Article translationsRead this investigation in your language24 official EU languages · English is the source text · translated with DeepL and hosted by PhishDestroy
Dark Web Investigation: Steam account theft at industrial scale Investigation
Exclusive investigation · Part I · August 2026

Valve Profits from 578,000 Stolen Steam Accounts

PhishDestroy ResearchAugust 14, 202640 min readPart I of III
Скачать PDF — Официальный отчёт
578K+Steam accounts for sale right now
$40M+Criminal market value on LZT right now
$450MEstimated minimum victim liability
$0.08Market price: your CS2 Prime JWT token
Live Intelligence Dashboard Full Dataset
LZT MARKET · LIVE FEED
connecting...
Steam
All platforms
Steam avg $
Market value
Infostealers
Phishing
Brute force
Support leak
Investigation in brief

Valve must be held accountable. Here is the evidence.

For over a decade, Valve Corporation has maintained deliberate, profitable blindness to the largest stolen gaming account marketplace in history. 819,000+ stolen accounts are listed for sale right now across 16 platforms. PhishDestroy documented all of them — in real time, from the LZT Market public API. The evidence is mathematical, legal, and irrefutable.

  • 578,465 Steam accounts for sale today

    86,668 via infostealers. 66,744 via credential stuffing. 7,081 via phishing. 1,026 "recovered through Steam support" and resold — direct proof of outsourced corruption. Valve sees every API call. They chose not to act.

  • Five legal vectors, one corporate defendant

    OFAC sanctions violations. Infostealer facilitation. GDPR data disclosure of minors. Fictitious ToS as corporate fraud. Internal corruption and unregulated virtual currency. Taylor Wessing cannot defend all five simultaneously.

  • $450M estimated minimum liability

    Documented victim real spend across stolen accounts on LZT Market plus frozen inventories on banned bots — assets Valve appropriated under the guise of fighting fraud.

  • Valve's own servers host the evidence

    Thousands of sanctions bypass tutorials and region-switching guides are hosted on Steam Community servers, indexed by Google, accessible to non-logged-in users. Valve moderates this platform. Nothing was removed.

Evidence boundary. All statistics reflect point-in-time measurements from direct LZT Market public API observation. Legal analysis reflects published US and EU law as of August 2026. All regulatory contacts are public official data.

An Exclusive Investigative Report by PhishDestroy Research

Who is PhishDestroy to challenge the Valve corporate machine? Where do our data on their vaunted European lawyers come from — the very ones whose reputation has been stained by internal sexual harassment lawsuits? They love to flaunt their status and "centuries-long history," but their memory goes conveniently blank when it comes to the origins of their German branch. They conveniently erase from their corporate chronicle the fact that the founder of their firm was a committed Nazi and a member of Hitler's Reichstag — a cog in a system that sent gay people to concentration camps.

But enough about history. Let's return to technical reality. These "elite attorneys" demonstrate absolute incompetence when processing GDPR requests — they simply do not know how to properly redact confidential information from documents. This is not an intern's mistake. This is direct evidence that they have never adhered to data disclosure procedures, preferring to deflect requests with threats and legal intimidation.

1. Genesis of PhishDestroy: Destroying C2 Infrastructure Instead of Bug Bounties

Between 2018 and 2021, the Steam ecosystem was experiencing a boom in uncontrolled spam. The name "PhishDestroy" did not yet exist, but it was us who laid the foundation for anti-fraud work within Steam. We are not pinning medals on ourselves — we were simply doing the dirty work that the corporation refused to do. From the moment of our inception to this day, we destroy scammer infrastructure on an industrial scale.

At that time, we brought our confirmed report count on Netcraft [1] to between 5,000 and 10,000. Given the specifics of the platform, the real number of generated reports was at least ten times higher. Netcraft required ironclad proof of phishing. Why? Because Valve categorically refused to cooperate with either security providers or anti-scam initiatives. Some reports simply died in the pipeline before being processed. Persistent phishing campaigns — especially resources hidden behind aggressive cloaking — required recording video evidence and parallel escalation through Cloudflare's abuse departments [2].

We saw the scam, and we destroyed it. Not to save naive users. We were banning resources solely for the purpose of inflicting financial and infrastructural damage on phishers. If the corporate sector thinks we were burning scammer servers for the sake of an iPad from Netcraft's Reporter Prizes program [1] — you are wrong. We have always been a strictly non-commercial operation. Our principled refusal of donations and rewards is a declaration of our independence and loyalty exclusively to the process of destruction.

2. Complicity and Monetization: How Valve Profits from Phishing

In those years, Steam's "security" rested on 50 volunteers. We were in contact with one of them — a Belarusian who went by the nickname Colt. He was the only one trying to block the malicious links that were flooding the platform. The ideal victim: children. The ideal accomplice: Valve.

THE X2/X3 MULTIPLIER — how Valve profits from every stolen account
×1 Victim buys the game — normal revenue.
×2 Account stolen → victim creates new account, buys the same games again.
×3 Scammer sells stolen skins via Community Market — Valve collects 15% commission.
+∞ Banned bot inventory frozen → artificial scarcity → prices rise → more commission forever.

The corporation did not merely turn a blind eye to phishing — it had a financial interest in it. Our data directly proves the implementation of algorithmic cynicism: the likelihood of a scammer bot being blocked depends directly on the value of the stolen inventory. Since 2021, following the introduction of trade holds, the theft of a skin worth $2,000 or more guarantees nearly a 90% chance of the fraudster's account being banned.

But here is the detail no one talks about: the ban does not benefit the victim. The assets are frozen on the banned account, effectively returning to Valve's economy. The corporation appropriates windfall profits under the guise of fighting fraud. And this applies not only to CS — scamming flourishes in Team Fortress and other titles, where bans work more aggressively only thanks to community activity and the targeted efforts of individual moderators.

3. Business Logic Abuse: Steam as a Digital Crime Scene

We have the right to publicly dissect Valve's complicity in the scam industry, because we have seen their rotten architecture from the inside. At the beginning of our work, we tried to engage with support. We created tickets and attached domains leading directly to phishing landing pages. Do you know what the Russian-language outsourced support responded?

"We are prohibited from following links. If you send a link again, we will ban your account."

This is not a security policy. This is concealment of evidence.

The overwhelming majority of phishing was distributed inside the platform itself. Steam is a closed ecosystem, ideal for conducting Business Logic Abuse. Users did not even need to leave the client. Attackers used the built-in browser in Big Picture mode. The attack vectors were primitive but effective: personal messages, comments, infected usernames carrying non-unique spam along the lines of "hello bro join giveaway free knife link use code GABEN."

The Steam client itself delivered the phishing, itself compromised the account, and itself facilitated the theft of skins. The corporation created a tool that devoured its users and refused to control it.

4. Billions for 79 People: The Anatomy of Valve's Greed

The scale of that profit and the level of corporate cynicism only became clear after the massive data leak of 2024 [3].

The documents revealed a shocking truth: as of 2021, the entire corporation employed exactly 336 people [3]. And working directly on the Steam platform — a global monopoly generating billions of dollars in revenue — were just 79 people [3]. Valve is not merely economizing on personnel. Internal documents show them boasting that their profit per employee exceeds that of Google, Amazon, and Microsoft.

These figures are not just a business case. This is mathematical proof of absolute disregard for security. A platform serving hundreds of millions of users physically cannot ensure protection with 79 people.

79 employees managing Steam for 500,000,000+ users.
That is 6.3 million users per security engineer. Twitter maintained 1 per 100,000.
But they do not need it to.

5. Lolzteam and the Shadow Economy of Stolen Profiles

Valve's fairy tale goes like this: "It's the user's own fault if they got hacked." The reality reads differently: Valve spawned the scam infrastructure, never fought it, and deliberately maintains a vast shadow layer of the economy aimed primarily at the CIS countries and China. The reason is simple — retaining audience, compensating for piracy, and fencing stolen assets.

Let's look at the black market figures that Valve refuses to see. The LZT Market platform (Lolzteam) is the epicenter for selling stolen accounts. Let us look at a real-time snapshot of the listings: right now the market has 578,465 Steam accounts listed [4]. Of these:

📊 Live Data — LZT Market Real-Time Snapshot
  • 86,668 accounts were stolen via infostealers.
  • 66,744 were obtained through brute force.
  • 7,081 are the result of direct phishing.
  • 1,026 accounts were restored through Steam support and resold
    DIRECT PROOF OF OUTSOURCED CORRUPTION

    1,026 accounts on LZT Market are listed as “recovered through Steam support” and resold. Valve support staff restored access to dormant accounts for criminals — documented, enumerable, legally actionable.

    (direct proof of outsourced incompetence).
  • 126,429 accounts have no $5 spending limit (meaning live users spent real money on them).

Source: LZT Market public API · Point-in-time measurement · PhishDestroy research, August 2026

The minimum estimated damage from accounts without a spending limit alone is over $630,000 at this very moment. But the real transaction figure is hundreds of times larger.

And here a certain figure named Nikita surfaces — a person who allegedly oversaw the Russian-language Steam support outsource (not affiliated with the Irish office) for many years. His account was registered directly on the Lolzteam platform. Why? To monitor large inventories and block them? To collect analytics?

Even if so, blocking stolen profiles does not require registering on shadow forums. LZT Market uses a public API. Valve can plainly see the mass, identical requests: password changes, email detachments, automated inventory checkers and account validators. All of these come from the IP addresses of known proxy farms.

The behavioral pattern of a stolen account being listed on the market lights up in Valve's logs like a Christmas tree. But the corporation prefers to look away.

6. Scale of the Catastrophe: Tens of Millions of Dollars Off the Books

Valve does not publish reporting on black markets, but the math is merciless. Item IDs on the LZT market (e.g., item_id 252853378 [4]) show that over 250 million lots have passed through the platform. Of these, the Steam category has historically accounted for 30-40%.

This means that over the platform's history, between 75 and 100 million Steam accounts have been passed through it. The same stolen profile can be resold dozens of times, generating an endless chain of transactions until it is permanently banned.

Each day, conservatively around 25,000 transactions are conducted in the Steam category — from cheap auto-registrations to high-value phished accounts. With an average transaction price of 150-200 rubles, this category alone generates between 3.5 and 5 million rubles in daily turnover. The annual volume of the shadow market around Steam on just this one platform reaches tens of millions of dollars. The market takes its commission (8-9%), the scammers receive windfall profits, and users lose money.

