Valve gives gambling sites 10 days

Its counsel's demand warned that continued commercial use of Steam accounts could lead to termination.

27 SEP

Washington presses Valve

The state's Gambling Commission demanded evidence of steps to stop skin transfers for gambling and set a 14 October response deadline.

17 OCT

Valve rejects the charge

Valve answered after the deadline, disputed that it facilitated gambling, said it had disabled associated accounts, and said it did not want to switch off trading and OpenID for everyone. At least one platform named in press reports of the July notices (CSGOFast) was operating a decade later. Both facts can hold only if the operator replaced the disabled accounts; the record that would show this has not been published. The WSGC should ask Valve to reconcile the two.

2026

The routes observed in September 2026

The route register records 44 platforms authenticating through separate-domain auth hosts, including CSGOFast, using the OpenID and trading mechanisms Valve described in 2016. The enforcement record that would show which operators were cut off has not been produced.

THE COMMISSION'S OWN BRIEFING · 30 JANUARY 2018

Eighteen months after Valve replied, the regulator still called it an intent.

Briefing its own legislature at the HB 2881 public hearing, the Commission described the July 2016 statement in its own words: Valve "announced its intent to crack down on the use of its platform to facilitate skins gambling." The same page records what that announcement did to the industry forecast — "as a result," the projected 2020 skin-gambling market was revised from $19.7 billion to $670 million, a cut of about 97 per cent, on the strength of the announcement alone. The forecast moved. The per-operator enforcement record that would justify it has still not been published.

The market figures are Narus Advisors / Eilers & Krejcik Gaming estimates reproduced in the Commission's briefing, not Commission findings; the same document puts 2016 skin wagering at about $5 billion, roughly $3 billion of it on casino-style sites. Retrieved 2026-09-22, SHA-256 c507c9025f93da0aadaf395c4d8882f25973211c318ee8e9b6f18a5b3755e050.

Valve's public 2016 position and today's observable infrastructure can be put side by side. The question is whether enforcement reached the accounts and routes used by prohibited operators. A ten-day notice is not evidence that the notice was carried out across the operators it named. The 2018 OPSkins action is the one documented intervention against a named operator; set against 189 platforms checked and no published per-operator record, one documented action does not show a pattern of enforcement.

Washington Gambling Commission's 2016 notice ↗ archived 2026-05-20 ↗ · Valve's 17 October 2016 response (document copy) ↗ · WSGC briefing to the legislature, 30 January 2018 (local copy, 4 pp.) ↗ · the same file on wsgc.wa.gov ↗ · retrieval record & hash ↗ · Valve's 2018 OPSkins action ↗ archived 2026-03-07 ↗ · Current route audit ↗

Forensic Longitudinal Audit · 2016 Cease & Desist Targets

The 10-Day Notice Decade: Forensic Survival Audit of the 23 Named Sites

On 19–20 July 2016, Valve General Counsel Karl Quackenbush issued formal cease-and-desist notices to 23 skin gambling platforms, ordering them to cease commercial use of Steam accounts within 10 days under threat of account termination and legal action. Over 3,700 days later, an empirical audit reveals the true pattern of enforcement: multiple operators never ceased operations, others ran for up to six years after the deadline, and the multi-billion-dollar ecosystem continued to leverage Valve's OpenID architecture.

5+ LIVE
Defiantly operational in 2026 (CSGOBig, CSGO500, CSGOFast, etc.)
6 YEARS
Longest post-notice run before closure (CSGOatse active through 2022)
$5.01B
2016 skin wagering volume (Narus / Eilers & Krejcik)
200+
Active skin gambling sites operating at market peak
The Surviving Titans · 2024–2026 Financial & Traffic Blueprint

From 10-Day Warnings to Offshore Conglomerates: The Multi-Billion-Dollar Turnover

Rather than eliminating skin gambling, Valve's 2016 notices catalyzed an industrial evolution. The surviving operators restructured as offshore corporate entities (Curaçao, Belize, Cyprus), pioneered Peer-to-Peer (P2P) trading to bypass bot bans, and now process over 10 million monthly web visits and billions of dollars in annual wagering handle while continuing to authenticate through Steam:

Platform / Domain July 2016 Notice Enforcement Outcome & Survival Status Recorded Verification / Primary Links
CSGOBig
csgobig.com
10-Day Notice (Jul 2016) STILL LIVE IN 2026
Temporarily paused, relaunched; authenticates via letmeinbig.com & csgobiglogin.com
X: @csgobig ↗ · FB: csgobigofficial ↗
CSGO500
csgo500.com / 500.casino
10-Day Notice (Jul 2016) STILL LIVE IN 2026
Rebranded into 500 Casino (Curaçao license #8048/JAZ2014-037), multi-million monthly turnover
Live Platform (500.casino) ↗
CSGOFast
csgofast.com
10-Day Notice (Jul 2016) STILL LIVE IN 2026
Actively operating roulette, crash, and jackpot via steam-login.authtofast.com
Dossier Auth Audit ↗
CSGOLounge / Dota2Lounge
csgolounge.com / dota2lounge.com
10-Day Notice (Jul 2016) STILL LIVE IN 2026
Pivoted to esports coin wagering and crypto betting; maintained continuous operation
Live Platform ↗
CSGOCasino
csgocasino.net / csgocasino.gg
10-Day Notice (Jul 2016) LIVE VIA SUCCESSOR (2026)
Domain redirected; active successor portal operates under csgocasino.gg
Successor Domain ↗
CSGOatse
csgoatse.com
10-Day Notice (Jul 2016) SURVIVED 6 YEARS (ACTIVE TO 2022)
Continued full gambling operations for six years following Valve's 10-day ultimatum
X: @CSGOatsecom (Active to 2022) ↗
CSGOSweep
csgosweep.com
10-Day Notice (Jul 2016) SURVIVED TO DEC 2017
Operated publicly for 17 months after deadline
X: CSGOSweep Status Dec 2017 ↗
CSGOWild
csgowild.com
10-Day Notice (Jul 2016) SURVIVED TO DEC 2017
Promoted by major influencers; ran for 1.5 years post-C&D before crypto migration
X: @Wild (Active Dec 2017) ↗
CSGOPot
csgopot.com
10-Day Notice (Jul 2016) SURVIVED TO SEPT 2017
Operated high-stakes jackpot betting 14 months past notice
X: @csgopot (Active Sep 2017) ↗
CSGODiamonds
csgodiamonds.com
10-Day Notice (Jul 2016) SURVIVED TO MID 2017
Ran through 2017 despite admitted outcome tampering for sponsored streamers
X: @csgodiamondscom (2017) ↗
CSGOLotto
csgolotto.com
10-Day Notice (Jul 2016) CLOSED JULY 2016
Shut down under public scandal; target of federal FTC consent order
FTC Consent Order (Docket C-4632) ↗
CSGODouble
csgodouble.com
10-Day Notice (Jul 2016) CLOSED JULY 2016
Shut down voluntarily immediately after C&D publication
X: @CSGODouble (Closed Jul 2016) ↗
CSGOMassive
csgomassive.com
10-Day Notice (Jul 2016) CLOSED 2016
Ceased public operations in late 2016
X: @csgo_massive ↗
CSGOStrong
csgostrong.com
10-Day Notice (Jul 2016) CLOSED 2016
Ceased public operations in 2016
FB: csgostrongfree ↗
Skins2
skins2.com
10-Day Notice (Jul 2016) CLOSED 2016
Ceased public operations in 2016
FB: CSNCOM ↗
Platform Monthly Traffic (Visits) Estimated Turnover / Volume Corporate Entity & Jurisdiction Key Regulatory Actions & Model
CSGOEmpire
csgoempire.com
2.3M — 9.0M / mo
Avg 6+ min duration; 80% direct
$1.5B — $2.5B Annual Handle
>1,000,000 P2P skin trades/mo; $6.4M active liquid order floor
Moonrail Limited B.V. (Curaçao #148182)
Payments: JHOLT LTD (Cyprus); Founder: "Monarch" (Ossi Ketola)
Pioneered 0% fee P2P item trading; licensed Curaçao OGL/2024/1183/0869
CSGORoll
csgoroll.com
2.74M — 3.5M / mo
Avg 9m 23s duration; 16% bounce rate
$1.0B — $2.0B Annual Handle
Est. $100M–$200M annual corporate revenue from house edge
Feral Holdings Limited
Headquartered in Belize City, Belize (Reg #171519)
Banned by Australian ACMA (May 2023); sponsored tier-1 team G2 Esports with underage players
500 Casino (CSGO500)
500.casino / csgo500.com
220K — 425K / mo
~105k unique monthly visitors
$100k / week ($5.2M/yr) in Royales
High-roller wagering requirement: $400 wager per $1 rakeback
Perfect Storm B.V. (Curaçao #150536)
Curaçao Gaming Control Board license OGL/2024/1354/0882
Banned by Swedish Spelinspektionen (Nov 2023) for unlicensed targeting of Swedish players
CSGOBig
csgobig.com
~169,600 / mo
Avg duration 19m 12s; US primary
Multi-Million Annual Volume
Mystery boxes, roulette, and case battles
Operates via auxiliary proxy routing
letmeinbig.com (reg 2023) & csgobiglogin.com
Target of July 2016 C&D; relaunched with proxy auth architecture
CSGOFast
csgofast.com
~150K — 250K / mo
Global multi-language audience
Multi-Million Annual Volume
High-velocity roulette and crash games
Offshore operational entities
Routes Steam auth via steam-login.authtofast.com
Target of July 2016 C&D; never discontinued operations; active in 2026
CSGOPolygon
csgopolygon.com / plg.bet
~300K — 500K / mo
CIS and Eastern European dominance
Multi-Million Annual Volume
Crypto & skin roulette, match betting
Second-wave target (Oct 2016)
Pivoted to cryptocurrency with mirror domain plg.bet
Survived a full decade; continues skin liquidation via third-party APIs
The Second Wave: Why Valve's C&D Targeted 43+ Sites in Total

