INVESTIGATION BY AGENT NADIACASE FILE 12 / 11 OCTOBER 2026
THREE GAMES / VALUE / SECURITY / ENFORCEMENTREVIEWED 11 OCT 2026 · UTC
THE DEFENCE NAMES ALL THREE.
Three games. Unequal protection.
Valve must answer for every game it puts behind its defence.
The New York response brings CS2, Dota 2 and Team Fortress 2 into one account of value, security and consumer rights. The documented controls do not cover them equally. Follow the gap between the statement, the protection available to a victim and the power Valve exercises over the same assets.
A greeting addressed to New Yorkers does not confine the economic mechanism to New York. Valve operates the account, inventory and transfer infrastructure across territories. The question is how existing law applies to the transactions it offers.
THE FILED CLAIM
All three games are in the complaint.
The 25 February 2026 filing expressly examines TF2 and Dota 2 alongside Counter-Strike. Paragraphs 67–74 describe their paid random-item mechanisms. Naming all three in the response therefore creates a responsibility to explain protection in each.
THE LEGAL QUESTION
Does the existing prohibition apply?
NYAG invokes existing New York law and seeks an injunction, consumer financial relief, disgorgement and a penalty. Valve’s preference for future legislation does not decide that dispute. The requested relief is set out on PDF pages 50–51.
THE WIDER CONSEQUENCE
The case tests a mechanism used across Steam: paid random outcomes, transferable items, outside liquidity and the issuer’s control. The consequences matter wherever that mechanism operates. Valve should explain which product and infrastructure changes it would make, which users would receive protection and how it would apply those changes across its games and markets.
STEAM CHINA / VALVE’S PUBLISHED PARTNERSHIP
Territorial adaptation is already part of Valve’s business.
Valve’s Steamworks documentation identifies Perfect World as the partner for an onshore Steam China. It requires government approval before a game is published there and an ISBN displayed on the product page. Valve can therefore describe regional partners, approval requirements and a distinct product configuration when that is how it enters a market.
The comparison sharpens the New York question: Valve has already configured a separate product for another territory, so it must identify the protections it can extend here, the alternatives it rejected and the cost it accepted. The Russian funding-provider record raises a separate demand for intermediaries, territorial controls and the transactions they process.
Valve writes to New York players of CS2, Dota 2 and Team Fortress 2. The account system, trading infrastructure and commercial incentives reach across those communities and borders. PhishDestroy’s question is broader than the letter’s local audience: how does Valve justify the same machinery wherever it operates?
A ruling in one jurisdiction has its own legal scope, but the product facts it examines are facts about Valve’s system. Valve should explain the consequences for that system and its users, rather than reduce the dispute to the preferences of one state. The demand is for accountability under the applicable rules—not a special law written around Steam’s business model.
02
THE SCOPE OMITTED FROM THE REASSURANCE
Who can actually get the items back?
A completed-trade reversal and a delay before delivery do different jobs. A platform-wide defence should identify which remedy each player receives.
THREE GAMES IN THE DEFENCEPROTECTION SCOPE · 11 OCT 2026
01 / NAMED IN VALVE’S RESPONSE
Counter-Strike 2
7 daysCompleted-trade reversal
Reversal
Yes · 7 days
After delivery
Immediate delivery; protected items cannot move again during the window.
Before delivery
CS2 is excluded from the old hold / escrow system.
02 / NAMED IN VALVE’S RESPONSE
Dota 2
No reversalCompleted-trade reversal
Reversal
Not supported
After delivery
General account, trade and item restrictions still apply.
Before delivery
The general policy can hold delivery for up to 15 days depending on authenticator conditions. A hold delays delivery; it does not reverse a completed transfer.
03 / NAMED IN VALVE’S RESPONSE
Team Fortress 2
No reversalCompleted-trade reversal
Reversal
Not supported
After delivery
General account, trade and item restrictions still apply.
Before delivery
The general policy can hold delivery for up to 15 days depending on authenticator conditions. A hold delays delivery; it does not reverse a completed transfer.
TWO CONTROLS. TWO DIFFERENT MOMENTS.
A hold delays delivery. A reversal returns a completed trade.
BEFORE DELIVERYAFTER DELIVERY
Counter-Strike 2Completed-trade protection
No old-style escrow
7 daysEligible trades can be reversed
Dota 2 / Team Fortress 2General before-delivery hold
Up to 15 daysDepending on authenticator conditions
No completed-trade reversal
The general hold policy and CS2’s completed-trade protection operate on different sides of delivery.