And what does Valve do? Valve counts profits per their 79 employees and continues to pretend that nothing is happening.

7. Legalizing Theft and the Steam Crypto Laundromat

Look at the ecosystem they refuse to acknowledge. The infrastructure for selling stolen accounts on Lolzteam is not hiding in the dark web. It openly accepts payments via crypto bots (Telegram, Binance [28], Bybit [28], Gate [28]), Russian bank cards, and even PIX or Alipay. A commission is charged on every transaction. A massive array of confidential data, including correspondence and personal information of US and European citizens, passes through these gateways.

And what does Steam do? They send an email about a credential change. If an account is stolen from a child (who is the primary audience of cheat industries in CS:GO and PUBG), the platform simply watches as a permanent VAC ban is placed on the profile. Valve possesses all the technical telemetry: they see patterns of IP address, hardware, and behavioral metric changes. They can stop the theft in real time. But doing nothing and waiting for the victim to create a new account and repurchase games — this is not an accident; this is an approved business model.

Incidentally, the shadow market itself has long ceased to be a "club of independent hackers." The forum on which this infrastructure is based is effectively controlled by structures close to the Russian government, with which Steam apparently coexists quite comfortably. Five decisions by Roskomnadzor [23] to block the resource have been successfully ignored or appealed in an invisible legal field — draw your own conclusions.

7a. Tiền pháp định kỹ thuật số: Tại sao các skin trên Steam không phải là vật phẩm trong game — chúng là một mạng lưới thanh toán không được cấp phép

Valve đã dành nhiều năm để xây dựng một giả thuyết pháp lý: rằng các skin chỉ là “các điểm ảnh trong trò chơi” không có giá trị trong thế giới thực. Giả thuyết này sụp đổ ngay khi phân tích cơ bản nhất về cách tiền thực sự lưu chuyển qua nền tảng của họ.

NGUYÊN LÝ 200 ĐÔ LA — chứng minh giá trị tài sản vật chất

Một thẻ quà tặng Steam trị giá 200 USD được kích hoạt. Tiền USD thực sự được chuyển vào tài khoản ngân hàng của Valve. Số dư này được sử dụng để mua một con dao trong game. Bây giờ: (1) Con dao đó có thể được dùng để nạp tiền vào LZT Market để mua các tài khoản bị đánh cắp không? Có. (2) Liệu nó có thể được bán trên các thị trường bên thứ ba (BitSkins, DMarket, Skinport) để đổi lấy rúp, đô la, PayPal hoặc tiền điện tử thật không? Có.

Điều này chứng minh vật phẩm có giá trị thực được hậu thuẫn bởi nhu cầu cộng đồng và hạ tầng nền tảng tập trung. Bạn có thể đầu tư tiền thật, sở hữu một skin và thanh lý nó với số tiền gần như tương đương. Đây chính là định nghĩa của một tài sản tài chính có tính thanh khoản.

Bằng chứng rõ ràng: Bạn có thể sở hữu và lưu trữ skin Steam mà không cần sở hữu trò chơi mà chúng thuộc về. Tại sao người dùng lại giữ những pixel cho một trò chơi mà họ không thể chơi? Để đầu tư và giao dịch. Valve đã xây dựng một công cụ đầu tư và gọi nó là giải trí để tránh các quy định tài chính.
KẾ HOẠCH A — Rửa tiền từ tiền mặt sang tiền điện tử (Mô hình Cartel)
TIỀN
BẨN từ hoạt động của cartel
CÁC KI-Ô TIỀN MẶT địa phương của STEAM TERMINAL
1.000 VẬT PHẨM
DOTA GIỐNG
HỆT NHAU chưa ra mắt trò chơi
BITSKINS
BÁN
trên thị trường bên ngoài
BITCOIN
SẠCH
Đã được rửa tiền hoàn toàn

Đây không phải là hành vi của người chơi. Đây là hoạt động chuyển tiền tài chính. Việc không có bất kỳ hoạt động chơi game nào trên tài khoản là một dấu hiệu cảnh báo mà bất kỳ nền tảng tài chính được quản lý nào cũng sẽ phát hiện và báo cáo. Hệ thống của Valve sẽ đánh dấu sự bất thường này và cấm tài khoản — sau đó âm thầm giữ lại 100% số tiền gửi ban đầu thông qua cơ chế Forced Breakage, mà không báo cáo gì cho bất kỳ cơ quan quản lý tài chính nào.

KẾ HOẠCH B — Trộn tiền điện tử qua sòng bạc (Tiền điện tử bẩn → Tiền pháp định sạch)
Tiền thu được từ hack tiền
điện tử "bẩn"
Tiền gửi tiền điện tử vào Sòng bạc STEAM
(CSGOFast)
RÚT
TIỀN DƯỚI DẠNG SKINS
không để lại dấu vết trên blockchain
BÁN
TRÊN THỊ TRƯỜNG
KYC — sàn giao dịch hợp pháp
TIỀN FIAT
SẠCH CHUYỂN VÀO TÀI
KHOẢN NGÂN HÀNG đã được rửa hoàn toàn

Không giống như Monero hay Tornado Cash, skin Steam không kích hoạt cảnh báo trên trình khám phá blockchain. Các ngân hàng chỉ thấy một giao dịch bán bình thường trên thị trường trò chơi. Tiền điện tử bẩn đã được chuyển đổi, thông qua cơ sở hạ tầng nền tảng của Valve, thành tiền pháp định sạch không thể truy vết. CSGOFast thuộc sở hữu của người Nga. Sòng bạc này bị cấm tại một số quốc gia EU. Steam lưu trữ tiện ích mở rộng quảng cáo của nó.

PHÂN LOẠI PHÁP LÝ: Valve Corporation vận hành Doanh nghiệp Dịch vụ Tiền tệ (MSB) không có giấy phép lớn nhất thế giới theo định nghĩa tại Đạo luật Bảo mật Ngân hàng (31U.S.C . §5330) và quy định tương đương của EU (Chỉ thị AMLD6). Một MSB là bất kỳ thực thể nào truyền tải, trao đổi hoặc lưu trữ giá trị cho bên thứ ba. Steam thực hiện cả ba hoạt động này — với quy mô vượt xa hầu hết các tổ chức tài chính được cấp phép — mà không nộp bất kỳ báo cáo hoạt động đáng ngờ (SAR) nào, không áp dụng các thủ tục xác minh danh tính khách hàng (KYC) và chống rửa tiền (AML) đối với các giao dịch skin, cũng như không đăng ký với FinCEN. Đây là một tội phạm liên bang tại Hoa Kỳ.

8. The Economics of Catastrophe: Steam as the Foundation of the Black Market

You might say that markets like this don't sell only Steam. True — profiles from World of Tanks (~340k), Fortnite (~140k), TikTok, and Discord are also traded there. But Steam is historically the foundation and the primary driver of this industry. Valve inventories and accounts create demand for infostealers. If Steam had implemented strict anti-theft measures, the development of stealers would simply become economically unviable.

An important detail: accounts stolen solely via SSFN files are almost never listed on the market. Mobile authenticators complicated full account takeover. However, SSFN files give attackers an active session, a contact list, and the ability to send phishing en masse or integrate into botnets. And if the account is truly valuable, Steam's outsourced support enters the picture. Fraudsters draw up fake activation keys, write to support, and incompetent (or bribed) employees transfer the expensive inventory to a new address. This gave rise to an entire category of "Recovered Accounts" — profiles that Valve's outsource effectively stole and laundered for criminals.

9. The Myth of Duplication and Shadow Confiscation of Assets

Steam Account Theft Pipeline — Valve Sees Every Step
VICTIM
Phishing/Stealer/Brute
SCAMMER BOT
7-day mandatory hold
(Valve sees the transfer)
LZT MARKET
Listed for <$250 avg
(API checkers active)
BUYER
Resale / drain / spam
VALVE
15% commission on skins
+ frozen inventory
The 7-day trade hold is not a security measure. It is a transparent forensic window that Valve chose never to act on.
DiagramThe linear theft pipeline Valve could have disrupted at any step since March 2016.Every transaction visible in Steam logs. Action was a choice.

Steam loves to hide behind fighting "duping" (item duplication) to justify refusing to return stolen items. This is a brazen lie. The era of duping ended in 2014. With the introduction of the 7-day trade hold in December 2015 [14] (and its subsequent tightening), the logistics of theft became entirely linear: Victim -> Scammer's bot (7-day hold) -> Shadow market.

Where is the dupe in this? If a scammer deceived a victim and took a rare skin, it sits on the bot. Valve bans that bot. And then what? The item does not return to the victim. It is permanently frozen in the banned bot's inventory. Valve removes the asset from circulation, creating artificial scarcity of rare items, which directly drives up prices on the marketplace and increases the corporation's commission income.

This is not justice. This is shadow confiscation. In financial systems (such as those involving USDT), blocked funds are returned to the legitimate owner through a chargeback mechanism. Steam knows perfectly well how a chargeback works when it comes to topping up their own balance with dubious cards — they block those transactions instantly. But when a user has an item worth $5,000 stolen, Steam washes its hands. They close tickets, threaten account deletion, and refuse to reverse the single fraudulent transaction, proving that their primary objective is to appropriate the asset for themselves.

9a. Sự mù quáng bị ép buộc: Cách Valve che giấu hàng trăm triệu tài sản bị tịch thu

CẤU TRÚC PHÁP LÝ BA TẦNG — lý do tại sao Valve làm cho các kho hàng bị cấm trở nên vô hình
1. PHÁ HỦY BẰNG CHỨNG CHO CÁC VỤ KIỆN TẬP THỂ

Khi tài sản trong tài khoản bị cấm còn được công khai, bất kỳ luật sư nào cũng có thể truy vấn SteamDB, CSGO.exchange hoặc Backpack.tf và trong vài giây, đưa ra tổng giá trị tài sản đã được kiểm toán mà Valve đang nắm giữ. Con số đó — ước tính khoảng 300–500 triệu USD tài sản người dùng bị đóng băng — là con số cơ bản cần thiết để chứng nhận một vụ kiện tập thể. Valve đã cố tình đóng cửa cơ hội này. Bằng cách ép các tài sản vào một “hộp đen”, họ đã loại bỏ dấu vết kiểm toán tài chính độc lập mà luật sư của nguyên đơn cần để xác định mức độ thiệt hại trên quy mô lớn.