On 17 October 2016, Valve's legal counsel formally disclosed to the Washington State Gambling Commission that following the initial 23 notices on July 19, Valve had sent cease-and-desist letters to more than 20 additional skin gambling sites (bringing the official total above 43). This second wave was necessitated because the initial list inexplicably omitted the largest, most notorious gambling hubs in the world:

  • CSGOJackpot.com: The historic originator of skin jackpots, which handled hundreds of millions in volume before shuttering under threat of federal indictment.
  • CSGOShuffle.com: The site at the heart of the July 2016 streaming scandal, where Twitch streamer PhantomL0rd secretly owned 33% of the company and was exposed rigging odds with house funds.
  • The Macro Ecosystem (200+ Operators): According to industry research by Narus Advisors and Eilers & Krejcik Gaming, over 200 distinct skin gambling sites operated in 2016, generating $5.01 Billion in wagering volume from 3.03 million active players. Valve's 43 letters addressed less than 20% of the active market.
Official Government & Regulatory Investigations on Steam Skin Gambling

The skin gambling phenomenon is documented across multiple formal statutory inquiries, enforcement actions, and government position papers:

1. Washington State Gambling Commission (WSGC) (2016–2018)

Issued formal Cease & Desist demand on 5 Oct 2016; published Legislative Briefing on 30 Jan 2018 documenting that skins are cash equivalents and reporting the $5.0B skin wagering volume.

WSGC Legislative Report PDF (Local Copy) ↗
2. U.S. Federal Trade Commission (FTC) (Sept 2017, Docket C-4632)

First federal regulatory enforcement action involving skin gambling against CSGOLotto owners Trevor Martin and Thomas Cassell for deceptive practices and undisclosed platform control.

FTC Decision & Consent Order ↗
3. UK Gambling Commission (UKGC) Position Paper & Youth Audits

Formally classified in-game skins as "money or money's worth" under Gambling Act 2005. Subsequent surveys found over 11% of children aged 11–16 had bet skins on video games.

UKGC Research Repository ↗
4. Australian Senate Environment & Communications Inquiry (2018)

Federal Parliamentary report on "Gaming micro-transactions for chance-based items", evaluating Valve's loot box mechanics, secondary market cashouts, and regulatory circumvention.

Parliament of Australia Inquiry ↗
The outstanding demand

Publish the enforcement record: which gambling accounts and bots were disabled, which return hosts were restricted, and which commercial services received permission. A public prohibition and a homepage warning do not establish that the underlying operation was stopped.

Part B — Rules and enforcement record · Section 12

The hostname is already in the request.

Valve already runs a domain blocklist. Valve already receives the login host in every OpenID request. Nothing needs building — the two have to be joined. That is a hostname lookup against a list Valve maintains itself. The pseudocode below is an illustration, not Valve's implementation.

Context & source limits

Valve already maintains a domain list (the Link Filter) and already receives the auth hostname in every OpenID request. The pseudocode below shows the logical shape of connecting the two. No public evidence shows that Valve does so.

forensic_autoban.py
# ILLUSTRATIVE PSEUDOCODE — Valve.block_domain() and flag_session_as_mitm() are not real API calls. This demonstrates the logical structure of a mitigation Valve could implement against proxy auth domains, not actual Valve internals.
# Illustration: the logical shape of a check on the incoming OpenID request
def audit_openid_request(request):
blocked_origins = database.get_blacklisted_platforms()
proxy_domain = request.params.get('openid.realm')
target_redirect = request.params.get('openid.return_to')

# Logic: If the proxy routes back to a blocked site, ban the proxy.
for site in blocked_origins:
if site in target_redirect:
Valve.block_domain(proxy_domain)
Valve.flag_session_as_mitm(request.session)
# Result: the login request for that host is refused

Observation:
Where a main domain is already on the Link Filter (e.g. howl.gg, blocked 2026-09-18/19/21) and its auth host (howl.uno) appears in the OpenID request from that site's login button, the association is observable to Valve from its own request data. The check is automatable; whether it is run is not.

Documented and reported precedents

Valve has intervened against a third-party operator at least once on the record: in 2018 it revoked OPSkins' access over the ExpressTrade system (Valve's announcement ↗ archived 2026-03-07 ↗). Community reports from 2018 also describe a marketplace (SkinJar) losing access; those reports are unverified and the mechanism is inferred from the outcome, not from a disclosed process.

What the precedent establishes:

Valve can cut off a third-party operator's access when it decides to. CSGOFast, named in press reports of the July 2016 notices, was operating on 2026-09-21 with an auth host registered 2026-06-30 that returned no Link Filter block. Why one operator was cut off and others were not is not explained by any published criteria.

What a registration date does and does not show

The registration date of an auth host is a lower bound on when the host could first have appeared in an OpenID request; it does not establish continuous use. sc-auth.net, for example, was registered 2019-04-02 (RDAP) and was observed in Skin.Club's Steam login flow in September 2026; what happened between those two dates is not in the public record.

Comparative Audit: API Compliance Standards

Enforcement Dimension GitHub API Rules Steam Web API (Valve)
1. Compliance Neutrality Published, uniform rules. Documented rate limits (e.g. 5,000 calls/hr for authenticated users, 15,000/hr for GitHub Enterprise Cloud organisations) and published acceptable-use policies apply to every account. No published criteria. Individual accounts are terminated under the automation and commercial-use clauses (archived complaints), while no per-operator enforcement record for commercial platforms has been published.
2. OpenID / Auth Proxy Abuse GitHub's published policies allow OAuth apps and tokens to be suspended or revoked for abuse, and its documentation describes automatic revocation of exposed tokens (authors' summary of GitHub documentation). Separate-domain auth hosts observed in Steam OpenID flows (e.g. rbsnin.com, howl.uno, sc-auth.net) returned no Link Filter block on 2026-09-21 while their main domains did.
3. Monetization of Abuse GitHub takes no transaction fee on items moved by third-party automation; its revenue model is subscriptions and marketplace listings. Valve sells the case keys that produce the items, and the Community Market charges a combined fee of about 15% on sales completed inside the Market. No figure for revenue attributable to third-party platforms is estimated here.
4. Evasion Loop Lifespans Suspended OAuth client IDs stop working platform-wide at suspension; the documentation does not publish a time-to-action figure and none is assumed here. Separate-domain auth hosts with registration dates from 2011 to September 2026 returned no Link Filter block in the checks of 2026-09-19 and 2026-09-21. Registration date is a lower bound on possible use, not proof of continuous use.
Sources: GitHub column — GitHub's published API rate-limit and platform-policy documentation (authors' summary, not quoted) · Steam column — Link Filter checks of 2026-09-19 and 2026-09-21 (linkfilter-recheck-2026-09-21.json), RDAP registry (domain-registration.json) and the archived support complaints (evidence archive).
Part B — Rules and enforcement record · Section 13

The off-Steam price gap

The item sits in a Steam inventory; the sale happens elsewhere. A Factory New AWP Dragon Lore had 62 live offers on CSFloat; the cheapest asked $10,623.95. Steam's own market cannot display an asking price above approximately $1,800. To sell for the observed higher price, an owner needs an off-Steam buyer or marketplace. The item and its transfer still depend on Steam.

Context & source limits

Three different counts appear in this section and they are not interchangeable. 245 is the number of CS2 item-name categories whose cheapest active offer exceeded $1,800 on CSFloat alone, 20 September 2026. 241 is that same set minus the four categories pinned at CSFloat's $100,000 ceiling, which is the panel the $13.63M floor is calculated on. 248 is a different snapshot: categories priced above the cap by two or more of five marketplaces on 23 September 2026. The marketplaces overlap, so counts from different venues must never be added. Every figure here is an asking price, not a completed sale, and none of it is revenue, turnover or profit — for Valve or for anyone else. PriceEmpire's listed values are rounded estimates published by that site, and its Steam card covers items from other Steam games, so the scopes across the comparison are not identical.