The Trade Protection FAQ names CS2 as the only supported game. Reversal undoes all protected trades from the preceding seven days and imposes a 30-day trade and Market cooldown on the initiator. Counterparties do not receive that cooldown merely because another person reversed.
THE ACCOUNTABILITY GAP
Dota 2 and TF2 users appear in the defence. They do not receive the reversal it invokes. Valve should publish the reason for the difference, the rollout timetable and the theft losses left outside the remedy.
TEAM FORTRESS 2 THE REMEDY VALVE DESIGNED
When rarity broke, Valve designed a remedy.
A July 2019 bug made some crates produce an Unusual hat on every opening. Valve fixed it the following morning and locked the affected hats. Its announced remedy made the first affected hat per account tradable, kept additional ones locked, restored qualifying deleted hats and offered eligible refunds for hats, crates and keys. The 16 August update confirmed the selective release.
01Identify
Locate the hats created by the crate bug.
02Control
Release the first affected hat; keep additional hats locked.
03Restore / refund
Restore qualifying deleted hats and offer eligible refunds.
That is active administration of scarcity and consumer remedies. Put the same specificity into the theft policy: identify the affected item, the available intervention, the reason for refusal and who bears the loss.
THE PLAYER’S COLLECTION
A collection is more than its resale price.
Items can serve as an appearance, a remembered collection and an exchange instrument at the same time. Preserved Dota testimony describes cosmetics as support for the game and a refused restoration. This is an account of personal loss beyond the case-opening transaction.
PERSONAL ATTACHMENT / ITEM CIRCULATION
The Dota cases show an inventory functioning as a personal collection: attached to a hero, a period of play and the player’s own history. A lower resale price does not make its theft a minor loss. Some players describe leaving after losing that collection. Their experience belongs in Valve’s security account alongside the price of the stolen items.
CS2’s outside markets and gambling services assign another role to highly liquid items: a repeatedly transferred store of exchange value. Dota Arcanas and TF2 keys also have specific trading roles, but a game-wide slogan about “cosmetics” hides these differences. Our question is why Valve addresses all three communities together while offering different recovery mechanisms and leaving each community’s losses unaccounted for.
PHISHDESTROY’S COMPARISON / THREE DIFFERENT ITEM ROLES
Attachment. Circulation. Recovery.
Choose a game to follow the role highlighted in this investigation. This is a qualitative comparison of the cases and instruments discussed below.
CS2 / SELECTED LIQUID SKINS
01 / THE PLAYERA favourite appearance.
A skin can become part of the player’s loadout and identity.
02 / THE OUTSIDE ECONOMYA circulating instrument.
Selected liquid skins are priced, transferred and used for settlement by outside markets and gambling services.
03 / THE REMEDYProtected trades.
CS2 has the trade-reversal route described in Valve’s Trade Protection FAQ. Market and Wallet losses have other rules.
Victim accounts centre on a collection attached to a hero, a style and years of play.
02 / THE OUTSIDE ECONOMYItem-specific liquidity.
Arcanas and other transferable items have trading roles. Price alone does not account for the personal loss.
03 / THE REMEDYOutside CS2’s reversal.
The FAQ’s supported-game scope leaves Dota outside that recovery route. Valve should explain its protection and restoration policy.
·
TF2 / THE KEY AND THE COLLECTION
01 / THE PLAYERA collected identity.
Cosmetic appearance and rarity remain part of what the player values.
02 / THE OUTSIDE ECONOMYA tradable key.
The Mann Co. Supply Crate Key is documented as tradable and marketable. Follow its role after the CS:GO key restriction.
03 / THE REMEDYA different intervention.
Valve designed a selective remedy for the 2019 issuance bug. Theft recovery and CS2’s trade reversal need their own explanation.
·
PhishDestroy’s comparison of attachment, circulation and recovery.
THE INVESTIGATION’S COMPARISON
A favourite item and a circulating chip have different roles.
The Dota testimony shows a collection becoming personal through its connection to a hero, a style and years of play. Losing it can remove part of the reason to return to the game. The significance of that loss is not captured by a cheap item’s market price. The victim reports belong beside the financial ledger, because the harm includes the relationship with the game.