2. CHẶN GIẤY PHÉP TRÒ CHƠI CỦA BÊN THỨ BA — CAN THIỆP TRÁI PHÁP LUẬT

Khi Valve khóa một tài khoản, họ thu hồi quyền truy cập vào các trò chơi của CD Projekt Red, EA, Ubisoft và hàng nghìn nhà phát hành độc lập — những trò chơi mà người dùng sở hữu giấy phép thông qua các nhà phát hành đó, chứ không phải thông qua Valve. Valve chỉ là nhà phân phối và cổng thanh toán trong chuỗi hợp đồng đó, chứ không phải bên cấp phép. Việc thu hồi giấy phép vĩnh viễn do bên thứ ba cấp — do tranh chấp trên Steam Marketplace — là một trường hợp điển hình của hành vi can thiệp trái pháp luật vào hợp đồng. Theo Chỉ thị về Quyền của Người tiêu dùng của EU, việc chặn quyền truy cập vào nội dung kỹ thuật số đã thanh toán mà không hoàn tiền, trong trường hợp không có vi phạm nào đối với sản phẩm cụ thể đó, cấu thành hành vi vi phạm trực tiếp quyền sở hữu của người dùng đối với giấy phép.

3. MẸO VỀ CƠ SỞ DỮ LIỆU CẤM “VĨNH VIỄN” — sự bắt chước pháp lý

Valve không ghi “vĩnh viễn” trong cơ sở dữ liệu cấm. Họ ghi các mốc thời gian cụ thể: 10 năm, 25 năm hoặc thời điểm tràn bộ đếm thời gian Unix 32-bit — ngày 19 tháng 1 năm 2038. Đây không phải là sự cố kỹ thuật. Đây là lối thoát pháp lý.

Trong các hệ thống pháp luật dân sự và theo học thuyết về các quyền cơ bản của EU, điều khoản dịch vụ của một công ty tư nhân không thể áp đặt việc tước đoạt vĩnh viễn, không thể đảo ngược đối với quyền sở hữu mà không qua xem xét của tòa án. Bằng cách gọi việc đình chỉ 25 năm là “hạn chế dịch vụ dài hạn”, Valve có thể lập luận trước tòa: “Đây là biện pháp an toàn tạm thời, không phải hình phạt vĩnh viễn.” Trong khi đó, người dùng thực tế bị tước bỏ tài khoản và tất cả các giấy phép trong suốt phần đời còn lại của họ. Valve đặt cược rằng phần lớn nạn nhân sẽ quên đi, chuyển sang việc khác hoặc không thể tồn tại qua khoảng thời gian bị cấm. Đây là hành vi “lừa dối tâm lý” được thiết kế ngay từ cấp độ kiến trúc cơ sở dữ liệu.

Vấn đề về tài sản không được nhận: Tại hầu hết các bang của Mỹ và các nước thành viên EU, tài sản do một thực thể tư nhân nắm giữ mà chủ sở hữu không thể truy cập trong vòng 3–5 năm trở lên phải được chuyển giao cho nhà nước theo Luật Tài sản Không Được Nhận. Các kho hàng Steam bị đóng băng — được Valve giữ trong nhiều năm sau khi cấm, mang lại lợi ích kinh tế gián tiếp cho Valve thông qua sự khan hiếm nhân tạo — có thể cấu thành hành vi giữ lại tài sản bất hợp pháp mà lẽ ra phải được chuyển giao. Chưa có cơ quan quản lý tiểu bang nào yêu cầu Valve phải giải trình. Khi họ làm vậy, “hộp đen” của Valve sẽ trở thành gánh nặng lớn nhất của họ.

Lý do “chống trùng lặp” của Steam hoàn toàn vô lý. Lỗ hổng trùng lặp vật phẩm cuối cùng được xác nhận đã được vá vào năm 2014. Mọi trường hợp cấm và đóng băng kể từ đó đều diễn ra theo một chuỗi trộm cắp tuyến tính — Nạn nhân → Bot lừa đảo → Thị trường → Kho hàng bị đóng băng của Valve — mà không có bất kỳ lý do kinh tế nào để giữ lại tài sản vĩnh viễn. Đơn vị duy nhất hưởng lợi từ việc đóng băng này chính là Valve, thông qua việc tăng giá vật phẩm, hoa hồng được thổi phồng và việc loại bỏ vĩnh viễn mọi trách nhiệm pháp lý đối với những gì đã xảy ra với tài sản đó.

TIỀN LỆ TRỪU TƯỢNG (THÁNG 7 NĂM 2018) — bằng chứng được ghi lại rằng Valve CÓ THỂ đảo ngược các giao dịch
KẾ HOẠCH
Các nhà phát triển dưới bí danh Kirill_Killer34 đã trả phí phát hành 100 đô la của Steam Direct để tải lên các trò chơi giả mạo “Abstractism” và “Climber.” Sau đó, họ tạo ra các vật phẩm trong kho đồ của những trò chơi này, là những bản sao chính xác đến từng pixel của những vật phẩm đắt nhất trong toàn bộ nền kinh tế Steam: CS:GO AWP | Dragon Lore, Dota 2 Dragonclaw Hook và TF2 Australium Rocket Launcher. Hàng nghìn người giao dịch đã nhìn thấy thứ trông giống như một chiếc Dragon Lore trong cửa sổ giao dịch. Tên trò chơi “Climber” được hiển thị bằng chữ nhỏ. Họ đã trao đổi các vật phẩm thật, có giá trị cao lấy những hình ảnh trống rỗng từ một trò chơi rác. Các trò chơi này còn chứa một trình khai thác tiền điện tử Monero ẩn, chạy âm thầm trên máy tính của các nạn nhân.
PHẢN ỨNG CỦA VALVE — lời thừa nhận “vàng”
Khi vụ bê bối bùng nổ trên Reddit (“Các nhà phát triển phần mềm rác trên Steam Direct tạo ra các vật phẩm giả mạo của TF2, DOTA2 và CS:GO”), nhà phát triển chính thức của Valve, Tony Paloma (u/Drunken_F00l) đã xuất hiện trong chủ đề này. Valve đã gỡ bỏ các trò chơi, cấm các nhà phát triển, đưa ra các biểu ngữ cảnh báo giao dịch (“Bạn chưa bao giờ chơi trò chơi này”) và — quan trọng nhất — chính thức xác nhận rằng những nạn nhân bị mất vật phẩm trước khi có biểu ngữ cảnh báo sẽ được hoàn trả vật phẩm của họ. Người dùng đã xác nhận rằng họ đã nhận lại được vật phẩm của mình. Việc hoàn trả đã diễn ra. Trên quy mô lớn. Mà không làm ảnh hưởng đến nền kinh tế trong game.
SỰ PHỦ NHẬN HỢP LÝ ĐỐI VỚI LỜI KHAI “KHÔNG THỂ THỰC HIỆN VỀ MẶT KỸ THUẬT” CỦA VALVE
SỰ THẬT 1 Vào tháng 7 năm 2018, Valve đã khôi phục lại hàng nghìn giao dịch gian lận liên quan đến các vật phẩm cấp Dragon Lore. Nền kinh tế không sụp đổ. Không xảy ra hiện tượng nhân bản hàng loạt. Việc khôi phục đã thành công.
SỰ THẬT 2: Kể từ năm 2016, khi người dùng mất vật phẩm do các trò lừa đảo “API”, lừa đảo qua email (phishing) hoặc việc chiếm quyền kiểm soát tài khoản do phần mềm đánh cắp thông tin gây ra, bộ phận hỗ trợ Steam trả lời: “Việc khôi phục vật phẩm là không thể và có thể dẫn đến việc sao chép vật phẩm.”
KẾT LUẬN: Khả năng kỹ thuật đã tồn tại và đã được áp dụng. Vấn đề không nằm ở khả năng kỹ thuật. Vấn đề nằm ở việc ai là người có lỗi. Năm 2018, quy trình kiểm duyệt của chính Valve đã thất bại (họ đã phê duyệt các trò chơi giả mạo). Rủi ro pháp lý là trực tiếp và khổng lồ. Chức năng khôi phục đã được kích hoạt. Khi những kẻ lừa đảo trên API vét sạch kho đồ của bạn vì Valve từ chối vá lỗ hổng phát hiện bất thường, theo cách giải thích của chính họ, Valve không có lỗi — do đó chức năng khôi phục vẫn bị tắt. Món đồ Dragon Lore của bạn bị đóng băng. Valve thu 15% khi bán lại món đồ đó.
Nguồn chính: Chuỗi bài đăng trên Reddit r/Steam · “Các nhà phát triển trò chơi rác trên Steam Direct tạo ra các vật phẩm giả mạo của TF2, DOTA2 và CS:GO” — xác nhận chính thức từ một nhân viên phát triển của Valve có tên u/Drunken_F00l. Đã lưu trữ. Có thể được yêu cầu cung cấp làm bằng chứng. Đây không phải là suy đoán — đây là tuyên bố được ghi chép lại, chính thức từ một nhân viên Valve được nêu tên, xác nhận rằng việc đảo ngược giao dịch về mặt kỹ thuật là khả thi và đã được thực hiện. Quan điểm “không thể” hiện tại của họ là một lời nói dối có thể chứng minh được.
CƠ CHẾ TỊCH THU 100% — tại sao mức hoa hồng 15% là con số sai
Bước 1
Tiền pháp định được chuyển vào tài khoản ngân hàng của Valve
Người dùng nạp tiền thật vào ví. Số tiền đó được chuyển vào tài khoản ngân hàng của Valve ngay lập tức và vĩnh viễn. Tiền trong ví Steam không thể rút ra. Valve đã sở hữu 100% số tiền đó.
Bước 2
Skin = Giấy nợ kỹ thuật số
Mặt hàng trong kho là một giấy nợ kỹ thuật số. Valve nợ người sở hữu một tài sản ảo. Trong khi nó lưu hành, nó vẫn giữ được sức mua trong hệ sinh thái. Valve có một khoản nợ trên sổ cái nội bộ của họ.
Bước 3
Cấm tài khoản = Phá vỡ bắt buộc
Cấm tài khoản. Phiếu nợ kỹ thuật số bị hủy bỏ. Nợ nội bộ của Valve biến mất. Tiền pháp định thực sự đã đảm bảo cho vật phẩm đó? Đã có trong ngân hàng của Valve. Valve giữ 100%. Đây là việc hủy bỏ của công ty — giống hệt như việc hết hạn thẻ quà tặng, nhưng bị ép buộc bởi quyết định cấm đơn phương.
TOÁN HỌC CỦA VIỆC TỊCH THU 100%
Mô hình 15% (theo tuyên bố của Valve):
Kẻ lừa đảo bán Dragon Lore bị đánh cắp trên Community Market. Valve thu 15% hoa hồng = $300 trên một skin trị giá $2,000.
Mô hình 100% (điều thực sự xảy ra):
Valve cấm tài khoản bot lừa đảo. Dragon Lore bị đóng băng vĩnh viễn. Valve loại bỏ $2,000 nợ ảo. Người mua ban đầu đã trả $2,000 tiền mặt thực. Valve giữ $2,000. Hoa hồng: 100%.
Phí hoa hồng 15% trên Community Market không phải là nguồn lợi nhuận chính. Đó chỉ là chi phí phụ. Động lực thực sự là chu trình “cấm và đóng băng”: người dùng nạp tiền fiat vào hệ thống ngân hàng của Valve để mua tài sản ảo, những tài sản đó bị tiêu hủy thông qua việc cấm, và tiền fiat vẫn còn lại. Valve không quan tâm liệu kẻ lừa đảo hay người dùng hợp pháp đang nắm giữ kho hàng bị cấm. Việc cấm $100,000 giá trị vật phẩm xóa bỏ $100,000 nợ ảo của Valve trong khi vẫn giữ nguyên $100,000 ban đầu trong tài khoản ngân hàng của họ. Đây không phải là biện pháp bảo mật. Đây là hành vi chiếm đoạt tiền pháp định đơn phương mà không qua thủ tục tư pháp.
Phân loại pháp lý: Trong tài chính truyền thống, thu nhập từ tài sản bị hủy (số dư thẻ quà tặng không được nhận, điểm thưởng hết hạn) được quy định tại hầu hết các khu vực pháp lý — các công ty phải công bố thông tin này và, sau một khoảng thời gian theo luật định, thường phải chuyển giao số tiền đó cho nhà nước. Việc Valve cưỡng chế hủy bỏ tài sản thông qua các lệnh cấm không được công bố cũng như không được chuyển giao cho nhà nước . Nó không được phân loại là gì cả — bị chôn vùi dưới danh nghĩa chung chung là “thực thi Điều khoản Dịch vụ (ToS)”. Theo các chỉ thị kế toán của EU và Chuẩn mực Kế toán Hoa Kỳ (US GAAP), thu nhập từ tài sản bị hủy bỏ đáng kể mà không được công bố có thể cấu thành hành vi trình bày sai lệch tài chính trong bất kỳ báo cáo công khai nào. Vì Valve là công ty tư nhân và không công bố báo cáo tài chính công khai, khoản nợ này đã tích lũy không bị thách thức trong suốt một thập kỷ.
Trình diễn tương tác: Thu hồi tài sản — Giao thức Tether so với Nền tảng Steam

