The audience comes for the player.
The sponsor gets the attention.
On 2 May 2023, CSGORoll announced a G2 partnership: branding on the G2 and OYA jerseys, plus a skin-and-prize activation at G2’s Paris Major booth. Its announcement described a CSGORoll-themed slot machine. The operator itself placed the gambling brand at the intersection of a famous team, valuable skins and a flagship Counter-Strike event. CSGORoll’s announcement · 2 May 2023 ↗
Advertising mechanism inferred from the operator’s announcement. The source establishes what was promoted; it is not footage confirming the booth’s operation.
Sharpr’s 4 May report described the launch video featuring m0NESY, who had turned 18 the day before the partnership announcement. A young star was the face of a skin-gambling promotion. That is the commercial bridge this investigation follows: the player earns the audience’s attention; the sponsor buys access to it. Sharpr · G2’s skin-gambling deal ↗
The announcement documents a team partnership and a planned Major activation. It does not establish a direct CSGORoll–Valve sponsorship contract. Establishing who approved the activation would require the team’s, organiser’s and distributors’ agreements and decisions.
READ WITH THE MAJOR DATA98.7% of recorded weapon inspections involve a non-default finish.Seven Majors. 491 maps. The skin is already in the foreground before a sponsor enters the picture.
Open the Major showcase →A warning existed.
Forty-three days earlier.
The Australian regulator’s original warning is dated 20 March 2023. CSGORoll announced the G2 deal on 2 May. The addressee was Feral Holdings Limited, at a Belize address, identified as the operator of CS:GO Roll. ACMA · original formal warning ↗
ACMA’s 17 May public statement described the economic loop: skins become gambling credits; winnings become skins; external services convert those skins into money. It reported the service’s withdrawal from Australia. A cosmetic’s lack of weapon damage does not remove its financial role. ACMA · enforcement announcement ↗
43 days = 2 May − 20 March 2023. The warning concerns Australian law. These dates do not establish when G2 learned of it.

Original document, page 1 of 2. Date on page 2.
Ten days to stop.
A letter is not an outcome.
On 13 July 2016, Valve described the mechanism in public: OpenID identifies a Steam account; automated accounts make web calls resembling ordinary users. Using those mechanisms for gambling, Valve said, violated its API and user agreements. This was a known infrastructure route, described by the platform itself. Valve · In-Game Item Trading Update ↗
Letters signed by general counsel Karl Quackenbush gave operators ten days to stop commercial use of Steam accounts. Ars reported 23 recipients and Valve’s confirmation of the letter. HLTV identified CSGOFAST and CSGOLounge among the named sites. These records do not establish CSGORoll as a recipient. Ars · the cease-and-desist letters ↗ HLTV · named recipients ↗
OpenID, automated accounts and a ten-day demand.
Eight teams; $10,000 prize pool.
Jerseys, a branded slot machine, skins and prizes.
A credential handed from the Steam session to the operator.
A dated response, preserved with its checksum.
HLTV’s event record dates CSGOFAST Cup 2 to 20–22 December 2017. The brand’s later tournament presence is documented. That alone does not establish uninterrupted operation or unchanged ownership after the 2016 demand. CSGOFAST Cup 2 · event record ↗
The letter records what Valve demanded. Enforcement records would show what happened next.
When one advertising surface closes,
another can carry the brand.
RushBee’s own Metality case study names GG.BET as its client and describes a Vitality campaign built around touring rock-star imagery. It says brand placement in game packs maintained visibility while adhering to jersey sponsorship restrictions. A branded bus, gaming sessions and player meet-and-greets carried the campaign beyond the shirt. RushBee · Metality campaign ↗
This is a documented intermediary and a documented change of advertising surface. It is not, by itself, evidence of a concealed owner or an unlawful workaround. The useful question is concrete: what does a jersey restriction prevent when the same sponsor can reach fans through the surrounding event?
BLAST’s January 2024 announcement gives a second route: GG.BET’s BLAST Premier partnership included on-broadcast betting odds, predictions, Pick ’Ems, giveaways and physical and digital branding. It also records GG.BET’s previous partnerships with the Stockholm 2021 and Antwerp 2022 Majors. The newly announced deal was for BLAST Premier; it should not be relabelled as a new Major contract. BLAST · GG.BET partnership ↗
| Relationship | Documented surface | Record |
|---|---|---|
| CSGORoll → G2 | Team jerseys; announced Paris Major booth activation | 2 May 2023 |
| GG.BET → RushBee / Vitality campaign | Game packs, branded tour bus, meet-and-greets | Agency case study |
| GG.BET → BLAST Premier | Odds in the broadcast, predictions, content and branding | 22 Jan 2024 |
| CSGOEmpire → Empire Cup | Announced $50,000 online tournament | 26 Mar 2024 |
Sources: operator announcement, agency case study, organiser announcement and HLTV’s tournament reporting. These are distinct relationships, not a single ownership chain.