One item. Two price systems.FOLLOW THE RECORD
STEAMAbout $1,800Published Community Market listing cap
SAVED CATALOGUE$10,623.95Factory New AWP Dragon Lore floor ask
THE DEPENDENCYStill a Steam itemThe inventory and transfer remain on Steam

At that ask, the seller needs an off-Steam venue or buyer. The item still depends on Steam's inventory and transfer system.

01 / ITEMValve game inventoryCS2 or Dota 2 item held in Steam
02 / CEILINGAbout $1,800 on SteamMaximum price for one Market listing
03 / OUTSIDE ASK$10,623.95 for Dragon LoreCheapest CSFloat offer in the dated snapshot
04 / DELIVERYSteam remains in the chainOwnership and item transfer rely on its system
245 CS2 categories on CSFloat.166 CS2 and 3 Dota 2 categories on Skinport.

Each figure counts item-name categories whose cheapest active offer was strictly above $1,800 on 20 September 2026. The marketplaces overlap; their counts must not be added. An offer is not a completed sale.

Inspect the item-level register →
DIRECT CSFLOAT API / DATED SNAPSHOT$13.63M

Minimum aggregate asking value in 241 item categories and 3,395 active offers. Calculated as each category's cheapest ask × its offer count. Four categories pinned at CSFloat's $100,000 ceiling are excluded from this conservative panel.

What the dollar figure shows

These offers represent at least $13,631,888.25 in posted asking prices for this limited CSFloat subset. Including the four ceiling-priced categories produces $14,231,888.25. This is a floor on active asks, not completed sales, cash turnover, profit or the entire CS2 market.

Recalculate from the 245-row CSFloat snapshot ↗
PRICEEMPIRE / LISTED VALUESteam: #15 of 39

Many venues list more dollar value than Steam.

UUSkins
$133.8M
YouPin898
$127.5M
Buff.163
$104M
Moon.Market
$100.3M
White.Market
$89.6M
Buff.Market
$86.7M
Steam
$31M

The six largest displayed values and Steam. PriceEmpire rounds these figures; Steam shows $31M. Fourteen listed venues rank ahead of it by the displayed dollar values.

PRICEEMPIRE / OFFER COUNTSteam: #1 of 39

Steam still leads in number of offers.

Steam
32.2M
YouPin898
5.9M
C5Game
4.6M
HaloSkins
4.4M
Skinport
3.8M

Steam shows 32.2M offers. Number of offers and total asking value answer different questions; many low-priced listings can dominate the count.

Source: PriceEmpire's public comparison ↗ archived 2026-09-21 ↗, captured 2026-09-20 19:03 UTC; dated 39-row extraction ↗. Its figures are rounded estimates, and inventory can overlap across sites. Steam's card also describes items from other Steam games, so the scopes are not identical. Listed value measures asking prices, not sales or revenue.
42
ANOTHER SOURCE / STEAMANALYST

The commercial ecosystem is in plain sight.

SteamAnalyst's marketplace directory archived 2026-07-19 ↗ lists 42 third-party CS2 marketplaces alongside Steam, with recent price data for 32 of the 43 entries. PriceEmpire lists 39 marketplaces under its own inclusion criteria. Named businesses, public offers, visible prices: this economy is open to inspection.

THE CEILING IS THE MECHANISM: THE SALE LEAVES STEAM, THE ITEM DOES NOT.

Across five marketplaces captured in one licensed snapshot, 248 CS2 item categories are independently priced above Steam's approximately $1,800 listing ceiling by two or more of them — and every single one is absent from Steam. The same snapshot banded the whole catalogue by price: Valve's market carries 95.3% of the item categories below its cap and 1.9% of those above it. The collapse does not track falling demand; it lands exactly on the published rule. Selling at those prices requires an outside buyer or marketplace, while Steam still controls the inventory and the transfer — the business leaves Valve's checkout and the delivery stays on Valve's infrastructure.

Steam Market FAQ ↗archived 2026-09-21 ↗Steam Subscriber Agreement ↗archived 2026-09-21 ↗Five-marketplace atlas dataset ↗Provenance manifest ↗Earlier CSFloat snapshot ↗Skinport snapshot ↗PriceEmpire ↗ archived 2026-09-21 ↗SteamAnalyst ↗ archived 2026-07-19 ↗Price-gap register ↗Price-ladder atlas ↗

Part C — Legal frameworks · Section 15 · Commercial scale

Follow the money. Separate the transactions.

The item is Valve's. The inventory is Valve's. The transfer runs on Valve's servers. Only the payment happens somewhere else — which is the step that decides whether anyone is a money transmitter, and the one step Valve does not operate.

Context & source limits

The commercial-use question becomes sharper when the money flows are separated. Third-party item transfers, Valve's primary sales and external cash-outs are different transactions.

The revenue mechanism

Where the money actually moves.

Three paths / one item economy
  1. 01 / AccountUser inventory

    Items held on Steam

  2. 02 / TransferP2P trade

    User ↔ bot or user ↔ user

  3. 03 / SettlementExternal platform

    Site balance or payment off Steam

CirculationThe economic engine extends beyond a transfer fee

Steam supplies the inventory and transfer infrastructure used by outside markets. The investigation's economic argument is that resale liquidity and repeated demand sustain spending on cases, keys and replacement items, with fees on subsequent Community Market sales. A direct P2P transfer carries no Community Market commission; that accounting fact does not settle the wider benefit. Valve retains control over account access and trading restrictions throughout.

  1. 01 / Secondary demandLiquidity & resale value

    External trading and gambling demand

  2. 02 / Primary spendingKeys, cases & capsules

    Purchases from Valve where offered

  3. 03 / RevenuePrimary-sale income

    Plus fees on actual Market sales

5% + 10%Steam + CS2 fee on Community Market sales

The investigation's economic inference: liquid resale markets can encourage spending on new items. The familiar 15% combines Market fee rates, subject to minimums and rounding; it is not a levy on every external trade.

Valve's Community Market fee schedule ↗ archived 2026-09-21 ↗. On 25 February 2026 the New York Attorney General filed an action archived 2026-09-01 ↗ alleging that paid loot boxes are connected to external cash resale and gambling harm — the same connection this dossier documents from the technical-infrastructure side. That complaint is an allegation, not a finding; it is cited here because a state law-enforcement agency has put to Valve a question adjacent to the one this dossier asks: where is the enforcement record that matches the public declarations?

  1. 01 / EntryCrypto deposit

    External service and wallet records

  2. 02 / ConversionBalance → skins

    Items delivered through Steam trades

  3. 03 / ExitExternal fiat sale

    Seller, buyer and payout provider

KYC?Identify the control at every handoff

This is the route to investigate, not a native Steam API cash-conversion service. Document identity checks, custody, transaction IDs and payout recipients at each external operator before asserting a no-KYC cash-out.

United States / Bank Secrecy Act

Classify the activity, then the obligation.

FinCEN assesses money transmission by what a business does. Accepting and transmitting convertible virtual currency can trigger money-services obligations, subject to the applicable definitions and exceptions. Valve's Steam Wallet accepts funds and converts them to in-game items; those items are then liquidated through third-party operators for real currency. The item and its transfer run on Valve's infrastructure; the cash-out does not, and whether any part of that cycle meets the money-transmission definitions is a classification question for FinCEN, not a conclusion drawn here.

FinCEN FIN-2019-G001, §§ 1–2, 5.1 ↗ archived 2025-07-11 ↗

European Union / money laundering

Trace proceeds, knowledge and assistance.

Directive (EU) 2018/1673 covers intentional laundering and participation involving criminal proceeds. The investigative question is what Valve knew about the operators using its trading and OpenID infrastructure after 13 July 2016, when it publicly described that use, and what it did about them. Valve has published no per-operator enforcement record; that record, not this dossier, would answer the question.

EU criminal-law framework ↗

AMLD6 terminology: the criminal-law directive above is distinct from Directive (EU) 2024/1640, also called AMLD6. The latter has a general transposition deadline of 10 July 2027, with specified exceptions. Article 78 ↗ archived 2026-08-30 ↗

Part C — Legal frameworks · Section 16 · Notice, response, responsibility

The Digital Services Act: put knowledge on the record

Under the DSA a hosting provider keeps its liability shield only until it has specific knowledge and fails to act. This dossier is that notice. It names the hosts, the dates, the saved responses and the hashes. From publication the question is no longer whether Valve knew — it is what Valve did next.

Context & source limits

Two elements of an Article 16 notice sit with the submitter rather than with this dossier: the submitter's own details and a statement of good faith that the information is accurate. Everything else the Article requires — the substantiated explanation and the exact electronic location — is set out in Section 3 and in the route register, with saved responses and hashes, so that any party can lodge it. Two further limits on the law itself: losing the hosting exemption does not by itself establish liability under any other law, and the 6% in Article 52(3) is a statutory ceiling, not an assessed penalty against Valve.