So sánh song song: cách Tether khôi phục 10.000 USD USDT (vụ hack Bybit) so với cách bộ phận hỗ trợ của Steam phản ứng trước một vụ trộm tương tự. Nhấp vào RUN để mô phỏng cả hai trường hợp.

10. A Training Ground for Global Scamming

PhishDestroy has been tracking scams since 2018. We know the inner workings. Steam became the primary incubator for cybercriminals. Teenagers aged 14-19 who started with primitive brute-forcing and distributing stealers through fake TeamSpeak servers have grown up. Today those same people use the techniques they refined to attack the Web3 industry (Uniswap) [26] and corporate networks.

Valve raised this generation. Their refusal to punish, their blindness, and their greed showed underage fraudsters that stealing is safe. And the Russian-language outsource, playing at justice and handing out permanent bans without explanation (hiding behind non-disclosure of VAC algorithms), only reinforces this impunity.

10a. Sự tương phản của Twitch: Điều gì sẽ xảy ra khi một nền tảng thực sự quyết tâm chống lại

Valve khẳng định việc chống lại các vụ lừa đảo quy mô lớn là không thể. So sánh với Twitch chứng minh điều này là sai sự thật.

VỤ LỪA ĐẢO TRỰC TUYẾN GIẢ MẠO TRÊN TWITCH — và cách Twitch đã chấm dứt nó

Trong một thời gian, Twitch tràn ngập các luồng phát trực tiếp giả mạo “tặng skin Steam” mạo danh các tuyển thủ thể thao điện tử chuyên nghiệp — tất cả đều thực hiện các chiêu lừa đảo Steam và lừa đảo trực tuyến làm mục tiêu chính. Các luồng phát trực tiếp này đã thu hút hơn 20.000 người xem giả mạo thông qua lưu lượng truy cập mua sẵn. PhishDestroy đã ghi lại diễn biến của chiến dịch và báo cáo tích cực.

PHẢN ỨNG CỦA TWITCH (THỰC TẾ)
  • Cấm kênh ngay lập tức khi nhận được báo cáo
  • Cấm nhóm proxy — chặn toàn bộ dải địa chỉ IP
  • Thay đổi thuật toán: sắp xếp theo mức độ tương tác, không phải số lượng người xem thô
  • Cơ chế cấm tự động: tài khoản mới + bắt đầu phát trực tiếp + lượng người xem tăng đột biến bất thường
  • ~45.000 kênh bị gỡ bỏ trong suốt thời gian diễn ra chiến dịch
  • ~2.000 tên miền bị báo cáo và gỡ bỏ
ĐƯỜNG CONG SUY GIẢM CÓ THỂ QUAN SÁT ĐƯỢC
20.000 người xem · cấm
10.000 · khóa
3.000 · bị cấm
Chết
Mỗi buổi phát trực tiếp tiếp theo đều thu hút ít người xem hơn trước khi kết thúc. Chiến dịch này đã thất bại do sự suy giảm dần trong vòng vài tháng.
Nhận định quan trọng: Twitch đã chiến đấu chống lại các vụ lừa đảo trên Steam — không phải việc đánh cắp tài khoản Twitch, cũng không phải gian lận vật phẩm ảo trên Twitch. Họ đã triển khai nguồn lực đáng kể — kiểm duyệt thủ công, hệ thống cấm tự động, thay đổi thuật toán — để bảo vệ người dùng khỏi một vụ lừa đảo kiếm tiền thông qua nền tảng khác . Twitch đã quan tâm đủ đến người dùng của mình để chống lại các vụ lừa đảo trên Steam. Steam thì chưa bao giờ quan tâm đủ đến người dùng của mình để chống lại các vụ lừa đảo trên chính nền tảng Steam.

So sánh này phá vỡ lập luận cuối cùng mà Valve có thể đưa ra: rằng vấn đề quá lớn và diễn biến quá nhanh để có thể đối phó trên quy mô lớn. Twitch đã chứng minh rằng các hành động quyết liệt và có mục tiêu của nền tảng có thể làm suy yếu và tiêu diệt các hoạt động lừa đảo tinh vi chỉ trong vòng vài tháng. Steam đã có những công cụ tương tự, nhiều nguồn lực hơn và lợi ích tài chính trực tiếp trong việc bảo vệ chủ tài khoản — trong hơn một thập kỷ qua. Quyết định không hành động luôn là một sự lựa chọn.

EPIC GAMES — VÍ DỤ THỨ HAI: CHẶN TÍCH CỰC THEO THỜI GIAN THỰC

Trong khi Valve thu 15% hoa hồng từ các tài khoản Steam bị đánh cắp, Epic Games lại áp dụng cách tiếp cận ngược lại. Tại thời điểm điều tra này, LZT Market hiển thị một thông báo hệ thống đang hoạt động cho danh mục Fortnite/Epic Games: “Epic Games (bị vô hiệu hóa một phần: tính năng tải lên và xác minh tài khoản có thể không khả dụng)” — có nghĩa là hệ thống hậu trường của Epic chủ động phát hiện và chặn các hệ thống tự động mà LZT sử dụng để xác thực và liệt kê các tài khoản bị đánh cắp. Epic không chỉ chống lại những kẻ lừa đảo. Họ còn chống lại chính cơ sở hạ tầng của thị trường này, theo thời gian thực.

CÁCH TIẾP CẬN CỦA EPIC GAMES
  • Chặn chủ động các điểm cuối kiểm tra tài khoản API của LZT Market
  • Các hệ thống chống tự động hóa phát hiện và vô hiệu hóa việc xác thực tài khoản hàng loạt
  • Vô hiệu hóa theo thời gian thực các kênh tải lên tài khoản bị đánh cắp
  • Kết quả: Danh mục Fortnite trên LZT được đánh dấu là “bị vô hiệu hóa một phần”
“PHƯƠNG PHÁP” CỦA VALVE
  • API trên Steam vẫn hoàn toàn mở cửa cho các công cụ kiểm tra tài khoản trên LZT Market
  • Không có giới hạn tốc độ đối với các yêu cầu xác thực hàng loạt tự động
  • Không phát hiện các khóa API có nguồn gốc từ LZT
  • Kết quả: Steam là danh mục lớn nhất và hoạt động sôi nổi nhất trên LZT

Tham khảo: Sự phụ thuộc của ngành công nghiệp đánh cắp thông tin vào thông tin đăng nhập trò chơi được ghi nhận trong báo cáo của Infostealers.com: “Tương lai của tội phạm mạng năm 2025” — trong đó chỉ ra rằng các tài khoản trò chơi luôn nằm trong danh sách các mục tiêu có giá trị cao nhất của những kẻ đánh cắp thông tin. Các biện pháp đối phó tích cực của Epic Games chứng minh đây là một vấn đề có thể giải quyết được. Sự thiếu hành động của Valve là một lựa chọn chính sách, chứ không phải là hạn chế kỹ thuật.

11. Proof of Convenient Blindness

There is an irrefutable fact proving that Valve deliberately covered for black markets. For years — we emphasize, years — direct, open links to stolen Steam profiles were posted on the pages of shadow markets. Valve needed no complex investigations. A ten-line script could have parsed the market's database once a minute and placed a "Red Tag" (KT) on compromised accounts pending verification by the rightful owner.