CSGOEmpire announced a $50,000 online cup with Fortuna in March 2024. After the disruption at the Copenhagen Major on 29 March, participants withdrew; this was not the Paris Major of 2023. A later 3DMAX statement dated 2 March 2025 confirmed that its brief Empire sponsorship had been terminated. The record shows both commercial recruitment and pushback, not one permanent partnership. HLTV · Empire Cup announcement ↗ HLTV · withdrawals ↗ 3DMAX · termination statement ↗
Valve’s currently published tournament licence has separate provisions for betting sponsorship and skin-economy sponsors. That distinction makes the applicable contract, date and jurisdiction material. Today’s licence cannot establish which clause governed a 2023 activation. Valve · tournament licence, §2.4(d)–(e) ↗
The operator’s instruction:
hand over the token.
The sponsorship buys attention. The trading workflow asks for something else: a credential from the customer’s Steam session. In its 10 April 2024 WebAPI P2P SOLUTION post, CSGORoll told sellers to copy a webapi_token from their authenticated Steam browser session into the operator’s trading page. CSGORoll · published instructions ↗
The post addressed sellers listing skins, rather than buyers alone. It described daily token renewal, invalidation after logout or session termination, and encrypted storage. These are the operator’s claims about use and handling. The post was still publicly accessible when collected; that does not establish that its 2024 procedure remains in use unchanged.
The user key and the session token are different credentials.
Steam users manage a personal Steam Web API key at steamcommunity.com/dev/apikey ↗. This is the user-key route, not a Steamworks publisher credential for a game studio. Valve’s authentication documentation explicitly separates User Keys from Publisher Keys. Valve · User Keys and Publisher Keys ↗
CSGORoll’s cited procedure asks for a different object: the session’s webapi_token, not the personal API key registered on that page. The sample examined for this investigation is a JWT access token. JWT describes its format; the API is the interface that accepts it. A token accepted by a Steam endpoint does not become a publisher key. JWT format · RFC 7519 ↗
Registered on the user’s account
A separately managed credential at Steam Community’s API-key page. Its creation and revocation are distinct from those of a browser-session access token.
User API-key management ↗Issued in the logged-in session
The credential requested in the cited workflow. Its expiry, accepted endpoints and revocation depend on the session-token system; the API-key page does not define those controls.
Maintainer’s access-token account ↗The distinction is documented in trade tooling. In March 2024, the maintainer of node-steam-tradeoffer-manager described access-token authentication for parts of Steam WebAPI, including a fallback when an account lacked an API key and registration required mobile confirmation. The maintainer dates that confirmation requirement to late 2023 and calls the token route officially unsupported. This establishes a documented alternative credential path; it does not establish which library CSGORoll used. Library maintainer · Access Tokens ↗
The trust boundary moves after sign-in.
Steam OpenID confirms a Steam identity to the relying site. That sign-in step alone does not give the site the user’s Steam session token. CSGORoll’s separate copy-and-paste instruction is the material step: a session credential crosses to the operator. Valve · Steam OpenID provider ↗
The published instruction supplies no endpoint-level permission list or evidence of an independently revocable, site-specific grant. Its promise to use the token for monitoring does not establish that Steam restricts the token to that purpose. The questions for the platform are the permissions accepted by each endpoint and the mechanism for ending the transferred access.
A confirmation gate on API-key registration does not close a separate session-token route.
Continue in Part II: which credential crosses the boundary? →
The token worked
from a different IP.
The source reports testing the same session access token from a different IP address and receiving authenticated access. In that reported test, a change of source IP did not cause the server to reject the credential. This is a behavioural observation, separate from decoding the token.
The sample decoded for this investigation declares EdDSA and an audience of web:community. Its ip_subject and ip_confirmer values match. The account identifier, IP addresses and credential are withheld.
web:communityThe result matters because the IP fields can look like a security boundary. A recorded address is not, by itself, a server-enforced restriction. The source’s test reports that the boundary did not hold for the request tested. It does not establish that every Steam endpoint accepts the token from every possible IP.