01July 2016 / the dossier exhibit

A ten-day demand.

The notice reconstructed above is the historical starting point for the investigation's enforcement comparison.

0217 February 2024 / general application

The DSA time window.

Separate historical conduct from conduct during the period when the relevant DSA obligations apply.

03Ten years / original dossier snapshot

Duration needs a notice trail.

The elapsed time since July 2016 (see Section 11) is a dossier metric. It is not ten years of established DSA violations. Link each notice to a specific item, applicable law, delivery evidence and response.

Part C — Legal frameworks · Section 17 · Identity, age, commercial access

Minors: a Steam login is not an age check

"Sign in with Steam" proves an account exists. It proves nothing about age — and on these sites it is the only gate between a child and a deposit. Read it with Section 3.1: inside the Steam client the warning a browser would show never fires, so the child never sees one.

Context & source limits

No minor's data appears anywhere in this dossier and none was collected: the authors did not register on, deposit at, or complete a login to any platform named. Anyone building on this section should keep evidence involving a child private and redact identifying details from public exhibits. COPPA is cited here as a children's privacy law with its own scope conditions — audience, actual knowledge, personal data collected — and not as a general gambling-age rule; the 2026 New York complaint is an allegation by a state authority, not a finding.

What Steam OpenID providesAccount identity

A verified SteamID used to log in or link an account.

What the operator must establishEligibility to participate

Age, jurisdiction and any required identity checks.

Technical basis: Steamworks OpenID documentation ↗ archived 2026-09-21 ↗. The documented identity assertion is not a certification that the user may legally gamble.

COPPA / children under 13

Identify the operator and the data.

COPPA applies to covered child-directed services and services with actual knowledge that they collect personal information from children under 13. It is a children's privacy law, not a universal gambling-age rule. Establish the audience, personal data collected, knowledge and parental-consent process.

FTC: COPPA requirements ↗ archived 2026-09-21 ↗

The evidence to preserve

Record the journey from login to deposit.

Preserve the site's age gate, registration wording, eligibility terms, payment flow and complaint history. Assess each operator separately. Keep any evidence involving a child private and redact identifying details from public exhibits.

A related public enforcement record is the 2026 New York complaint announcement archived 2026-09-01 ↗, which alleges harm to young users from paid loot boxes. It is not a COPPA finding.

Part C — Legal frameworks · Section 18 · GDPR Article 15 request

The request. The reply. The missing comparison.

He asked for four things, one of them the log that would name whoever put an API key on his account. Three days later the ticket was closed with a link to a page that holds none of them — and the sentence used to close it is contradicted by Valve's own lawyers.

Whose account this is · Provenance & Limits

These screenshots are not PhishDestroy's. They come from an ordinary Steam account holder — one respondent to a short survey run by this project, who filed the request himself and supplied the captures. The account is his, the ticket is his, and the correspondence is between him and Steam Support. This project did not submit the request, holds no account on the platform, and is not a party to this ticket.

On 16 September 2026 he filed a GDPR/CCPA Article 15 subject access request asking specifically for API-key registration logs, login history with IPs, device authorisation history and trade history. On 17 September agent "Logen" referred him to the self-service Account Data page. On 18 September he stated that the requested categories were not on that page and asked for escalation to the Privacy Team or DPO. On 19 September agent "Kal" closed the ticket with the same referral. Both screenshots are preserved below (requester e-mail redacted; SHA-256 in steam_tos_assets/screenshot-manifest.json).

He is a fitting requester for an ordinary reason: his account carries a Steam Web API key he did not create, registered to localhost. When it was created is not known — not to him, and not from anything Valve has made available to him, because the single record that would date it is the API-key registration log, which is exactly the category the closure withheld. The key is not new: it predates his awareness of it by an interval he cannot measure, for the same reason.

Other account holders are filing the same request. Any reply that arrives will be added here on the same terms as these two — ticket number, capture date, SHA-256, requester redacted — whether it supplies the categories or refuses them.

This project takes no position on why the ticket was closed. No reason was stated in it, and none is inferred here.

The request. The response. The comparison.FOLLOW THE RECORD
THE REQUESTSpecific categoriesAPI-key, login, device and trade records
THE RESPONSEAccount Data referenceInspect the support exchange
THE TESTWhat was supplied?Compare each requested category

He asked for four named categories. The Account Data page he was referred to is Valve's own self-service export, and this project cannot enumerate its contents for someone else's account — so no full category-by-category comparison is published here. What is on the record is his statement of 18 September that the categories were not there, and the closure of 19 September that repeated the referral without addressing them.

Screen 1/2 — Request (16 Sep) and first reply, agent "Logen" (17 Sep)
GDPR ticket HT-2YBP-F7JP-D4VB — request and first response
Source: help.steampowered.com, ticket HT-2YBP-F7JP-D4VB · captured 16–17 Sep 2026 · requester e-mail redacted 2026-09-21 · File: gdpr-ticket-1.png · SHA-256 da940c731ab9869d226e9d06ccc8a1b393738766b7b0c445a56662623e025a66 (screenshot-manifest.json).
Screen 2/2 — Escalation request (18 Sep) and closure, agent "Kal" (19 Sep)
GDPR ticket HT-2YBP-F7JP-D4VB — escalation request and closure
Source: help.steampowered.com, ticket HT-2YBP-F7JP-D4VB · captured 18–19 Sep 2026 · File: gdpr-ticket-2.png · SHA-256 44844ea7b251f7fd7d79f87ee1578a846606a97b9659d3a53b322120c422219b (screenshot-manifest.json).
Closing response, 19 Sep (verbatim):
"The data Steam retains can already be found in your Account Data page. As there's no further information Steam Support can offer, this request will be closed."
No data supplied · no legal basis for refusal stated · no escalation outcome shown
That sentence is false, and Valve's own lawyers prove it. Counsel's letter of 1 October 2025, paragraph 1.9, describes device-level correlation linking one device to dozens of accounts (Appendix A). The same response carried 830 pages of retained records (Appendix B). None of it is on the Account Data page.
Why this account asked for the API-key log

He did not pick those four categories at random. The localhost key on his account is the mark of a script, not of a person typing a real domain into the developer page (Section 5, Section 6). The one record that shows who created it and from where is the API-key registration log. That was the first thing he asked for. That is what the closure withheld.

Source: the account holder, during this project's survey. The ticket screenshots above are hashed; the key page is not published.

Assessment · PhishDestroy

Closing a ticket with the question still open is not an accident here. It is the normal outcome. We hold 16,319 preserved complaint and support records and 354 de-duplicated support exchanges drawn from them. This ticket is one dated, fully captured example of the shape they take.

Support Ticket — Preserved HT-2YBP-F7JP-D4VB
Request type GDPR Article 15 DSAR
Ticket status CLOSED 19 SEP 2026 — NO DATA SUPPLIED
Agents in the exchange "Logen" (17 Sep), "Kal" (19 Sep)
Filed 16 Sep 2026
Data requested Who registered the Web API key linked to this account, and from which IP / device / timestamp
Legal basis cited GDPR Art. 15 — right of access to personal data
The legal frame: Article 12(3) gives the controller one month from receipt (extendable with reasons). That period had not expired at publication, and this dossier does not assert a deadline breach. The objection is to the substance: the closing response links to a self-service page but does not show that the four named data categories were produced, and if the controller declines to act, Article 12(4) requires it to state the reasons and the complaint routes. Neither appears in the closing response.
Why this specific data matters

The Web API key event log is the record that shows whether a third party registered a key using a stolen session cookie — the mechanism described in the inventory-theft complaints preserved in this dossier's archive. Disclosing who registered an API key, from which IP, and at what timestamp, would:

  • Allow the victim to compare the API creation IP against their own login history
  • Reveal data-centre IPs linked to known phishing / gambling bot infrastructure
  • Produce evidence usable in civil or criminal proceedings against the actor
  • Show whether the account holder was notified when the key was created
What the record shows: Valve retains device-level and account-correlation records — its counsel's letter of 1 October 2025 describes them (see Appendix A, Evidence Memorandum — Source 1). In ticket HT-2YBP-F7JP-D4VB the same class of records was requested by the data subject and the ticket was closed with a referral to a self-service page that the data subject reported did not contain them. Whether that refusal is lawful is a question for the supervisory authority; the effect is that the person the data concerns does not get it.
The exchange — four messages, three days

Two Steam Support agents replied under first names shown on the ticket: "Logen" on 17 September and "Kal" on 19 September. Both referred the requester to the Account Data page. Nothing on the ticket shows whether the request reached Valve's Privacy Team or Data Protection Officer, and the dossier does not assert who the agents are, what their roles are, or how the ticket was routed.