This did not happen. Millions of transactions passed under the cover of "convenient blindness." Only recently have the markets begun proxying data (via steam-preview) to hide profiles from independent researchers and bypass privacy settings. But history remembers everything. Valve could have destroyed this market with a single click. Instead, they chose to skim the cream off it.

12. Digital Fingerprinting: Why Proxying Markets Does Not Save Valve

The newest defensive mechanism of shadow markets — proxying links through steam-preview — is used by Valve as yet another convenient excuse for their inaction. The corporation pretends that it is now "harder" for them to identify stolen profiles. This is an absolute lie. For Valve's security systems, an account listed for sale remains as transparent as glass.

Identification via Digital Fingerprint: The market's preview dump openly publishes exact purchase dates and amounts (for example, -2.85 EUR from June 15, 2026), the exact registration date, and balance. In Valve's database, no two accounts with an identical transaction history physically exist. A straightforward SQL query from the support side locates this profile in milliseconds, even if a direct link to it is hidden behind a proxy.

API Anomalies and Interception Patterns: To generate a preview, the shadow market's checker queries the Steam API. On the account itself, a characteristic chain reaction is triggered at that moment: email change, password reset, Steam Guard re-linking, and a simultaneous inventory valuation request, all compressed into a few minutes. All of this happens from the IP addresses of known proxy farms.

13. The Evolution of Interception: From SSFN to Pass-the-Cookie and JWT

Valve's most egregious crime is not the theft of skins. It is their conscious facilitation of the spread of malicious software and the financing of global botnets through vulnerabilities in their own architecture.

For a long time, the primary vector for session interception was SSFN files [27]. Today the industry has moved forward: attacks have shifted to hijacking web session cookies and JWT tokens (JSON Web Tokens) [21]. The architecture of scamming has become smarter — attackers have learned to validate these tokens locally, without direct requests to Steam's servers, making such attacks invisible to Valve's primitive anti-fraud systems, assuming those systems are not configured for strict monitoring (and they are not).

The technical mechanics work as follows:

Step 1. Trust Infrastructure as a Free Assembly Line: Since a single stolen token is often insufficient for fully unlinking a protected account, attackers squeeze a different resource from the obtained session — trust. A script gains access to the victim's chats and sends phishing links or virus installers to the entire contact list. Steam graciously provides hackers with its internal P2P infrastructure as a perfect, free engine for the geometric expansion of botnets.

Step 2. Criminal Negligence (Ignoring UEBA): Whether it's an outdated SSFN tied to specific hardware, or modern session cookies — Steam sees 100% of the anomalies. When a token legitimately issued to a PC in, say, Moscow suddenly initiates activity from a German dedicated server, any normal corporation (take Google, for example) would instantly kill the session and issue a red alert: "Session compromised. Your PC is infected with an infostealer." Steam does not do this. They allow the bot to burn through the entire friend list, infecting hundreds of new machines.

Interactive Demo: JWT P2P Propagation Engine
JWT_PROPAGATION_ANALYSIS_ENGINE
SESSION: GRAPH_DEPTH: 2 NODES_COMPROMISED: 1 PROTOCOL: JWT_P2P_RELAY ENGINE_CLOCK:
TIMESTAMP STEAM_ID64 JWT_HASH ATTACK_VECTOR STATUS

Demonstration of how a single compromised JWT token propagates through Steam's P2P friend network infrastructure.

Step 3. Global Damage (Corporate Collapse): This is where the main threat to the entire internet lies. Because Steam does not notify the user of the session interception, the person continues to sit at their compromised computer. If an alert had come, they would immediately wipe the OS. But Steam stays silent. That same person, on that same infected PC, continues to log into their corporate VPN, work email, and crypto wallets.

By ignoring session interception anomalies, Steam is not merely allowing the theft of in-game pixels. They are concealing from the user the fact that an infostealer is running on their system. This corporate blindness directly leads to massive corporate data breaches and infrastructure compromises, with damages running into millions of dollars.

Step 4. Exposing the Lie: The Lawyers' Data

Valve frequently hides behind the claim that they allegedly have "no technical capability" to track complex theft chains, or that "the user is at fault" for the compromise. But the case of the improperly redacted documents from their European lawyers (Taylor Wessing) [9], which we uncovered, proves the opposite.

In the unredacted GDPR request data [10], we clearly saw: Valve logs absolutely everything. They collect deep telemetry on hardware, IP addresses, device change histories, and behavioral patterns. They know the moment an account is hijacked. They see infostealers and spam-sending software running. They have all the tools for automatic blocking and issuing a Red Tag. Their inaction is a conscious corporate choice.

Step 5. Real Motives: Why This Benefits Valve

The lie about "technical impossibility" covers a cold economic calculation.

Support Cost Optimization via Scripts: Blocking a suspicious session means receiving a ticket from a user that needs to be processed. It is more profitable to simply ignore the incident. Steam relies on primitive scripting logic that scammers know perfectly and exploit. Russian-language support staff likely read these algorithms, but not to patch vulnerabilities. Issuing a Red Tag requires no man-hours if the algorithm is properly configured. Previously, a Red Tag could be removed automatically by simulating recovery from a new IP via a VPN. Now, ticket processing times are deliberately dragged out to discourage users from contacting support at all. And a support employee's ability to unilaterally close an unresolved ticket is the pinnacle of corporate cynicism.

The Money Cycle: A hijacked account that has burned through its friend list with spam will eventually receive a VAC ban or community ban. The victim (or their deceived contacts) registers a new account and buys the same games again. The corporation makes double revenue from a single user.

Symbiosis with the Shadow Market: The more accounts are stolen, the faster the gears of LZT Market and other hacker exchanges turn. This shadow activity paradoxically sustains the engagement of a huge audience (especially in regions where the cheat industry flourishes). And any subsequent transaction involving stolen skins still brings Valve their rightful commission percentage.

14. Trading in Lives: What Steam Is Actually Selling for $2

Valve claims to care about privacy. But what does an attacker who has bought a hijacked profile on the market for a couple of dollars actually receive? Steam will not show them the full credit card number, but it will hand over something far more valuable for social engineering.

With an active session (SSFN, cookies, or JWT), a hacker can pull the saved billing address in a few clicks — the victim's real first name, last name, city, and zip code. Through Steam's built-in data panel, they gain access to IP address history and links to other platforms (Twitch, Xbox). And if you look through the support ticket history, you will find archives of unredacted bank receipts and photos of activation keys from physical discs that users sent for verification.

WHAT A $0.08 STEAM ACCOUNT ACTUALLY CONTAINS — BEYOND IN-GAME ITEMS
CHILDREN'S PERSONAL DATA
Real name, last name, home address, postal code — from receipts and support tickets. Minors routinely share home addresses when requesting help with activation keys.
IP ADDRESS HISTORY
Full log of home IP addresses and hardware IDs. Reveals home network, ISP, geolocation. Direct target for spear-phishing and — in conflict zones — physical risk.
PERSONAL PHOTOS & CHATS
Via support tickets: photos of CD keys, receipts, family photos. Private chat archives store years of conversations — links to social accounts, passwords, family details.
CROSS-PLATFORM ACCESS
Steam profile links to Twitch, Xbox, Discord, YouTube. Active JWT session gives access to shared credentials. Infected PC = corporate VPN, email, crypto wallets.
Valve's own GDPR logs confirm they collect all of this. When forced to release data under GDPR Article 15, they handed over hardware fingerprints, IP histories, and behavioral logs — then tried to hide it under a black PDF overlay. Taylor Wessing redacted nothing. The data was fully readable. It was seen by at least 5 parties before the original owner received it.

But the most alarming aspect is the chat logs. We see how Valve has been carefully storing unencrypted archives of personal correspondence for years. In those archives, teenagers leave links to their real social media accounts, share their problems, send passwords for local servers and home IP addresses. By refusing to instantly reset hijacked sessions and by covering for infostealers, Steam effectively puts users' life histories and digital security on display in the windows of shadow markets.

14a. Hồ sơ kỹ thuật số trị giá 1,60 USD: Cách Steam bán cuộc sống của trẻ em cho các thị trường ngầm

Khi Valve đề cập đến vấn đề bảo mật tài khoản, họ thường nói về giá trị kho đồ. Nhưng giá trị thực sự của một tài khoản bị đánh cắp không thể đo lường bằng các pixel. Đối với hàng triệu thanh thiếu niên, Steam không chỉ là một cửa hàng — mà còn là mạng xã hội chính của họ. Nơi đây lưu giữ những thành tích, bí mật, mối quan hệ và những mối tình đầu của họ.

Khi một hacker đánh cắp một tài khoản và thản nhiên bán nó trên LZT Market với giá 150 rúp (khoảng 1,60 đô la), người mua không chỉ nhận được quyền truy cập vào các trò chơi. Họ còn nhận được một kho lưu trữ không được mã hóa về cuộc sống của một đứa trẻ.

TRÒ CHUYỆN, ẢNH VÀ CUỘC SỐNG RIÊNG TƯ

Steam lưu trữ hàng gigabyte tin nhắn cá nhân. Thanh thiếu niên sử dụng ứng dụng trong trò chơi để giao tiếp hàng ngày — những lời tỏ tình, những cuộc cãi vã, những kế hoạch cuộc đời. Các trường hợp được ghi nhận trên các diễn đàn ngầm cho thấy các tệp lưu trữ nhật ký bị rò rỉ chứa những bức ảnh cá nhân và riêng tư của trẻ vị thành niên. Valve không kiểm duyệt nội dung này, không triển khai mã hóa đầu cuối và cho phép những kẻ tấn công lấy cắp tất cả dữ liệu chỉ bằng một lần xuất.

ĐỊA CHỈ IP & MỐI ĐE DỌA VỀ THỂ CHẤT

Khi thanh thiếu niên chơi cùng nhau trên các máy chủ riêng, họ đăng địa chỉ IP nhà và các cổng mở trực tiếp trong trò chuyện Steam. Dữ liệu này nằm trong các bản ghi không được mã hóa trong nhiều năm. Đối với người mua tài khoản bị đánh cắp, đây là cơ sở dữ liệu sẵn có để thực hiện các cuộc tấn công DDoS, lừa đảo có mục tiêu, quét mạng gia đình — hoặc báo cảnh sát giả mạo. Mối đe dọa kỹ thuật số trở thành mối đe dọa thực tế chỉ trong vài phút.