In the CS2 services examined by this investigation, selected liquid skins function as exchange instruments: deposited, priced, wagered, transferred and resold. Their usefulness to the surrounding business depends on movement. A player keeping a favourite skin indefinitely contributes differently from a player repeatedly circulating value through trades, markets and gambling services.
PhishDestroy’s criticism is that this circulation has become a commercial dependency around CS2. Outside platforms recruit and monetise the movement of Steam-issued items, while the player carries the risk of theft, restrictions and failed recovery. The “purely cosmetic” description leaves this economic machinery out of the explanation.
Dota Arcanas and TF2 keys require their own item-level analysis. Their trading roles do not erase the personal significance of another player’s collection. Addressing all three communities creates a duty to explain each game’s losses and remedies, rather than borrow a CS2 protection feature as reassurance for everyone. Follow the transaction mechanism ↗ · Follow the outside settlement services ↗
03
THE ISSUER’S ADMISSION / THE COURT’S ORDER
The monetary function was already on the record.
VALVE / KEY CHANGE28 OCT 2019
Valve stopped newly purchased CS:GO keys from circulating.
Valve said fraud networks were using keys to liquidate proceeds and believed nearly all purchased keys subsequently traded or sold were fraud-sourced. It made new in-game key purchases non-tradable and non-marketable. Existing keys retained those functions.
Valve’s own explanation identifies a monetary use for game items and a restriction the issuer could impose. The distinction between existing keys and new purchases also shows how precisely it could change the trading function.
TF2’s Mann Co. Supply Crate Key remains a documented tradable and marketable instrument. After Valve restricted new CS:GO keys in 2019, what monitoring followed the other liquid instruments on its own platform? Publish the cross-game review, the services identified and the restrictions actually applied. The issuer cannot end its explanation at the boundary between two games.
OPSKINS / A NAMED TARGET AND A DEADLINE
Valve could direct enforcement at the operator.
After ExpressTrade launched, Valve said it violated the Subscriber Agreement and enabled avoidance of Valve’s policies. The company published a demand to stop and announced that OPSkins’ Steam accounts would be locked by 21 June.
The record names a business, a practice and an account-level deadline. Apply that level of detail to the operators warned in 2016 and to the later P2P model: what was disabled, what reappeared and which business actually lost the ability to operate?
ONTARIO / PLETERSKI & AP PRIVATE EQUITYORDER + TRUSTEE’S REPORT
THE CANADIAN ORDER TESTED VALVE’S CONTROL.
Disclose the records. Freeze the accounts.
The Ontario court ordered Steam to disclose account information and freeze the bankrupt’s accounts.
The trustee records receiving login, account, inventory and trade histories for five accounts.
153+skins in the trustee’s trade analysis
CAD 430,312trustee’s estimated value
The 11 July report concerns Aiden Pleterski and AP Private Equity. The trustee identifies more than 100 trades during bankruptcy and infers cryptocurrency settlement. The court order and the records subsequently supplied by Steam show that inventory, account histories and transfer restrictions can become concrete instruments of asset recovery.
Follow the item, identify the account, preserve the history and explain the restriction. Those are concrete requests directed at the issuer and custodian of the record. The Canadian file gives the investigation a documented example to put beside Valve’s general statements about control.
The monetary function did not disappear with one restriction.
Valve’s own 2019 explanation records fraud networks using CS:GO keys to liquidate proceeds. The company then changed what newly purchased keys could do. That admission is central to this investigation: the issuer knew that a game item could serve as a financial instrument and could intervene in its circulation.
The next question follows the value into other instruments and services: pre-existing keys, TF2 keys, liquid skins, outside exchanges and cryptocurrency settlement. Our investigation asks what Valve monitored after the change, which routes it identified and how its controls followed the displaced activity.
The Canadian asset-recovery file supplies a concrete account-and-inventory trail to place alongside that question. The payment chapters examine intermediaries, territorial restrictions and the movement from skins into platform balances, vouchers and cryptocurrency. The inquiry follows those documented mechanisms; it does not need an unrelated scandal to explain why the “cosmetic” label is economically inadequate. Follow the voucher route ↗ · Follow custody and release control ↗
04
KNOWN LOSSES / MEASURABLE RESPONSIBILITY
A ban total cannot replace a security loss ledger.