16 SEP
Art. 15 request filed with four named data categories
17–18 SEP
Referral to Account Data; requester asks for DPO escalation
19 SEP
Ticket closed with the same referral; no data, no stated basis
What Article 15 GDPR explicitly entitles the subject to
Art.15(1)(a) Processing purposes — why Valve holds the data
Art.15(1)(b) Categories of data — what Valve holds
Art.15(1)(c) Recipients or categories of recipients — who received the data (e.g., API key holder)
Art.15(1)(d) Retention period or criteria for determining it
Art.15(3) A copy of the personal data undergoing processing — i.e., the API-key log itself
ART.12(3) Response required within one month of receipt; an extension must be communicated within that month. The period had not expired at publication. Art. 12(4): if the controller does not act, it must state why and inform the subject of the complaint routes.
Regulatory complaint pathway — for any user

Any user who submitted an Article 15 GDPR request to Valve and received no compliant response (or a template refusal without data) may file a complaint with the supervisory authority in their EU/EEA member state. Valve's EU establishment is Valve GmbH in Hamburg, so the lead supervisory authority for cross-border complaints is the Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (HmbBfDI). (Valve's Article 27 representative is also located in Hamburg; a representative's address does not by itself determine the competent authority.) A complaint may also be filed with the authority of the complainant's own member state under Article 77.

Ticket reference for any complaint: HT-2YBP-F7JP-D4VB — preserved in this dossier as a documented instance.

One documented instance

The records exist; the data subject did not receive them.

Valve's counsel described device-level correlation records in a letter of 1 October 2025. On 19 September 2026 an Article 15 request for the same class of records was closed with a referral to a self-service page the requester reported did not contain them, without a stated legal basis. Ticket HT-2YBP-F7JP-D4VB is one documented instance; whether it reflects a wider practice is a question for the supervisory authority, which can ask Valve for its handling records.

Part C — Legal frameworks · Section 19 · Contract law

The Subscriber Agreement against the platform's own architecture

Three of the SSA's central provisions sit awkwardly with how the platform is built: the commercial-use prohibition against a Market price ceiling that pushes high-value sales off-platform; the user-liability clause for API keys against a key endpoint that, before 2023, required no second factor; and the enforcement language against a public record that shows no per-operator enforcement. Whether these tensions affect enforceability is a question for a court; this section sets out the facts a court would have before it.

Context & source limits

The authors are not lawyers and none of this is legal advice. The SSA is quoted from the revision of 10 September 2026; a different revision may read differently, and clause numbering has changed across revisions — check the clause against the version that governed the conduct in question. The Articles 25 and 32 arguments state what the regulation requires, not that a supervisory authority has found a breach. The figures in Argument 1 carry the scope limits set out in Section 13.

Argument 1 / Market Cap Architecture

The Market ceiling and the commercial-use prohibition

The Steam Community Market has a listing ceiling of about $1,800. Across five marketplaces in a dated snapshot (23 Sep 2026), 248 CS2 item categories are independently priced above that ceiling by two or more of them; such items cannot be sold at those prices on Valve's own platform. Owners who want those prices use third-party markets, which run on Steam accounts and the Steam API — use that the SSA classes as commercial unless expressly permitted.

Items exceed the Market ceiling → third-party markets fill the gap → those markets use Steam accounts and the Steam API → the SSA prohibits commercial use without permission → no register of permissions has been published. The Community Market's combined fee of about 15% applies only to sales completed inside the Market, not to these external trades.
Argument 2 / API Key Security Architecture

The API-key vulnerability as a platform design question rather than user negligence

Before 2023, Steam's API key creation endpoint accepted a POST with a stolen sessionid and generated a high-privilege credential without e-mail confirmation, a second factor or device verification. The API hijack complaints collected in this investigation follow one pattern: attacker script, stolen session cookie, silent key creation, trade interception (the request payload is shown in Section 8).

GDPR Article 25 (data protection by design) and Article 32 (security of processing) require technical measures appropriate to the risk. Issuing a credential capable of trade interception without a second factor or owner notification is a design question for the controller. Whether the SSA clause placing liability on the user can be relied on against that background is a question for a court and the supervisory authority.

Argument 3 / Real-Time Visibility

Valve receives the auth hostname on every login

The auth hostname arrives at Valve's OpenID endpoint in plaintext in openid.return_to and openid.realm (the request shape is shown in Section 3). Extracting it is a standard operation. As of 2026-09-22, in 26 pairs the main domain was on the Link Filter while the host carrying its Steam login was not. Valve has published no per-operator enforcement record, so whether any measure other than the Link Filter has been applied to these hosts cannot be established from public data.

Who bears the cost

The pattern in the archived complaints

In the reviewed complaints, Steam Support's response to an API-key hijack claim follows one form: decline restoration, cite the user's responsibility for the account and its API key, close the ticket. No aggregate figure for accounts affected or value lost is estimated in this dossier; no source for such a figure has been located.

The question is not whether individual users made mistakes. The question is who is responsible for an architecture that, until 2023, allowed a POST request with a stolen cookie to create a high-privilege trading credential with no notification and no second factor.
The SSA as a document vs the SSA as a contract

A court evaluating this record would not read the SSA in isolation.

It would read it alongside counsel's October 2025 letter describing device-level correlation, the auth-host registration dates, the batch registration timestamps, the API-key request payload, and the ten years between the July 2016 notices and the platforms still operating in September 2026. That is the record Valve would have to address.

Appendix B — The produced PDF · redaction check

The redaction in the produced PDF is cosmetic: the covered text remains extractable

Valve's counsel answered a GDPR access request with an 830-page appendix in which the redactions are painted over the text rather than removing it. 902,270 characters sit under the black bars and come straight out with a text-extraction tool — including the third-party identifiers the bars were there to withhold. Only aggregate counts are published here; no covered content is reproduced, and the appendix itself is not published.

1. What the geometry check found

The GDPR Art. 15 response dated 1 October 2025 was accompanied by an 830-page PDF appendix (Aspose.PDF for .NET producer metadata, created and modified on the same date). The authors ran a page-level geometry check: for each page, opaque near-black rectangles painted after the text layer were located and the extractable characters lying beneath them were counted.

Measured on the produced file
902,270
Characters still extractable from under the black bars
Counted, not estimated. This is a count of covered characters — not of victims, re-identifications or incidents.
830 / 830
Pages affected — every page
986
Rectangles over extractable text
1,329
Opaque black rectangles in total
The black bars are drawn over the text layer; they do not remove it. Text under the bars can be extracted with standard PDF tools. Only aggregate counts are published; no covered content is reproduced here.
Forensic Demonstration: Layer Separation
ASPOSE.PDF FOR .NET VECTOR OVERLAY MOCKUP (APPENDIX P. 412)

Report filed against account: [LOGIN: redacted_user_667]

Reason submitted by user: [TEXT: "User reports duplicate items in inventory and abusive trade conduct..."]

Foreground: <path fill="#000" /> Flaw: Underlying UTF-8 stream intact
Source: PDF appendix to the counsel letter of 1 October 2025 (830 pages, Aspose.PDF for .NET producer metadata) · measured by the authors, method and per-page counts in disclosure-audit.json · SHA-256 of the appendix recorded in the same file · the appendix itself is not published.
2. Why this matters for a data-subject response

Valve's counsel sent this file to a data subject in answer to a request for that person's own records. The bars on it are cosmetic: the text underneath was never removed, so the third-party identifiers the bars were applied to withhold went to the recipient along with the file. A redaction that lifts with a text-extraction tool withholds nothing, and it also leaves the recipient unable to establish what was disclosed and what was not.

Article 15(4) is the reason those bars exist at all: the right to obtain a copy must not adversely affect the rights and freedoms of others. That is the obligation this production did not meet. Whether it is characterised as a personal data breach under Art. 4(12) is for the supervisory authority to determine; the disclosure itself is measurable in the file, and reproducible by anyone holding the same bytes — the SHA-256 is published, the appendix is not.

What was under the bars was not account numbers. It was the body of user reports filed against the requester, with their authors attached: Steam logins that, because a login is rarely used only on Steam, identify the person behind them — on the authors' count, over 60% of the users named in the document are fully identifiable — together with the raw, unredacted text of what they wrote. That text includes death wishes and abuse directed at the requester's nationality. Some of the people so identified are minors. The production handed a named list of reporters to the person they had reported, which is the precise harm Art. 15(4) is written to prevent.

The sequence around the file matters as much as its contents. The request was met first with a demand for further proof of identity, on the ground that the requester's alias email address did not contain his name; the account was permanently banned during the delay that followed. The letter that finally delivered the data, more than six weeks past the Art. 12(3) month, threatened the recipient with criminal prosecution and withheld the remainder of his own data until he explained his account activity to counsel. The disclosure also settles two questions Valve has not answered in public: the records produced show account-linking reaching back to 2019, and internal telemetry of a depth Valve has never described.

Scope of this section: the observation here is limited to the mechanics of the redaction, measured on the file as produced. The authors' further analysis of the produced logs is withheld pending independent review and is not relied on elsewhere in this dossier.