SỰ VÔ LÝ CỦA MÃ CD-KEY

Khi một đứa trẻ mất đi cuộc sống xã hội, bộ phận hỗ trợ của Steam yêu cầu một bức ảnh chụp mã CD-key từ một trò chơi được tặng cách đây 10 năm. Một tập đoàn lưu trữ dấu vân tay phần cứng, vị trí địa lý và dữ liệu hành vi trong nhiều năm lại buộc một thiếu niên phải lục lọi bãi rác để tìm một chiếc hộp các-tông. Đây không phải là một hệ thống bảo mật. Đây là một cơ chế được thiết kế có chủ đích để từ chối hỗ trợ một cách hợp pháp.

► 150 rúp ($1,60) trên LZT Market mua được: phiên Steam đang hoạt động • nhật ký trò chuyện riêng tư trong nhiều năm • lịch sử địa chỉ IP tại nhà • các tài khoản Twitch/Xbox/Discord được liên kết • thành phố thanh toán và mã bưu chính • danh sách bạn bè (hơn 200 người) • toàn bộ lịch sử yêu cầu hỗ trợ • dấu vân tay phần cứng (để tấn công bằng phương pháp "credential stuffing" vào các mạng VPN của doanh nghiệp). Đây không phải là một tài khoản game. Đây là một hồ sơ thông tin cá nhân hoàn chỉnh về một trẻ vị thành niên.
VI PHẠM COPPA — ĐẠO LUẬT BẢO VỆ QUYỀN RIÊNG TƯ TRỰC TUYẾN CỦA TRẺ EM
Hơn 50.000
Tiền phạt
của FTC cho mỗi vi phạm
<13
Độ
tuổi mà COPPA áp dụng
70 triệu+
Số tài khoản được bán
qua LZT trong suốt thời gian hoạt động
NHỮNG YÊU CẦU CỦA COPPA — NHỮNG ĐIỀU STEAM BỎ QUA
COPPA quy định
  • Phải có sự đồng ý của phụ huynh có thể xác minh trước khi thu thập dữ liệu của trẻ em dưới 13 tuổi
  • Chính sách lưu trữ và xóa dữ liệu rõ ràng
  • Không chia sẻ thông tin cá nhân (PII) của trẻ em với bên thứ ba mà không có sự đồng ý
  • Giảm thiểu dữ liệu — chỉ thu thập những thông tin cần thiết
Thực tiễn hiện tại của Steam
  • Lịch sử IP, vị trí địa lý, dấu vân tay phần cứng — được ghi lại từ ngày đầu tiên
  • Lưu trữ các bản ghi trò chuyện riêng tư trong nhiều năm mà không có cơ chế xóa
  • Thông tin cá nhân (PII) được chia sẻ với đơn vị hỗ trợ bên ngoài (đã được Taylor Wessing xác nhận)
  • Các mã thông báo phiên JWT chứa dữ liệu người dùng bị rò rỉ qua các tài khoản bị xâm phạm lên các diễn đàn ngầm
Cách tính toán của FTC: Mỗi hồ sơ của trẻ em được thu thập, xử lý hoặc chuyển giao mà không có sự đồng ý của cha mẹ có thể xác minh được đều là một vi phạm COPPA riêng biệt , với mức phạt dân sự từ 50.000 USD trở lên. Steam không xác minh độ tuổi của người dùng mới. Nền tảng này không yêu cầu sự đồng ý của phụ huynh. Steam lưu trữ nhiều năm nhật ký trò chuyện, lịch sử IP và hồ sơ hành vi — sau đó cho phép dữ liệu đó thoát khỏi nền tảng thông qua các mã thông báo JWT bị xâm phạm, được rao bán trên LZT Market với giá 1,60 USD.
Tính toán theo công thức của FTC: 70 triệu tài khoản đã được bán trên LZT trong suốt thời gian hoạt động. Một ước tính thận trọng về mặt thống kê cho thấy tỷ lệ người dùng dưới 13 tuổi là 10–15% tổng số người chơi, theo chính báo cáo của Steam. Điều này tương đương với 7–10 triệu trường hợp vi phạm COPPA tiềm năng . Với mức phạt 50.000 USD cho mỗi trường hợp, mức bồi thường dân sự có thể lên tới 350 tỷ đến 500 tỷ USD — chưa tính đến các vụ kiện theo Đạo luật Bảo vệ Quyền riêng tư Trẻ em (GDPR ), các hành động của Tổng chưởng lý các bang, hay các vụ kiện tập thể. Con số này không phải là con số thực tế, vì việc thi hành luật mang tính chính trị. Tuy nhiên, trách nhiệm pháp lý về mặt cấu trúc vẫn tồn tại, và Valve chưa từng thực hiện một cuộc kiểm toán COPPA nào.

16a. Phân tích dữ liệu quy mô công nghiệp: Open API của Valve như một nền tảng nhắm mục tiêu nạn nhân

Làm thế nào mà những kẻ lừa đảo biết được ai là mục tiêu? Làm thế nào mà trẻ em lại trở thành nạn nhân trên quy mô công nghiệp? Bởi vì Valve đã để cánh cửa cơ sở dữ liệu của họ mở toang.

THỜI ĐẠI HATLER — Dịch vụ "API" của Steam như một công cụ quét nạn nhân quy mô công nghiệp

Trong nhiều năm, các nhà điều hành thị trường ngầm đã sử dụng phần mềm chuyên dụng (bao gồm các công cụ như Hatler) để phân tích người dùng Steam trên quy mô công nghiệp thông qua cơ sở dữ liệu mở API của Valve. Những kẻ lừa đảo đã cấu hình các bộ lọc giống như cách một nền tảng bán lẻ cấu hình tìm kiếm sản phẩm:

Bộ lọc: Thành viên nhóm. Phân tích tất cả thành viên của một cộng đồng game cụ thể. Nhắm mục tiêu những người hâm mộ một streamer nổi tiếng.
Bộ lọc: Giá trị kho đồ. Tìm tất cả người dùng có kho đồ mở chứa các vật phẩm cấp Covert trong CS:GO hoặc Arcanas trong Dota 2.
Bộ lọc: Trạng thái trực tuyến. Tìm tất cả người dùng hiện đang hoạt động. Thời điểm lừa đảo tối ưu: ngay bây giờ.
Dùng phương pháp brute-force dự phòng. Khi việc nhắm mục tiêu dựa trên nhóm không đủ hiệu quả, các trình quét đã dùng phương pháp brute-force để quét các dải SteamID: 20 triệu ID cùng một lúc, thông qua các proxy công cộng giá rẻ. Valve không thấy có vấn đề gì với việc này.
CƠ CHẾ BOTNET — 300.000 bot, hàng triệu tin nhắn, không có hành động nào
300.000
bot cho
mỗi trang trại đang hoạt động
10.000–30.000
Số bot trên mỗi
người vận hành
Lần/ngày
Số tin nhắn lừa đảo
giống hệt nhau được gửi

Valve tuyên bố sở hữu “các thuật toán tiên tiến”. Làm thế nào mà một thuật toán tiên tiến lại không thể phát hiện ra 300.000 tài khoản đang gửi hàng triệu tin nhắn giống hệt nhau đến cùng một mục tiêu, cùng một lúc, từ cùng một dải proxy, mỗi ngày? Nó không phải là thất bại. Mà là sự phớt lờ. Tất cả những thiệt hại thực sự đối với cơ sở hạ tầng lừa đảo đều do các dự án độc lập như PhishDestroy gây ra — chứ không phải do tập đoàn trị giá hàng tỷ đô la với bộ phận an ninh cồng kềnh, vốn được cho là có nhiệm vụ bảo vệ trẻ em trên nền tảng của mình. Valve đã không bảo vệ trẻ em. Công ty này đã cung cấp cho những kẻ lừa đảo một “API” thuận tiện để tìm ra các em.

15. "Efficiency" Built on Children's Tears: The Business Model of Total Indifference

Valve loves to boast about its financial analytics: hundreds of millions of dollars in profit per a couple dozen store employees. In the eyes of the tech industry, Gabe Newell often appears as a genius of optimization. But let's take off the rose-tinted glasses and call things what they are: this "efficiency" was purchased at the price of an absolute, cynical refusal to ensure the security of their own users.

Unlike public companies (such as Roblox or Tencent), whose market capitalization instantly collapses at the slightest scandal around child safety or data breaches, private Valve is accountable to no one. They have no board of directors. They do not need to reassure institutional investors. They have built an ideal printing press where the absence of spending on Trust & Safety and anti-fraud departments converts directly into personal billions for management.

The price of this "hyper-optimization" is millions of hijacked accounts, personal correspondence of teenagers leaked to the internet, a thriving shadow market, and complete impunity for scammers. Valve is not merely "failing to notice" fraudsters. It is economically beneficial for them to do nothing about it.

16. Steam API: A Corporate Toolkit for Hackers

Let's dissect Valve's lie about their alleged inability to control theft. If they wanted to, any support employee could go to a shadow market, take a link to a listed Steam account, and look in their own server logs at exactly which API key and from which IP address is right now evaluating that profile's inventory to generate a dump on the forum.

Valve would see a network of proxies and hundreds of API keys. Most of them have likely been obtained from previously stolen accounts. What should the corporation do? Revoke the compromised keys. But Steam does not do this. Why? Possibly because they fear catching "legitimate" services in the net — roulettes, illegal case-opening casinos, or third-party marketplaces where pixels are exchanged for crypto without AML procedures. This entire ecosystem exists in a gray zone, generating massive traffic while not being taxed. And Valve is entirely fine with that.

Steam's Terms of Service explicitly prohibit any automation. A reasonable question then arises: why does the official Steam API contain functions that are ideal for the automated hijacking of accounts (which takes milliseconds) or the mass linking of mobile authenticators?

Why does Steam allow virtual (VoIP) numbers from SMS activation services to be mass-linked to accounts? The solution for filtering such numbers is trivial — standard HLR lookups used by any normal service. But Steam does not do this. Perhaps, in the pursuit of impressive "record online" figures they love to brag about, bot farms are advantageous to them?

