< meta name="referrer" content="strict-origin-when-cross-origin" />
PART II / OSINT FORENSICS ACTIVE
REPOSITORIES: 252 ANALYZED
DEVELOPER PAIRS: 4,214 MAPPED
SUPPORT ALLEGATIONS: AUDITED
PROVENANCE HASHES: SHA-256 LOGGED
Skip to Part II

THE STEAM DOSSIER / II

Your account.
Their access.
Who answers?

Public automation. Outsourced support. The people left counting the cost.

Follow the infrastructure, the reported losses and the documents behind the claims.

Trace the infrastructure ↘
EXHIBIT 01 / LIVE SHADOW MARKET SURVEILLANCE550,000+

Steam accounts actively on sale on LZT Market
at this very moment

550,000+ LIVE INVENTORY · 231,829 IN HISTORICAL SCRAPED CORPUS (198,320 STEALER LOGS)

The primary underground clearinghouse for hijacked Steam accounts, lzt.market (Lolzteam / Zelenka), authenticates both buyers and sellers using Valve's official Steam OpenID (openid.realm = https://lzt.market). At any given minute, over half a million stolen and compromised accounts (stealer logs from RedLine/Lumma, phishing captures, credential stuffing) are actively listed for pennies ($0.50–$2.00). Neither lzt.market nor lolz.team is blocked by Valve's Link Filter. This is the industrial reservoir supplying the 63.06% paid bot accounts that Valve bans without assisting the victim.

Live Intel: Shadow Market Monitoring (550k+ Live) ↗ · Open capture record ↗ · Open Link Filter trace ↗550K+ LIVE

01 / AN ECOSYSTEM WITH AUTHORS

Automation has
a paper trail.

Named projects. Published capabilities. Trace a tool to its documentation, then inspect the collected developer relationships.

252REPOSITORIES COLLECTED
3,320GITHUB PROFILES
4,214PROFILE–REPOSITORY PAIRS
Valve infrastructure Community libraries Reusable applications
Lines show documented integrations or dependencies. Select a node to follow its evidence.
What the developer graph establishes

The graph maps published contributor and forker relationships between named projects and GitHub profiles. These are public records — repository forks, contribution lists, profile associations. The question is what the paper trail of published capabilities and developer relationships requires Valve to answer, not what this investigation invented. Source hashes are saved in the map provenance.

02 / DIFFERENT CREDENTIALS. DIFFERENT POWERS.

Which key
are we talking about?

Playing a game does not require the player to issue a personal Web API key. That is the distinction at the centre of this inquiry.

01 / USER ACCOUNT

Personal Web API key

steamcommunity.com/dev/apikey

Issued from a user account for permitted API calls. Key creation, visibility, revocation and abuse detection are account-security questions.

02 / GAME BACKEND

Publisher Web API key

Steamworks partners use publisher credentials for supported backend operations, including game-related services. A player’s personal key is a different credential.

03 / IDENTITY & SESSION

OpenID / session tokens

OpenID confirms identity to a website. A Steam session or refresh token has a different purpose. These mechanisms should not be presented as one interchangeable “API key”.

Valve documents both user and publisher Web API keys. The entire Web API is therefore not separate from Steamworks. API key documentation ↗ archived 2026-09-15 ↗ · Game-session authentication ↗ archived 2026-08-29 ↗

THE HUMAN SIDE / AN ILLUSTRATIVE PHISHING PATH

Still playing.
Already exposed.

A message from a friend. A request to vote. A “thank you” page. To the player, the task is finished. A compromised session can outlast that moment.

ON THE PLAYER’S SCREEN

A FRIEND’S ACCOUNT

OUT OF SIGHT

Silent session token capture

Account security is the issue before any item is sold.

The player did not set out to create an automation credential or delegate control. Returning to a game is not evidence that the account is safe. Valve holds the session logs, the API key creation record, and the device correlation data. The victim does not. That asymmetry is the accountability problem.

Session access and credential types

An API key and a logged-in session are separate credentials with different capabilities. Revoking a key does not terminate an active session. Valve’s own documentation describes both; Valve holds the logs that would show which credential was active at the time of any disputed action. The demand is disclosure of that record — not an inference the investigation has invented. Maintainer documentation on token handling ↗ archived 2026-09-24 ↗ · Valve key documentation ↗ archived 2026-09-15 ↗

03 / THE OFFICIAL MARKET HAS A CEILING

The item can be rare.
The limit stays.