VALVE’S OWN HISTORICAL FIGURE77,000accounts hijacked and emptied per month
In December 2015, Valve reported this scale and described organised theft aimed at experienced users as well as newcomers. It also recognised the monetary incentive created by item trading. This is a dated baseline, not a current monthly estimate or a cumulative count.
How much loss followed a known defect, and how long did Valve leave that defect in place? Answering requires the incident records, notice dates, fixes and remedies in Valve’s possession. Neither the 2015 figure nor the later million-account total — the March 2026 statement reporting over one million locked accounts — supplies that breakdown.
DOTA / WALLET LOSS REPORT
44 purchases. About US$500 lost.
The author reports unauthorised purchases of low-value Dota items on 6 July and says support sent template replies. The disputed route is the Market and Wallet.
The author reports that support reset credentials and removed protections in an earlier incident, followed by inventory theft and refusal to restore. The authenticated recovery decision sits in Valve’s support records; Valve should produce it.
These are dated victim reports. The account and support logs that would settle them are held by Valve and belong in the disclosure demand. A standard warning about suspicious links does not resolve the specific transaction or recovery decision being disputed.
01 / ACCOUNT AUTHORITY
Keys and sessions
Record the credential involved, its creation and use, confirmation prompts and the actions it authorised. The historical key-registration issue and the later session-token workflows must be tested separately.
A substituted trade, a direct transfer and a Market purchase move value differently. Identify the receiving account, the confirmation event and the remedy applicable to that route.
A malicious page, a renderer exploit and a support-mediated account reset need their own evidence. A single label such as “API scam” conceals the stage where protection failed.
Valve owns the protection delivered inside its client.
DARKNAVY’s June 2024 research documents Steam’s embedded Chromium architecture and historical exploitation. It puts the browser security timeline directly into the accountability record: exposure, disclosure, patching and the consequences for users.
Chromium documents Google-service and API integration choices; the CEF maintainer describes its upstream Safe Browsing default. Valve controls the configuration it ships. It should disclose its actual service connections, reputation checks, patching cadence and the reasons for excluding any available protection.
THE DISCLOSURE THAT WOULD SETTLE IT
Publish the shipped CEF version, patch lag, sandbox settings, active reputation services and reproducible warning results across the client, overlay and Big Picture. Compare the same dated destinations and record which protection actually stopped the visit.
The dossier’s embedded-browser investigation places the user’s actual protection on the record. A failed warning in a captured build is a concrete failure to address. Valve controls the shipped configuration and should disclose which services it enables, which it excludes, how quickly it patches and what those choices mean for users exposed to malicious destinations. Read the wider browser investigation ↗
VAC / KERNEL ACCESS / PLATFORM STRATEGY
Valve chooses the architecture. Users bear the consequences.
THE COMPARISON VALVE MUST ANSWER
Kernel-level protection is already deployed.
Riot documents Vanguard’s kernel-mode driver. FACEIT describes a kernel driver, client and server SDK for protected CS2 matches, with Windows-only availability. These are deployed approaches to protecting competitive play. Microsoft documents the driver-signing and compatibility requirements that govern this route.
VALVE’S RESPONSIBILITY TO ITS USERS
Explain the gaps. Account for the damage.
Valve must account for cheats that survive its protections, the time they remain active, the matches they affect and the users left without an effective remedy. Detection coverage, response times, erroneous bans and appeal outcomes belong in that account. A technical strategy is judged by the protection it delivers to players.
Valve’s own Steamworks guidance recommends authoritative servers and explains how game-ban systems should communicate with affected users. That gives Valve a standard against which its implementation and treatment of users can be examined. Publish how the layers work together, where coverage fails and how those failures are remedied.
PhishDestroy’s criticism is directed at Valve’s priorities. SteamOS, Proton and control over its browser and anti-cheat stack serve Valve’s platform strategy. Corporate independence does not discharge its responsibility for security. When users face cheating, inventory theft or ineffective recovery, Valve owes an account of the protection it shipped, the alternatives it rejected and the consequences it accepted. The relevant configuration and decision records are in Valve’s hands; producing them is part of accountability.
THE QUESTION TO VALVE
What protection did your architecture leave missing, who carried the cost, and what have you changed to prevent the same harm recurring?
PHISHDESTROY’S ARCHITECTURAL CRITICISM
Corporate independence has a cost paid by the user.