When a user receives a VAC ban [15] for cheating, the ban hits all accounts tied to the same phone number. But when hundreds of accounts are hijacked from a specific pool of VoIP numbers — Valve does not ban those numbers. Any normal service (Telegram, Netflix, Apple, Google) blocks junk or compromised phone numbers. But for Valve, security is an empty word.

Five Legal Vectors for Valve Accountability
Vector 1: OFAC Sanctions Violations & Money Laundering

Direct transactions and wallet top-ups from sanctioned territories (Crimea, DNR, LNR) continuing since 2021. Use of sanctioned gateways (Tinkoff Bank) via shadow intermediaries and region-switching. ToS self-certification clauses are legally void — Valve collects full hardware telemetry and traffic routing, meaning they practice Willful Blindness as defined under OFAC doctrine.

Targets: DOJ NSD · OFAC · FATF
Vector 2: Complicity in Infostealer Distribution (CISA / IC3)

No immediate JWT/cookie session invalidation on anomalous geo-change. Steam's P2P infrastructure (chats, friend lists) used as botnet expansion engine. A $2 stolen log caused a corporate lockdown, $17M ransom, $100M+ total damage. Valve's silence is the enabling mechanism.

Targets: CISA · IC3/FBI
Vector 3: GDPR Violations — PII Disclosure of Minors

Taylor Wessing's improperly redacted GDPR DSAR response disclosed third-party PII including minors. Fines reach 4% of global revenue. Elite lawyers billing €1,500/hr leaking data in official responses proves the Data Protection Officer function is operationally nonexistent inside Valve.

Targets: EU DPAs (CNIL, BfDI, AP, DPC)
Vector 4: Corporate Fraud & Fictitious ToS (FTC / SEC)

Steam ToS prohibits all automation. The Steam API simultaneously processes millions of daily requests from LZT Market checkers validating stolen accounts. 79 employees for 500M users is mathematical proof security was never budgeted. Frozen inventory on banned bots (Shadow Confiscation) proves bans serve Valve's economy, not justice.

Targets: FTC (Section 5 UDAP) · SEC
Vector 5: Internal Corruption & Unregulated Virtual Currency

Support agents used system privileges to duplicate Dragon Lore/Dota couriers and fence them via Chinese exchanges. Sold trade-ban removals for crypto bribes. Steam Wallet and skin economy function as unregulated virtual currency serving criminal syndicates without KYC/AML. Forensic analysis links support staff crypto wallets to 100% AML-flagged addresses.

Targets: FinCEN · DOJ Criminal Division
The Washington Shield & The Moscow Bow: Valve's Legal Schizophrenia

For 99% of the planet, Valve has built an impenetrable legal fortress: "All disputes shall be maintained exclusively in King County, Washington, U.S.A." — the perfect shield against their own users.

But the final clause reads: "If you are a consumer who lives in Russia, you may also seek a remedy with local Russian state courts."

Out of 195 countries, Valve makes an exclusive legal carve-out for the Russian Federation — a state under the heaviest international sanctions in modern history.

Crimea, DNR, and LNR are, per the Russian constitution, serviced by "local Russian state courts." If a resident of these occupied, sanctioned territories sues Valve in such a court — does Valve comply?

If YES

Valve recognizes the annexation and commits a direct OFAC sanctions violation.

If NO

Valve violates its own ToS and defrauds users — breaking the Russian laws it so desperately appeases.

Checkmate, Taylor Wessing. You drafted a rule that makes you either liars or accomplices to international sanctions evasion. Pick your poison.

OFAC Sanctions Breach Docket — CRIMEA VIOLATION 20, COMPLIANCE ERROR, SOURCE 1 LEAKED
OFACSanctions breach categories documented by PhishDestroy in this investigation.

Valve created an ecosystem where violating the rules (automation, VPN use, farming, bot-running) is a basic condition of the platform's survival. They hand hackers a perfect toolkit (open API), turn a blind eye to virtual numbers, but carefully keep in the rules a strict prohibition of all of the above.

This is not mere negligence. This is deliberate blindness (Willful Blindness / Deliberate Ignorance), constructed as a perfect legal shield. When a regulator comes to Valve, lawyers like Taylor Wessing [9] will show the ToS: "Look, we prohibit everything!" And when a robbed teenager comes to them, they use that same ToS to legally deny them help and avoid spending time on an investigation.

18. The Symbiosis of Intelligence Services, Steam, and Hacker Markets

Let's return to LZT Market. We have already established that Steam does not care at all about this platform. But another aspect is interesting. Over the course of its existence, this shadow forum has survived at least three changes in management, which, by indirect (but very obvious) indicators, are connected with the redistribution of spheres of influence among certain echelons of power in the Russian Federation.

During periods of management change (for example, during the era of the administrator Thomas), radical purges took place on the forum. Fraud schemes targeting Russian residents were banned (Avito scam, anti-cinema), the leaking of intimate photos of minors with personal data was strictly suppressed, the sale of VKontakte accounts was completely removed, and currently the sale of Telegram accounts registered on Russian numbers is prohibited. The forum is clearly moderated to avoid touching Russian citizens in ways that are critical.

But the situation with Steam is different. The market still freely sells Steam accounts belonging to Russian citizens who were infected by stealers. The listing description directly states: origin — stealer, country — Russia, balance — in rubles. This means that a Russian user caught a virus that drained not only their Steam but also, very likely, their email accounts and work credentials. And the forum passes this through without issue.

The question arises: does Steam cooperate with the same structures that oversee this market? Or perhaps Valve could influence their "partners" in Russia to stop the double standards and ban the sale of stolen accounts belonging to Russian citizens? Because right now Steam and the shadow market are operating in perfect symbiosis, as if they copied each other's policy of double standards and hypocrisy.

19. The Anatomy of Scamming: From Fake Windows to $300,000 Net Profit via Google Ads

Over the past 5-8 years, PhishDestroy has dissected virtually every scam scheme in the Steam ecosystem. We have seen infostealers that substituted authentication windows on the fly, intercepted SMS messages, and wiped inventories clean. We have seen the mechanics of trade offer substitution (API Scam) that remained "unnoticed" by Valve for years. Unnoticed — or too profitable?

We conducted continuous analytics on the bots of the largest phishing networks. Here is an example: in 2024, we recorded a massive pour via Google Ads [29]. Fraudsters substituted the displayed URL in ads with the original Steam domains. The purchasing was so aggressive that it outbid official advertising, monopolizing the top search results.

By our calculations, in just a few days of continuous operation, the scammers' net income amounted to approximately $300,000. And that is accounting for the discount when selling stolen skins on shadow markets and the tiny, cosmetic bans that Steam occasionally handed out. Yes, these are peak figures driven by the economics of that period, but the fact remains: Steam is an enormous feeding trough.

And while phishing is almost exclusively interested in CS and Dota (rather than other games), Rocket League, Path of Exile, Rust, and PUBG should not be forgotten. But here, Valve's corporate extortion enters the picture: strict NDA (Non-Disclosure Agreement) conditions that all developers are required to sign. A developer is not permitted to publicly disclose security issues, data breaches, or vulnerabilities in Steam without Valve's written approval. Even if this directly threatens their players. Mouths are sealed by contract.

20. The BlockBlasters Case: A Month of Blindness and the Lie About a "Hacked Developer"

The BlockBlasters case is not about ignoring pixel theft — it is about concealing actual criminal offenses.

Recall the recent incident with the game BlockBlasters [5], which only received public attention thanks to the late streamer Raivo Plavnieks [6]. This was a targeted attack on influencers: fraudsters contacted streamers, bought advertising, and asked them to launch the game directly from Steam. The victims' logic was understandable and fatal: "It's the official Valve store — there can't be an outright stealer in there." How wrong they were.

Steam support began receiving reports with ironclad evidence as early as September 2nd. The tickets contained ChainAbuse [7] complaints about stolen cryptocurrency and direct evidence of the scammers' open Telegram API embedded directly in the game's code. What did Valve do? It waited. For a month. The stealer games were peacefully downloaded from the store.

And then the corporation rolled out an excuse that insults the intelligence of any security professional: "The developer's account was hacked." Let's call this fairy tale what it is — a brazen lie to cover their own negligence (or complicity).

To release a game, a developer is required to pass Steam Direct KYC [22]: pay $100, submit their real name, address, and banking and tax details. The perpetrator was not an anonymous hacker from the dark web — their legal information, including a W-8BEN tax form [8], was sitting in Valve's database.

The myth of a "hacked developer who for some reason stayed silent for 22 days" collapses against the architecture of Steamworks. When a legitimate developer loses access to the publisher console, they create a ticket about stolen credentials. Publication rights for updates and builds are frozen within hours.

Only two options remain. Either the "developer" was originally a co-conspirator of the fraudsters (meaning Valve's vaunted KYC is a fiction). Or Valve deliberately ignored, for an entire month, the desperate attempts by the developer and dozens of robbed victims to reach support, while malware stealing crypto was being distributed through their official store.

In both cases, Valve is acting not as a victim of circumstance, but as the primary accomplice in a digital robbery.

21. Destroying Evidence: How Valve Cleaned Up the Crime Scene

But the most disgusting part of the BlockBlasters case is the ending. Interference with a digital crime scene.

On the record: Valve did not delete the infected game. Our forensic analysis of the C2 infrastructure proves the opposite. The scammers themselves deleted the malicious builds from Steam's servers on September 21st — precisely when their Telegram botnets were publicly exposed and criminal charges were becoming a real possibility. They applied a scorched-earth tactic to cover their tracks.

Valve's statement about "security measures taken" is pure fiction and shameless PR. They deliberately waited for the criminals to erase the malware from their own servers, and only then leisurely removed the now-empty store page, claiming credit for themselves. This is not solving a problem. This is complicity and obstruction of justice.

Valve was not protecting users. It was cleaning up the crime scene so that federal agents with a court order for distributing infostealers through their own data centers would not show up at their offices.

22. The Illusion of Action: Restricting Limits to Save Server Costs

When Valve does introduce some restrictions (for example, cutting friend-request limits), naive users think it is out of security concern. Nonsense. This whole story about limits is not about fighting scams — it's about plain and simple savings on server capacity.

Let's recall what started the spam apocalypse. Before the famous trade offer substitution script appeared, the platform was being abused by primitive automation. Armies of bots with female avatars were sending phishing links by the thousands. This junk traffic created enormous demand for no-limit accounts. We were tracking shadow markets: due to this spam boom, the price of a stolen account without a spending limit shot up from 25 rubles to a stable 150. And this insane demand for stolen profiles persisted right up to 2024!