Evidence: counsel letter of 1 October 2025 and its PDF appendix (SHA-256 recorded in the audit file); page-level PDF measurements and method ↗. The sequence of the request, the page-8 refusal and the characterisation of the exposed records are set out in full in PhishDestroy's account, “My Dog vs. Elite GDPR Lawyers”, 17 August 2026 ↗ archived 2026-08-21 ↗. Account names and third-party data are omitted here; nothing covered by the bars is reproduced.

Page 8 of the covering letter refuses part of the request, and states the reason in writing: Eine genauere Auskunft ist aufgrund des Schutzes der personenbezogenen Daten anderer Nutzer der Steam-Plattform… nicht möglich. — a more detailed answer is not possible, because the personal data of other Steam users must be protected. The 830-page appendix was in the same package. What the bars covered was not account numbers: it was the reports filed against the requester, their authors named, with the raw unredacted messages attached. The account holder had asked Valve, through its counsel, for his own file; what he could extract from it was other people's. Nothing in this appendix turns on who drew the boxes. What it establishes is that the protection Valve invoked as its ground for withholding is the protection this same production failed, in the same envelope, on the same day.
Appendix D — Source collection

Selected primary records

Six records from the archive — three GitHub issues in Valve's trackers and three Reddit accounts of disputed support outcomes. Each source stays attached to the claim, the saved text and the question it raises.

GH-01 / GITHUBOpen in saved build

Hardware keys, requested in 2016

A user asked Valve to support U2F hardware keys as an alternative second factor. The saved issue carries both Feature Request and reviewed labels, with its state recorded as open.

I request U2F usb dongle support in steam as an alternative.

Excerpt from the GitHub issue ↗
Documented record
A dated request for an additional account safeguard, published in Valve's own issue tracker and labelled reviewed.
Accountability demand
Publish the product decision, the response date and the protection delivered after review.
In the dossier: Account safeguards →Archive #484 · build 2026-09-17
GH-02 / GITHUBOpen in saved build

Crash reports without an effective opt-out

The reporter describes a Steam client from 12 August 2019 on Ubuntu 16. They say disabling the crash-upload destination did not persist after a restart, and include the relevant configuration.

If I disable the `ServerURL`, it gets overwritten after every reboot.

Excerpt from the GitHub issue ↗ archived 2026-04-19 ↗
Documented record
A specific privacy complaint with a client date, operating system and configuration excerpt. The saved issue is open.
Accountability demand
Identify the investigation, the affected builds and the change that made the opt-out effective.
GH-03 / GITHUBOpen in saved build

Auth-ticket abuse reported to Valve

The author alleges that a server operation retained Steam authentication tickets after players disconnected and used misleading server listings. The post asks Valve to address the behavior.

Making their servers look packed.

Excerpt from the GitHub issue ↗
Documented record
A public abuse report lodged in Valve's tracker on 26 February 2022. Its saved state is open; the report includes links to screenshots.
Accountability demand
Produce the investigation result and the mitigation record for the reported authentication-ticket abuse.
In the dossier: Dataset scope →Archive #768 · build 2026-09-17
RD-01 / REDDITAuthor's account

44 disputed Market purchases

The author reports 44 unauthorized Market purchases on 6 July 2022 and roughly $500+ in losses. They say two-factor authentication was enabled and describe repeated template replies from support.

2nd ticket in and I have still yet to receive a non robotic copy paste template response from Steam.

Excerpt from the Reddit post ↗ archived 2025-03-20 ↗
Documented record
A dated account of disputed purchases, with links to transaction screenshots and a support response. The amounts and events are the author's report.
Accountability demand
Reconcile the disputed purchases with transaction and session logs. Explain the evidence behind support's decision.
In the dossier: Support and enforcement →Archive #4,533 · build 2026-09-17
RD-02 / REDDITAuthor's account

A permanent ban and closed appeals

The author disputes a permanent ban and says support cited suspected account transfer and community reports. They describe closed tickets and plans to request their personal data.

I explained my situation and asked for more details, but they're sticking to their decision and closing my tickets.

Excerpt from the Reddit post ↗
Documented record
A preserved appeal account, including the reasons the author says support supplied and links to four images. The post date comes from the selected support export.
Accountability demand
Identify the evidence supporting the permanent ban and the review available to challenge it. Closing an appeal does not explain the decision.
In the dossier: Request the underlying records →Archive #4,766 · build 2026-09-17
RD-03 / REDDITAuthor's account

A recovery reset and a reported $10,000 loss

The author alleges that support reset credentials and disabled account protections after someone else submitted a recovery ticket. They report a loss of about US$10,000 from an inactive account.

Steam Support reset my password and turned off all my account security.

Excerpt from the Reddit post ↗
Documented record
A preserved allegation about the recovery process overriding account safeguards. The saved post records what the author says support told them.
Accountability demand
Identify who authorised the reset, the ownership evidence they accepted and the access log. Account recovery is part of the security system Valve controls.
In the dossier: Request the underlying records →Archive #4,592 · build 2026-09-17

Six selected records. GitHub states describe the saved build. Reddit posts preserve the authors' accounts.

Download the six records ↓

The searchable build contains 16,319 distinct records: 393 Trustpilot, 5,635 Reddit, 2,395 GitHub, 276 web and 7,620 wiki records. Multiple records can concern the same event. The separate 40,448-row master export has a different scope.

Search the full archive ↗ · Build manifest ↗ · Dataset scope and counts →

Appendix E — Case study

ArchiSteamFarm and the automation clause

An open-source card-farming tool whose own FAQ states it runs on millions of accounts, set against the Subscriber Agreement clause (§ 4.C) that prohibits automation. The mechanics — what a farm has to buy from Valve before it can produce anything, why every way of cashing out a card breaches the licence, the enforcement record and who moderates the card economy — are set out in full in Exhibit V ↗.

The Steam Subscriber Agreement, § 4.C, states:

"You may not use any form of scripts, bots, macros, or other non-human-controlled systems ('Automation') to interact with Content and Services on Steam in any manner." — Steam Subscriber Agreement § 4.C (current) ↗ archived 2026-09-18 ↗

Valve enforces this clause. It is very good at it. The FAQ of ArchiSteamFarm (ASF) — an open-source tool its own documentation describes as running on more than a few million Steam accounts since a first release over 11 years ago — reproduces three Steam Support messages permanently banning users who ran bot networks. Valve found the networks, named them and killed them. The relevant question is therefore not whether Valve can detect automation at scale.

The project's official ArchiSteamFarm FAQ addresses the risk of a ban directly:

"This is extremely unlikely considering the fact that ASF is being used on more than a few million of Steam accounts, since its first release that happened over 11 years ago — but still a possibility, regardless of actual probability."

"Valve clearly acknowledges 'Steam idlers' existing, as stated here, so if you asked me, I'm pretty sure that if they weren't fine with them, they'd already do something instead of pointing out that they could cause problems VAC-wise. The key word here is Steam idlers, for example ASF, and not game idlers."

— ArchiSteamFarm FAQ, JustArchiNET. Source: GitHub wiki ↗ · verified verbatim 2026-09-22

The same FAQ answers "Did anybody get banned for it?" with Yes, and reproduces what Steam Support wrote to three of them:

1,000+ bots · trade banned
"It looks like this account was used to manage a network of bot accounts. Botting is a violation of the Steam Subscriber Agreement."

170+ bots · permanently banned, 2017 Winter Sale
"this account was used to illegally collect collectible cards on Steam, as well as related and not only commercial activities. The account has been permanently blocked and Steam Support can not provide additional support on this issue."

120+ bots · permanently banned
"This and other accounts were used for flooding our network infrastructure, which is a violation of Steam online conduct."

— Steam Support messages reproduced in the ArchiSteamFarm FAQ, section "Did anybody get banned for it?". Source ↗ · verified verbatim 2026-09-22

Put the two records side by side. A private user with 1,000 farming bots is identified, told that "botting is a violation of the Steam Subscriber Agreement", and permanently removed. The commercial platforms in this dossier run automated Steam accounts as their core business, at far greater scale, and authenticate through Valve's own OpenID on every login — and no per-operator enforcement record has been published for any of them. The clause works. The question is who it is pointed at.

ASF is not accused of anything here, and its reading of Valve's position is its own — its author states plainly that "ASF is not authorized by Valve". The tool is used here as a measuring instrument: it shows that Valve detects bot networks, names them in writing and bans them permanently. Valve can close the question in one sentence by publishing which commercial automation it authorises, and the per-operator record of what it did about the rest.

Where card farming touches Valve's revenue

Farmed trading cards are sold on the Steam Community Market, which charges a combined fee of about 15% on each sale completed inside the Market; the account must have spent $5.00 USD on Steam before it can receive a card at all; and card drops require game ownership or in-game purchases. No aggregate revenue figure is estimated here — the operating scale is stated only as the ASF FAQ states it. The FAQ also records Valve distinguishing "Steam idlers" (card farming) from "game idlers"; see the ASF FAQ ↗. The mechanics are set out in full in Exhibit V — the scale and the commercial-use trap.