Test provenance: result supplied to this investigation by the source. The request log, endpoint and test time are not included in this publication; the editorial review did not independently replay the credential.
The sample’s time claims span 87,649 seconds. This is the interval encoded in that sample, not a measured guarantee of usable access or a universal Steam token lifetime. Local decoding alone did not validate the signature.
Neither the personal API-key settings nor Steamworks publisher-key restrictions establish the IP controls on this JWT. The relevant evidence is the response to the session token at the endpoint under test. The reported cross-IP success is a reason to examine that control directly.
The response was a warning.
It offered a way through.
steamcommunity.com/linkfilter/?url=csgoroll.com
The captured Steam response offered continuation.
No “Link Blocked” screen was present.
Textual reconstruction of the saved response; not an interactive Steam security dialog.
This check establishes the result for one URL at one time. It does not reveal sanctions against trading accounts or imply Valve’s endorsement. It does leave a precise enforcement question: what criterion governs the public warning for an operator whose own instructions describe collecting Steam session tokens?
Response provenance and SHA-256
- Retrieved
- 2026-10-05T16:20:36.939554+00:00
- Request
- Unauthenticated HTTP GET; no user token submitted
- Saved response SHA-256
- 0878605b1ee6eead0ad27e515fd9d1b05cf657046f1ec7c7df666e73cccf324b
Who was removed?
Who was allowed back?
New York’s Attorney General raised precisely this selection problem in a complaint filed on 25 February 2026. Paragraphs 95–99 allege exclusions from the 2016 campaign and later restoration of access for certain services. These are the plaintiff’s allegations, not findings by a court. They identify records that matter: the exemption criteria, internal decisions and restoration trail. New York v. Valve · complaint, §§95–99 ↗
Valve also documented concrete action against OPSkins ExpressTrade in 2018. The question is the reach, consistency and durability of enforcement: which route was closed, whether its replacement was detected, and which commercial uses were permitted to continue. Valve · ExpressTrade ↗
The documents this record calls for
- 2016 recipients and outcomes. Account actions, follow-up and the reasons for exclusions.
- Event approval. Who approved the advertised G2 activation, under which dated agreements?
- Credential boundaries. Which endpoints accept session tokens, with what permissions, IP controls and revocation?
- Public warnings. The criteria for blocking, allowing or restoring the domains in this record.
The ten-day deadline was a demand made of the operators.
Ten years later, its enforcement belongs on the record.
Follow the documents.
This article connects dated public records, a locally decoded and redacted token sample, a source-reported cross-IP test, and a preserved unauthenticated Link Filter response. Source links sit beside each claim. Interpretations, announcements and allegations are identified where they appear.
- S01G2 / CSGORoll announcement ↗operator · 2023-05-02
- S02Sharpr: G2 skin gambling deal ↗reporting · 2023-05-04
- S40ACMA formal warning to Feral Holdings ↗regulator · 2023-03
- S03ACMA: CSGORoll warning ↗regulator · 2023-05-17
- S04Valve: In-Game Item Trading Update ↗valve · 2016-07-13
- S06Ars: July letters confirmed by Valve ↗reporting · 2016-07-20
- S34Valve letters / CSGOFAST named ↗reporting · 2016-07-20
- S19CSGOFAST Cup 2 ↗event-record · 2017-12-20/2017-12-22
- S23RushBee Metality campaign ↗agency-case-study · Retrieved 5 October 2026
- S10BLAST Premier / GG.BET ↗organizer · 2024-01-22
- S16CSGOEmpire Cup announcement ↗reporting · 2024-03-26
- S17Withdrawals after Copenhagen disruption ↗reporting · 2024-03-30
- S443DMAX termination statement ↗team-social · 2025-03
- S08Valve Limited Game Tournament License ↗valve-current · Retrieved 5 October 2026
- S39CSGORoll WebAPI P2P Solution ↗operator · 2024-04-10
- S31JWT standard ↗standard · 2015-05
- S27Steam Community · OpenID provider ↗valve-docs · Retrieved 5 October 2026
- S29Access Tokens: tradeoffer-manager ↗maintainer-primary · 2024-03-29
- S45Steam Community · personal API-key management ↗valve-user-account · Sign-in required
- S24Steam Web API · User Keys and Publisher Keys ↗valve-docs · Retrieved 5 October 2026
- S07NY OAG v Valve complaint ↗court-pleading · 2026-02-25
- S37Valve OPSkins / ExpressTrade action ↗valve · 2018
- S33Steam Link Filter: csgoroll.com ↗direct-observation · 2026-10-05