We read the browser and anti-cheat decisions together. Steam embeds a browser whose protection depends on the shipped version, services, sandbox and updates. Competitive play depends on a protection architecture that can detect and interrupt the cheats players actually face. Valve chooses both implementations and controls the account and inventory that become exposed when protection fails.
Control of the platform and independence from other technology companies carry exceptional weight in those choices: integrating browser reputation services raises a relationship with Google; deploying a Windows kernel driver brings signing, testing and compatibility obligations in Microsoft’s ecosystem. SteamOS, Linux and Proton also form part of Valve’s platform strategy.
That corporate preference is the object of our criticism. When Valve rejects, delays or weakens an available protection to preserve autonomy, users bear the consequence through compromised accounts, missing inventories and matches affected by cheating — the failed warning in the captured build is that consequence on record. Calling the trade-off privacy does not account for that cost. Valve should disclose the decision, the alternative considered, the protection lost and the remedy offered to the people affected.
The browser and VAC therefore belong in the same accountability question: whose independence did the architecture protect, and whose security remained exposed?
THE LOSS LEDGER
How many accounts, how many inventories, how many years?
Valve should publish the history of the credential and session pathways abused to take inventories: when each mechanism became known, when it changed, what replaced it and how many users lost value before an effective fix. API-key theft, stolen browser sessions and token-return pathways need their own dates and loss records.
Count what the farm pays. Then count what enforcement stops.
Valve’s CS2 documentation connects Prime status with weekly item rewards. That creates an economic question about paid access, item issuance and repeat account purchases. Answer it with a purchase cohort and transaction ledger.
The farm’s economics depend on how little hardware time each running instance consumes. Reducing rendering load and sharing resources increases the number of accounts a given setup can sustain. Microsoft documents GPU resource sharing across virtual machines. Valve should explain which signals it uses to identify such automation, which controls interrupt it and how long the farm continues earning before intervention.
EXPLORE THE THREE-MONTH PAYBACK SCENARIOEDITABLE SCENARIO · PHISHDESTROY’S RESEARCH BENCHMARK
Use one currency throughout. The starting values are illustrative assumptions, not current prices or expected returns.
ILLUSTRATIVE RESULT / CURRENCY UNITS
Simple break-even14.4 weeks
Gross entitlement spending
15,000.00
Weekly net per account
1.25
Net needed for 13-week recovery
1.38
After 13 weeks: 90.3% of the initial entitlement and setup cost recovered.
This simple scenario excludes bans, replacement purchases, price changes and time without earnings. Gross spending is not Valve’s recognised net revenue: taxes, refunds and the purchase channel must be reconciled. A Steam ban count supplies none of these inputs.
POPULATIONWhich accounts?
Newly purchased entitlements, legacy access, stolen accounts and ordinary users need separate cohorts.
RECEIPTSWhat did Valve receive?
Reconcile entitlement receipts, case purchases and internal Market fees. External trade value is a separate flow.
ENFORCEMENTWhat changed after the ban?
Track inventory restrictions, replacement accounts, continued operations and successful appeals.
THE UNCLASSIFIED POPULATION
Which half of a ten-million economy did the lock hit?
The population behind the ban count was never classified. Of roughly ten million accounts in this economy, about half sit above the $5 “non-limited” threshold — the tier that unlocks the Market and the Web API. Valve has never said how many of the locked million came from that half, or why “commercial use” is the charge applied to accounts whose only commerce was playing.
The classification records are Valve’s to produce: the limited and non-limited split of the locked accounts, the qualifying spend behind each, and the clause actually invoked. Publish them, and the ban count becomes an account of who was stopped — not a number over an unexamined population.
THE INCENTIVE TEST
Valve’s receipts and the farm’s continued operation belong in the same account. Match entitlement purchases, item issuance, Market fees, restrictions and replacement accounts over time. That would show the commercial benefit accumulated before a ban and whether enforcement actually stopped the operation.
WHO COLLECTS BEFORE THE BAN?
The farm’s payback period is also a revenue question.
PhishDestroy’s working benchmark is a farm designed to recover its setup cost in roughly three months. The calculator above makes the inputs visible: account entitlements, recurring costs, sale proceeds and losses from restrictions. A farm’s purchase and replacement cycle can generate revenue for Valve before enforcement arrives.
That is the relationship this investigation asks Valve to explain. Publish what these accounts paid, when the activity was recognised, what value was returned and whether the same operation resumed under replacement accounts. The scale of a ban announcement should lead to that ledger.