Subject ArchiSteamFarm — automated card farming
Stated scale Millions of accounts (per ASF FAQ — exact active count unverified)
Counted, not quoted 10,880,610 total API entries in ASF's own Steam group (5,360,499 non-limited, as Steam displays) — the FAQ's "millions" is not a story, it is a headcount. 88.97% carry no Steam ban of any kind. The full ban census ↗
Disclosures in the tool's own documentation
  • ASF logs accounts in headlessly and idles games for card drops without launching the Steam client (per the project documentation).
  • The FAQ reasons that Valve is aware of "Steam idlers" and that "if they weren't fine with them, they'd already do something".
  • No targeted enforcement reported in over 11 years (per the FAQ); the resulting card sales inside the Community Market carry Steam's combined fee of about 15%.
  • The FAQ states a recommended ceiling of ten accounts per operator and attributes it to Valve: "This recommendation is based on internal Valve guidelines, as well as our own suggestions." No such guideline is published by Valve.
  • Technical ceiling, per the same FAQ: "you can run up to 100-200 bots with a single IP and a single ASF instance."
  • Farmed playtime is recorded by Valve — "it's usually updated every 30 minutes or so" — and § 4.C lists "Faking gameplay statistics (e.g., inflated wins or losses, XP, playtime)" as a prohibited act.
The automation clause is explicit; the ASF FAQ has stated for years that the tool runs on millions of accounts; no targeted enforcement against it has been reported. The gap between the rule and its application is the record; the reason for it is not established here.
Appendix G — From a template refusal to the underlying record

DSAR playbook: request the evidence

Use Article 15 GDPR to request personal data relating to API-key creation, account recovery and support access. A retained record can test who initiated an action and what the platform relied on.

  1. 01

    Preserve your timeline.

    Save account notices, tickets, trade IDs and dates in UTC. Secure the account and review the recovery options applicable to the game and transaction.

    Steam Trade Protection information ↗
  2. 02

    Request your retained data.

    Ask for timestamps, source IPs, key lifecycle events, security confirmations and account-related recovery actions. Include support-access events and recipients where those data concern you.

  3. 03

    Keep the delivery record.

    Use Valve's privacy contact route. The usual response period is one month; a necessary extension of up to two further months must be explained within that first month.

    Valve privacy contact route ↗ archived 2026-09-21 ↗
  4. 04

    Compare the response.

    Reconcile logs with your timeline. Ask for reasons for omissions, then use the supervisory-authority complaint route if necessary. Preserve the response exactly as received.

Data subject access requestGDPR / Article 15

Account security & access records

Replace the bracketed fields before submitting.

To: Valve Privacy Team
Subject: Article 15 GDPR request — account security records

Account / SteamID: [YOUR ACCOUNT IDENTIFIER]
Relevant period (UTC): [START] to [END]
Related support tickets: [TICKET REFERENCES]

I request a copy of the personal data concerning me that you retain for this period, including:

1. API-key registration, confirmation, use and revocation events, with available timestamps, source IP addresses, registered domains, device or user-agent information and non-secret key identifiers.

2. Recorded account-recovery actions, password/email/phone changes, Steam Guard removals or resets, confirmation events and the account-related evidence relied on to authorize those actions.

3. Personal data in support-access and administrative-action logs concerning my account, including available dates, purposes, actions and the support entity involved, subject to applicable rights of others.

4. Account-related records used to determine any sanction, and available records of my complaints, reviews and responses.

Please also provide the applicable processing purposes, categories, recipients, retention periods or criteria, and available information about sources where data were not obtained from me.

Where processing relies on my consent, please provide the retained record of the consent relied upon and the wording presented at that time.

Please provide an intelligible electronic copy with time zones and field definitions. Please do not include active credentials or secret tokens. If any requested data are not held, please say so. For any withheld data, please identify the scope and legal basis of the restriction and provide the remainder.

Please acknowledge receipt and respond within the applicable Article 12 period, explaining any necessary extension. I also ask you to preserve relevant existing records while this request is handled.

Name: [YOUR NAME]
Date: [DATE]
Download .txt

What a data-centre IP can establish

A discrepancy is evidence to investigate.

An API-key request originating from a data-centre network, as in the hosting-provider example raised in this investigation, can be relevant when compared with login records, confirmations and the user's timeline. An IP alone does not identify the actor or automatically defeat every defence. Evidence that a hostile actor supplied the recorded consent could challenge reliance on that consent; other legal bases and liability issues require separate analysis.

See the preserved ban-and-GDPR complaint →
Appendix H — Wayback Machine archive analysis · published support statistics

Support volume. Published response times.

Compare Valve's archived support figures across the saved snapshots. The methodology explains what those figures can and cannot measure.

Context & source limits

Valve publishes daily support statistics at store.steampowered.com/stats/support. Wayback Machine archives preserve historical snapshots of this page from 2018 to 2026. The volume-to-headcount ratio implied by these figures is inconsistent with per-ticket human review at the published response times.

Volume against published response time (2018 → 2026)

Two queues at one support desk, read across 21 archived captures.

Valve publishes live support figures at store.steampowered.com/stats/support. Each point below is the lower bound Valve itself printed on that page on the day the Internet Archive captured it — not an estimate of ours. Both series are the same measure in the same unit, so they belong on one axis and can be read against each other directly.

Refund requests — money Valve is holding Account security & recovery — the account you have lost
Published lower-bound response time, refunds against account recovery, 2018–2026 Two series from 21 archived captures of Valve's public support statistics page. The refund lower bound stays between 49 and 55 minutes throughout. The account-recovery lower bound holds near 2.4 hours until December 2022 and stands between 5.8 and 10.9 hours in the 2026 captures. 0 h 2 h 4 h 6 h 8 h 10 h no captures · 38 months 2019 2020 2021 2022 2023 2024 2025 2026 8 h 44 m account recovery 52 m refunds 15 m — one capture only 2018-02-03 · refunds 50.12 minutes to 1.52 hours · account recovery 2.51 hours to 1.80 days 2018-05-07 · refunds 53.83 minutes to 1.47 days · account recovery 2.45 hours to 2.22 days 2018-08-02 · refunds 50.27 minutes to 1.59 hours · account recovery 2.44 hours to 22.17 hours 2018-11-03 · refunds 49.28 minutes to 1.54 hours · account recovery 2.42 hours to 1.31 days · capture archived in Czech 2019-02-01 · refunds 50.13 minutes to 1.52 hours · account recovery 2.44 hours to 2.04 days 2019-05-18 · refunds 51.03 minutes to 3.12 hours · account recovery 2.46 hours to 20.39 hours 2019-09-07 · refunds 50.65 minutes to 1.66 hours · account recovery 2.42 hours to 13.59 hours 2019-12-13 · refunds 50.77 minutes to 1.55 hours · account recovery 2.45 hours to 1.13 days 2020-03-25 · refunds 49.45 minutes to 1.53 hours · account recovery 2.48 hours to 3.62 days · capture archived in French 2020-06-26 · refunds 48.98 minutes to 2.29 hours · account recovery 2.39 hours to 6.99 hours 2020-10-21 · refunds 50.80 minutes to 1.54 hours · account recovery 15.33 minutes to 8.62 hours 2021-03-20 · refunds 50.80 minutes to 1.64 hours · account recovery 2.34 hours to 11.62 hours 2021-06-26 · refunds 51.93 minutes to 6.73 hours · account recovery 2.40 hours to 15.63 hours 2021-10-10 · refunds 51.88 minutes to 3.25 hours · account recovery 2.39 hours to 13.05 hours 2022-01-31 · refunds 53.65 minutes to 8.09 hours · account recovery 2.42 hours to 15.29 hours 2022-05-09 · refunds 51.83 minutes to 1.65 hours · account recovery 2.41 hours to 16.90 hours 2022-09-05 · refunds 53.67 minutes to 4.15 hours · account recovery 2.45 hours to 1.22 days 2022-12-08 · refunds 54.83 minutes to 6.67 hours · account recovery 2.46 hours to 18.89 hours 2026-02-01 · refunds 50.30 minutes to 1.52 hours · account recovery 10.91 hours to 21.30 hours 2026-05-09 · refunds 50.12 minutes to 1.52 hours · account recovery 5.81 hours to 15.60 hours 2026-08-10 · refunds 52.05 minutes to 2.07 hours · account recovery 8.73 hours to 16.52 hours
49–55 minThe refund lower bound in every capture from February 2018 to August 2026. Across eight and a half years it moves by under six minutes, while daily refund volume moves by a factor of nine.
2.4 h → 8.7 hThe account-recovery lower bound sits near 2.4 hours in every capture through December 2022 but one. In the three 2026 captures Valve publishes 10.9 h, 5.8 h and 8.7 h.
×2.8 → ×13How much slower recovery is than refunds, by Valve's own published figures. Steady for five years, then it widens — the queue that got slower is the one where the user, not Valve, is out of pocket.