A price above the listing cap cannot be realised through one Community Market listing at that full price.

ILLUSTRATIVE ASKING PRICE$5,000
$100$20,000

An illustration of the published limit, not a valuation or recommendation to trade.

LISTING CAP≈ $1,800
WALLET CAP≈ $2,000

Wallet funds cannot be withdrawn to a bank account. These constraints create the demand that third-party skin markets fill: a demand the listing and wallet caps produce, while Valve's own rules prohibit commercial operators from meeting it.

Steam’s market limits ↗ archived 2026-09-21 ↗

04 / INSIDE THE SUPPORT BOUNDARY

Entrusted with data.
Accountable for access.

Valve’s privacy policy expressly provides for sharing personal data with third-party support providers, as necessary for support.

THE PLAYERAccount & evidence
VALVERecovery process
SUPPORT PROVIDERDelegated access

Privacy Policy §5.2 ↗ · Valve's own policy authorises third-party support access. The open questions are: what permissions were granted, what audit trails exist, and what happened when access was allegedly abused.

Valve outsourced the desk — and said so

Valve keeps a small in-house Steam Support Leadership team and stated it "hired a couple different companies" to handle support (Erik Johnson, Valve, to Kotaku); its privacy policy § 5.2 authorises those third parties' access to user data. Which contractor holds account-recovery access, Valve has never disclosed — community discussion names vendors such as Concentrix, but none is Valve-confirmed. The outsourced desk was in place years before either admission below.

Kotaku: Valve on its support ↗ archived 2025-07-11 ↗

The first admission

Valve's CS:GO team accepts responsibility in writing for an account compromised through its own help-request process, and reverses the trades.

Open the outsourcing case ↓

The second admission

33 months later, Steam Support writes that a technician "failed to follow our process which resulted in your account restored to someone else." Same channel. Same outcome.

Dexerto, 14 Nov 2025 ↗

CASE FILE / HFB & THE OUTSOURCING ALLEGATIONS

The way in was Steam Support itself.
Valve said so in writing.

In the support reply reproduced by Dexerto, Valve's CS:GO team accepts responsibility for an account compromised through the help-request process — its own channel, not a phishing page and not the user. The items were recovered and the trades reversed, which is the remedy Valve tells other victims does not exist. HFB's inventory was reported at $2,000,000+ on the day and $3,000,000+ in the follow-up; Qkss lost $1,000,000+ the same way and got nothing.

SUPPORT REPLY / REPRODUCED BY DEXERTO · 21 FEB 2023
“compromised through a support help request, for which the CS:GO team takes responsibility”
Read the reporting and reproduced message ↗ archived 2025-08-18 ↗
01 / WHAT VALVE ADMITTED

Its own support channel was the way in

The reply covers the compromised account and the reversal of its trades. Valve reversed them — so the trades were reversible. The original authenticated ticket is not in this collection.

02 / WHAT THE SACKINGS DID NOT FIX

The same door opened again in November 2025

The contractor dismissed its entire Steam-support staff — reported by Mzkshow via Dexerto, not a Valve personnel statement. Thirty-three months later Steam Support wrote to another collector that "a support technician that handled the help request failed to follow our process which resulted in your account restored to someone else." Valve's own sentence, about the same channel.

The second admission, 14 Nov 2025 ↗
03 / WHAT IS OPEN

Valve has never named the contractor

Neither the contractor nor the location is established by these sources. That is not a hole in the reporting — it is a disclosure Valve has not made about who held access to user accounts.

Contemporary account of the case ↗

Three questions Valve has not answered: who could override account recovery, what the access audit found, and what changed afterwards.

Later allegations in the preserved support archive

Two 2024 Reddit posts relay further Mzkshow investigations — a July 2024 VAC-ban removal case and a December 2024 $13,000 inventory case. These are separately reported incidents. The accountability question in each is identical: who had override access, what did the audit find, and what changed.

05 / FOLLOW THE LOSS

Every amount
needs a case.

Ten cases, June 2022 to March 2026. Every amount is the figure its named source published — $6,300,000, $2,000,000+, $1,000,000+, ≈$320,000, ≈$300,000, and down to €288. Valve holds the transaction log, the session record and the support audit trail for each one, and has produced none of them.

Attribution and amounts remain as reported by each source. Valve holds the transaction logs, session records and support audit trail for every one of these cases. Produce them. A preserved Reddit post does not settle the question — Valve's own records do.