THE REVENUE BEFORE THE BAN / AN ILLUSTRATED AUDIT ROUTE
Follow the receipt through the cycle.
The model shows the records to join. The payback calculator above provides the editable arithmetic.
OPERATOR / ACCOUNT COHORTThe farm
Setup, paid access, operating cost and replacement decisions.
ISSUER / PLATFORM RECORDSteam
Entitlements, issued items, internal fees and restrictions.
REALISATION / SETTLEMENTThe sale
The item route, actual proceeds and the recipient.
01 / PAID ACCESS
The first receipt precedes enforcement.
The scenario begins with newly purchased entitlements for the farm’s accounts. The payment and the account cohort are the first entries to reconcile.
Valve’s CS2 documentation connects Prime status with weekly item rewards. Follow what the eligible accounts receive, when the activity is recognised and which protection interrupts it.
Eligible account · reward date · issued item · activity record03 / SALE AND PROCEEDS
Follow the item into realised value.
The farm’s receipts depend on the route and fees. An internal Steam Market transaction and an outside cash sale leave different ledgers. Reconcile the reward, transfer, sale and money actually received.
Item identifier · transfer · venue · sale proceeds · retained fees04 / BAN OR REPLACEMENT
Did the intervention end the business cycle?
A restriction changes the account’s access. The investigation asks whether the same operation continues, replaces its accounts or loses the ability to earn. Follow purchases and losses after the intervention.
Restriction date · retained inventory · replacement account · later receipts
Manual stage selection stays available when motion is off.
Stage 1 of 4: Paid access.
LOW RENDERING LOAD / MANY ACCOUNTS
The farm is a business relationship before it is a ban statistic.
The model examined by PhishDestroy reduces rendering work through minimal settings and small output dimensions, then distributes available resources across many running clients. The business calculation starts with the accounts sustained by that setup and the rewards they can realise. Those inputs belong in the farm’s economics alongside electricity, hosting, equipment and replacement costs.
Our criticism is the incentive relationship: the farm seeks recurring item proceeds; Valve can receive payments for access, replacement accounts and internal transactions. Enforcement that periodically removes accounts can coexist with a purchase-and-replacement cycle. The investigation asks whether intervention disrupts that cycle or leaves it commercially viable.
A roughly three-month recovery target is the author’s working benchmark, exposed through the editable scenario above. To turn the headline ban count into an account of responsibility, Valve should publish the associated purchases, restrictions, retained fees, surviving operators and repeated registrations. How much did the system receive before the operation was stopped—and was it actually stopped?
06
COLLECTIBLES / PRECEDENTS / COMMUNITY
Labubu, CS2 charms and Valve’s chosen analogy.
Lisa dates her collecting interest to early 2024.
In an interview published on 8 November 2024, Lisa looks back at her interest in blind boxes and rare collectibles earlier that year.
The original April post — the first-person collecting record behind the 8 November 2024 interview — remains a separately sought primary source.
Valve introduces the Armory and weapon charms.
The official release describes paid passes, play-earned credits and item redemption. It places another cosmetic product inside Valve’s monetisation architecture.
Valve invokes Labubu in its public defence.
The statement compares mystery boxes with physical collectibles. Valve issues the item, sets the paid sequence, executes the transfers and can stop the holder from using the market. The collectible comparison erases every one of those issuer powers.
Valve chose a collectible associated with a recent, highly commercial collecting boom. Put that choice beside the sequence: Lisa dates her collecting interest to early 2024; Valve introduces CS2 weapon charms on 2 October 2024; Valve invokes Labubu in its 11 March 2026 defence. PhishDestroy’s argument is that the analogy makes paid random outcomes feel like familiar collecting while directing attention away from Steam’s liquid item economy and the issuer’s control. The commercial role of appearance is also visible in the seven-Major inspect dataset ↗.
THE COMMERCIAL SCALE OF THE COMPARISON
THE MONSTERS revenue
POP MART annual report · RMB billions · scale 0–15
2024
3.04 billion RMB
2025
14.16 billion RMB
Company-reported revenue for the full IP that includes Labubu, not resale turnover or Labubu alone. These figures show the commercial scale of the collectible market that Valve chose for its analogy.
STEAM’S OWN TRANSFER ECONOMY
Read the actual transfer architecture.