Source: 21 Wayback Machine captures of store.steampowered.com/stats/support, 2018-02-03 to 2026-08-10; extraction in VALVE_EVIDENCE_PACK/databases/steam_support_stats_history.json. Read the limits with the figures: the chart plots the lower bound of the range Valve prints. The published upper bound is worse on both lines — refunds ranged 1.5 hours to 1.5 days, recovery 7.0 hours to 3.6 days. Two captures were archived in a localised edition of the same Valve page — 2018-11-03 in Czech, 2020-03-25 in French — and are marked (cs) and (fr) in the table; their figures appear here with the unit words translated and the numbers as published, and the verbatim source strings are kept in the extraction file. Every capture published a response time for both queues, and no point on either line is interpolated. The single 15-minute recovery figure of 2020-10-21 is flagged on the chart and left in: it appears in one capture only and no other capture is within an order of magnitude of it. No capture exists between 2022-12-08 and 2026-02-01; that 38-month hole in the record is shaded, and nothing is drawn across it. These figures describe published response times. They do not show what happens inside a ticket, and Valve has published no headcount against which to read them.

Open every capture as a table
Every archived capture, as published
CaptureRefunds / dayRefund responseRecovery / dayRecovery response
2018-02-0398,78850.12 minutes to 1.52 hours25,6622.51 hours to 1.80 days
2018-05-0760,49453.83 minutes to 1.47 days24,2262.45 hours to 2.22 days
2018-08-0269,08450.27 minutes to 1.59 hours28,9532.44 hours to 22.17 hours
2018-11-03 (cs)63,41049.28 minutes to 1.54 hours33,9102.42 hours to 1.31 days
2019-02-0176,30550.13 minutes to 1.52 hours35,1642.44 hours to 2.04 days
2019-05-1878,95151.03 minutes to 3.12 hours27,5142.46 hours to 20.39 hours
2019-09-0778,94150.65 minutes to 1.66 hours28,8122.42 hours to 13.59 hours
2019-12-1369,58950.77 minutes to 1.55 hours25,3222.45 hours to 1.13 days
2020-03-25 (fr)139,27849.45 minutes to 1.53 hours32,3022.48 hours to 3.62 days
2020-06-26278,50448.98 minutes to 2.29 hours20,3432.39 hours to 6.99 hours
2020-10-21107,63350.80 minutes to 1.54 hours20,68815.33 minutes to 8.62 hours
2021-03-20158,95650.80 minutes to 1.64 hours25,7602.34 hours to 11.62 hours
2021-06-26547,90751.93 minutes to 6.73 hours29,7282.40 hours to 15.63 hours
2021-10-10170,10351.88 minutes to 3.25 hours23,9892.39 hours to 13.05 hours
2022-01-31354,38653.65 minutes to 8.09 hours24,3912.42 hours to 15.29 hours
2022-05-09172,55551.83 minutes to 1.65 hours23,2892.41 hours to 16.90 hours
2022-09-05153,45353.67 minutes to 4.15 hours23,5942.45 hours to 1.22 days
2022-12-08181,07554.83 minutes to 6.67 hours27,1112.46 hours to 18.89 hours
2026-02-01317,76250.30 minutes to 1.52 hours47,19710.91 hours to 21.30 hours
2026-05-09246,77650.12 minutes to 1.52 hours35,2645.81 hours to 15.60 hours
2026-08-10373,24452.05 minutes to 2.07 hours45,3198.73 hours to 16.52 hours
KEY OBSERVATION:
Across 21 Wayback captures spanning 2018-02-03 to 2026-08-10, daily refund submissions ranged from 60,494 (May 2018) to 547,907 (June 2021) — a 9.1× spread. The 2026 figure is 373,244 (+278% vs the February 2018 capture).
Over those same nine years the published lower bound for refund response time never left a 49–55 minute band: a total movement of under six minutes while the workload behind it moved by a factor of nine.
If a person read each ticket for even 5 seconds, processing 373,244 tickets per day (current) would occupy 22 agents working 24/7 just to open and close them; at peak (547,907, June 2021) that rises to 32.
If the published response time reflected per-ticket handling time (~52 min/ticket), the implied concurrent staffing would be on the order of 13,500 agents at current volume and ~20,000 at peak. No sourced figure for Valve's support headcount has been located; none is assumed here.
What follows: the volume-to-headcount ratio is inconsistent with per-ticket human review at the published response times. The figures are consistent with a largely automated first pass; what proportion receives human review is not published.
Why this matters for GDPR compliance

GDPR Article 22 prohibits solely automated individual decision-making that produces significant legal effects, without providing the right to human review on request. If Steam Support decisions (ticket closures, account actions, refusal of data requests) are made entirely by automated scripts, every such decision that "significantly affects" the user may violate Article 22.

Ticket HT-2YBP-F7JP-D4VB (Section 18) was closed after three days with a template referral and no engagement with the legal basis cited. Whether a person reviewed it cannot be determined from the ticket; that is a question the supervisory authority can put to Valve under Article 22 and Article 15(1)(h).

Source: Wayback Machine snapshots of store.steampowered.com/stats/support (2018-02-03, 2021-06-26, 2026-08-10) — data extracted into VALVE_EVIDENCE_PACK/databases/steam_support_stats_history.json (21 snapshots, 2018–2026). Note: the "~52 min" response time is the refund-category lower bound; account security response was 2.4–16.5 hrs across the same snapshots. 2021-06-26 is the all-time peak (547,907 refund requests), not a monotone midpoint — volume surged ~6× in 2020–2021 then partially fell before recovering to 373K in 2026.
Appendix I — Dataset scope · counts that can be reproduced

Count the records. Check the scope.

Inspect the underlying datasets, reproduce the counts, and distinguish source rows from unique incidents.

Context & source limits

Count the records, then test the claims: every figure below is re-derivable from the published files.

The master CSV contains 40,448 rows. Of these, 36,516 come from the Discord-AntiScam phishing feed. The remaining 3,932 rows span GitHub, reviews, search results, forum material and other sources, providing a comprehensive index of reported community topics and security reports.

Within that CSV, 1,690 rows are categorised under the "Unpatched Security Exploit" collection label, representing historical user issues and vulnerability disclosures. Tracing these reports involves reviewing each thread's specific build timeline and public patch history.

The 16,319-record searchable archive is a separate, curated build with its own manifest, designed for precise local exploration of specific user claims and incident reports.

To build a reliable audit trail, every user-reported record must be verified against documented build timelines and historical patch logs.

The separate Part II collection records 231,829 unique listing IDs, including 33,509 in the automated registration category and 198,320 flagged as unverified transfers. The input file's SHA-256 matches the preserved measurement. These counts describe listing attempts and observed transfers rather than finalized transaction values or verified theft totals, highlighting the need for primary platform records to measure the exact economic impact. Listing measurements and hashes ↗

Master CSV ↗ · Searchable archive manifest ↗ · Inspect source records ↗

Appendix J — About this investigation

Valve publishes no enforcement record.
We built one.

Independent. Non-commercial. Built from public data only. Submitted to regulators.

88.97% automation fleet untouched — no ban of any kind
67.77% of 51,732 adjudicated scammers walk free
$26.8M+ floor on store spend by non-limited fleet
3.6% gambling domains blocked by Valve's Link Filter
8 years of security incidents documented

What this is. A forensic dossier into Valve Corporation's Steam platform — its enforcement record, its card-farming economy, its legal framework, and the authentication infrastructure that gambling operators use through Steam's own OpenID relay. Every figure is reproducible from two sources: Valve's own public API and the datasets published alongside this investigation.

Who it is for. Regulators with jurisdiction over Valve — the GDPR supervisory authority for the Netherlands, FinCEN, the SEC, the DSA Digital Services Coordinator, UOKiK, and any law enforcement agency examining Steam-linked financial flows. Also for journalists, researchers, and every user who received a permanent account ban, a refused refund, or a stolen inventory and was told there is no appeal.

The single demand. Valve holds this data at full fidelity — ban reasons attached, full ID space, real-time. It can run every query in this dossier in seconds and has chosen not to publish any of it. The question for any competent authority is simple: why not?

What the authors do not claim. No login to Steam was completed on any third-party platform during this work. A supplied OpenID URL establishes the request parameters, not a completed login. A separate registrable domain is not by itself proof of evasion. Registration dates are lower bounds on when a host could first have appeared in an OpenID request; they do not establish continuous use. The authors do not assert what Valve knew or intended: every statement about Valve is tied to a dated public document or a dated observation. Where a claim could not be put behind a source document, it has been removed.

Who we are

PhishDestroy — independent investigators. No affiliation with Valve Corporation or any platform named here. One Steam account was used solely to document the GDPR request in Section 18.

Legal disclaimer

Non-commercial, decentralized public-interest investigation. All data provided "as is" with zero warranties. This publication is not a judicial finding.

PUBLIC DOMAIN
Licensing

All rights surrendered to humanity. Reproduce, adapt, publish — attribution not required. OFAC-region access: prohibited. Full licence & disclaimer →