The useful comparison with FIFA is the architecture of value. Steam combines transferable inventory, an internal Market and outside sale routes. Valve created and administers the transfer infrastructure on which that liquidity depends. A judgment about EA’s implementation cannot answer questions about Valve’s own system. Valve’s regional response in the Netherlands belongs at the centre of that comparison: when the obligation changes, the platform can change access. Follow the regional-control record ↗
THE COMMUNITY’S SECURITY PROBLEM
Players ask for protection.
In the community material examined by PhishDestroy, the appeal to privacy repeatedly meets ridicule and complaints about cheating, fraud and the security of inventories. Valve’s defence fails to answer the problem those players experience: a platform with extensive records and commercial control that still leaves them exposed. Their demand is effective protection and a remedy after loss.
The statement and the research record+
Valve published the response on 11 March 2026. Its choice of audience, collectible analogy and privacy argument are the subjects of this analysis. The investigation treats the publication as the company’s position.
The broader dossier brings together support records, community discussions, reviews, technical material and commercial data. Those streams are used to examine how Valve’s public account compares with its users’ experience. The source archive preserves the dated records behind each part of that examination.
THE AUTHOR’S ECONOMIC COMPARISON
Steam’s exchange architecture is the issue.
PhishDestroy compares Steam’s liquid item economy with an exchange: the issuer creates the asset, defines its permissions, supplies the transfer infrastructure and records the internal market, while outside venues supply cash trading and gambling settlement. This is why we reject FIFA as a substitute explanation for Valve’s system. The relevant questions are liquidity, conversion, custody, control and the paid random transaction.
Valve’s API, trading functions and Market were created by Valve. Outside operators commercialise access to that infrastructure. Our criticism is directed at the platform that supplies and administers it, and at an enforcement account that counts restricted accounts while leaving the surrounding business capabilities unexplained. Follow the ledger and item routes ↗ · Follow Steam access ↗
07
THE RECORD VALVE SHOULD PRODUCE
Turn the defence into an auditable account.
01
Protection by game and route.
Publish theft losses, reversals, refusals and the reason Dota 2 and TF2 remain outside Trade Protection. Separate trades, Market purchases, gifts and recovery incidents.
02
The post-2019 fraud trace.
Identify the financial instruments monitored after new CS:GO keys stopped circulating, the flows displaced and the interventions that followed.
03
Notice, fix, exposure and remedy.
For each security failure, provide the first notice, affected builds, exploitation evidence, patch date, affected population and compensation or restoration outcome.
04
The money behind account enforcement.
Reconcile the relevant account cohorts with entitlement receipts, item issuance, fees, restrictions, repeat purchases and operator survival.
05
The design decisions and their cost.
Disclose browser protection settings, anti-cheat coverage and measured trade-offs. Make the decisions that affect user security open to independent examination.
THE FINDING
The items have an economic function. Valve has operational control. Protection and accountability must match both. The record now contains Valve’s own fraud admission, a court-directed account disclosure and a documented gap between the three games named in its defence.
HOW PHISHDESTROY CONNECTS THE RECORD
The investigation follows the same mechanism across datasets.
Our approach brings together development material, other games, public reviews, community discussions, support experiences, court documents and the commercial services built around Steam. These are different views of the same system: what Valve issues, what it records, what outside operators do with that access and what happens to the person who loses an account or inventory.
The review-incentive chapter adds a further acquisition layer. A giveaway recruits public reviews; those reviews help establish trust in an extension; the extension then requests access and operates inside Steam’s interface. The code case follows that access into registered account operations. The questions about protection and enforcement travel through the whole chain. Review incentives and developer replies ↗ · The SIH account-operation record ↗
08
THE PUBLIC RECORD
Inspect the evidence.
26 RECORDS
Sources cited in this article appear first. Select “All records” to inspect the complete 107-record register shared by the investigation; the dedicated evidence files retain their own detailed registers.
No matching records. Try a different term or select “All records”.
Research method and source status+
Reviewed 11 October 2026 UTC. The game comparison uses the current Trade Protection FAQ and the separate general hold policy. The Canadian exhibit distinguishes the court’s order from the trustee’s account and valuation. Victim reports retain their original dates and source links.
The farm model exposes its assumptions and arithmetic. Technical sources identify the documented architectures; the requested Steam-specific record includes the shipped configuration and observed protection. The New York exhibit is the February complaint, with its allegations and requested remedies attributed to the filing.