Do you think Steam cut the invite limit from 100 to 30 to protect you from phishing? Think again. Valve logs everything: every click, every invite, every cancelled request. The automated scammer farms were generating millions of empty transactions per day, polluting Steam's internal databases and overloading the infrastructure. And what is most telling — Valve did not crush these limits on freshly registered throwaway accounts, but on fully developed no-limit accounts (including those with a VAC ban, since they technically count as accounts that have crossed the spending threshold). Valve cut the limits solely to reduce the load on their own servers, not for your safety.

Restrictions at Valve only appear where they need to protect their own servers. Your money is none of their concern.

23. The Inner Workings: Why Scammer Supervisors Benefit from Bans

Since we have dissected scam teams from the inside, I will expose one dirty secret that ordinary traffers never even suspected.

In all scam teams (where rank-and-file workers are promised 90-95% of stolen inventory), the supervisors (team coordinators) had a financial incentive to get a trade ban or Red Tag placed on their bots. Therefore, they deliberately did not replace compromised bots. If an account received a ban, the supervisor's share shot up sharply: instead of a measly 5% from the skin sale, they received between 15% and 20% of Steam's price for the inventory (not the market price!), simply by selling banned accounts with valuable skins to the Asian market. Chinese buyers purchased them in bulk to play with expensive items and private cheats. This is why a huge number of accounts with trade bans also carry VAC bans. The scam industry was feeding the cheat industry, and Steam was happily collecting the online numbers.

24. Steam Workshop: A Perfect Testing Ground for API Scam

Steam's absolute disregard for security is well illustrated by the Workshop incident. At some point, literally 2-5 scammers completely flooded the Workshop with phishing ads. How? They used intercepted web sessions of real users.

This was not a hijacking in the classical sense. The attacker simply opened a parallel session on your account via the Steam API, scanned the inventory, waited for you to initiate a trade, instantly cancelled it, and substituted an identical offer (with the same avatar and friend nickname) from their own controlled bot. All of this happened within a legitimate user session through official Steam endpoints.

And what did Valve do when the Workshop was drowning in phishing? They did intervene, of course. They issued Red Tags and banned the compromised accounts... but did so only after the inventories of those victims had been completely wiped clean.

Excellent work, Steam. Thank you for "saving" the account when there was nothing left in it to save.

Ironically, the price of these tokens on the black market has collapsed. If previously a valid SSFN file could go for around $3, today on that very LZT Market (where the curator of Russian-language Steam support, Nikita, is registered) the price list looks like a mockery of Valve's security:

"Buying and processing Steam Tokens (JWT). Fast check with proprietary software. Prices:

$0.08
CS2 Prime
JWT token
This is the market price for a valid CS2 Prime session token on LZT Market. For eight cents, an attacker gets an active Steam session, access to the victim’s friend list, chat history, billing region, IP log, and the ability to send phishing to every contact.

CS2 Prime — $0.08 (no temporary or permanent bans)

OpenTM — $0.04 (open trading platform)"

Your account, your history, and your data are valued at 8 cents. That is all you need to know about the effectiveness of session protection in Steam.

The Illusion of "Technical Impossibility": The Fake Games Case

Support claims that returning stolen items is "technically impossible" or would "destroy the economy." The game spoofing incident proves otherwise.

The scheme was brazen: scammers uploaded dummy games to the Steam Store, creating items with names and icons copied one-to-one from expensive CS:GO and Dota 2 skins. During a trade, the victim saw a familiar Dragon Lore, completely unaware it belonged to a fake game. We remember this perfectly, as PhishDestroy was actively hunting and blocking these scammers at the time.

And what did Valve do when the very foundation of trust in the Community Market was threatened? A miracle occurred. The corporation, which for years had refused to help phishing victims, suddenly returned the real items to all affected users. The scammers were hit with such a carpet bombing that they howled on shadow forums for days: Valve issued hardware bans (HWID) and blanket-banned shared IPs so harshly that entire scam syndicates went deep into the red.

Moreover, Steam rolled out a massive security update in a matter of days. Suddenly, they found the resources to implement everything: trade holds, new verifications, developer deposits, massive red alerts stating "This game has never been played by you," and warnings about suspicious disparities in item values.

It turns out they can. They know perfectly well how to track transaction chains, roll back trades, and build a complex warning architecture. But they only do it when they feel a direct threat to their own business model and the credibility of their marketplace. If you are stripped naked by a standard stealer, you will simply receive a boilerplate reply that "Steam policy does not provide for item restoration."

79 Employees: An Architecture of Matches and Acorns

To fully grasp the "seriousness" of the platform's day-to-day security, consider the recent API bug that lived in production for two whole days. Anyone with a basic script could send a simple request and spam system notifications directly to absolutely any Steam ID, completely bypassing all privacy settings.

Two days of a gaping hole in the API allowing anyone to ping millions of users. Indeed, 79 employees for a multi-billion-dollar global platform is clearly enough. Why invest in a functional QA and security department when you can just write a Terms of Service agreement that blames the user for everything?

25. Infrastructure as a Service: Scam-as-a-Service (SaaS)

To give you a sense of the scale of commercialization spawned by Valve's inaction, look at a typical offer from a modern phishing team. These are no longer teenagers with broken scripts. This is a full-fledged SaaS business with fierce competition. While we were mercilessly blocking their domains and forcing them to lose money on infrastructure, they switched to providing free domains to their "workers" to maintain volume:

"Our project combines 3 in 1: Phishing (logs go to you), MaFile (5% commission), Substitution (API Scam — 80% to you). Only we offer: Auto-sale of logs on LZT, MaFile removal with a single code, Browser for substitution, Free domains and a multitude of fake templates."

Valve only fixes what becomes uncontrollable, or what affects geolocations they are afraid to disturb (USA, Japan, South Korea). Steam could see the spam, see the no-limit accounts, and sometimes even banned phishing domains (often when they were already dead). If the corporation saw a domain, it also saw the network of accounts distributing that domain. Given that the farms operated through cheap shared proxies (using the scheme of 1 server and 100 IPs per 1,000 accounts), blocking the entire botnet could have been done with a single SQL query. But Valve did not do it.

26. Geopolitical Hypocrisy: The Steam Economy Laundromat

Money laundering pipeline: Trade Hold (Bypass Sanctions) → Crypto Conversion (Laundering Step) → Windfalls (Clean Profit)
FlowStolen Steam skins used as anonymous currency: sanctions bypass → crypto conversion → clean profit.Valve takes 15% at each transfer step. No KYC. No AML. No enforcement.

Valve's tolerance for the gray CIS economy spawned yet another monster — the market for illegal balance top-ups and region-switching. When Valve officially closed direct top-ups for Russia, it simply turned a blind eye to the flourishing of shadow intermediaries. Much more convenient that way, right?

The "region-switching" service (to Turkey, Kazakhstan, or Argentina) was sold by the millions. On just one platform (like FunPay) [24], more than 500,000 transactions have been recorded from several large sellers. And there are hundreds more Telegram bots and forums. This top-up industry has become deeply intertwined with the laundering of money from phishing and crypto scams (the buying up of seed phrases).

What is Valve's logic? Do they genuinely believe in the mass migration of millions of teenagers from a sanctioned country? Or do Russian funds, passed through a Kazakhstani proxy and a stolen inventory, simply "smell different"? Valve does not care about sanctions and compliance. The main thing is that a 30% commission from every transaction reliably drips into their bank accounts, while lawyers churn out boilerplate letters about the "impossibility of technical intervention."

27. Corporate Benefit and Violation of Their Own ToS

Steam is an ecosystem that thrives on total violation of its own rules, and Valve knows this perfectly well. The Terms of Service (ToS) clearly state: extracting any commercial benefit on the platform is strictly prohibited.

Now let's look at reality. Selling stolen accounts, skin trading, bot farms for farming collectible cards, Level Up services (profile leveling), selling keys, and of course, balance top-up services for sanctioned regions. All of this is direct commercial benefit. And this is surreal: a platform that formally prohibits commerce is home to industries with multi-million turnovers. Valve (or their reliably NDA-protected Russian-language outsource) has abstracted itself from its own rules, applying them exclusively as a tool to punish those who fall out of favor or to protect infrastructure.

28. The Support Syndicate: Why Valve Cancelled Item Returns

When Valve justifies its refusal to return stolen items to users (hiding behind fighting inflation or "duping"), they are blatantly lying. The reason Valve permanently freezes assets on banned bots, pocketing them into their bottomless account, is not protection of the economy. It is an attempt to recoup operational losses inflicted on them by their own employees.

Historical fact: support agents (including cheap outsourced workers often mistaken for volunteers) were directly integrated into the shadow economy of Steam. Using their system privileges, they turned technical support into a corrupt cartel.

Industrial Duplication of High-Tier Items: Support employees were mass-generating copies of the most expensive items in the game (Dragon Lore in CS:GO, rare Legacy couriers in Dota 2) under the pretext of "returning stolen inventory to a user." This "returned" inventory was then fenced on Chinese exchanges for real money.

Selling Unbans: Support was selling the removal of Red Tags (KTs) and trade bans from the profiles of major scammers. For bribes (in crypto or skins), fraudsters were given the green light to cash out assets worth tens of thousands of dollars.

Upon learning the scale of the corruption, Valve's management was furious. They permanently abolished the policy of returning stolen items, cutting support's manual access to item generation. But those punished were not the corrupt employees — it was the users. Children and gamers around the world are paying with their money for Valve's failure to control its own staff.

The "Little Tyrant" Syndrome and the Fall of the Volunteer Police

In addition to official support, Steam had a second branch of power — a volunteer trade police integrated with databases like SteamRep [12]. They held enormous informal influence over the platform's economy and the fates of traders. And they turned out to be no better than the outsourced staff.

The volunteers devolved into a closed, corrupt caste of "faceless shadow authorities." They suffered from a classic "little tyrant" syndrome: they buried traders they disliked, banned users who discussed vulnerabilities, and issued "free passes" to friends.

When logs surfaced proving that SteamRep [12] admins were taking bribes to remove "scammer" labels and were running cover for massive bot networks laundering stolen skins, Valve's trust collapsed completely. By 2022, Valve had expelled the last volunteer moderators, replacing them with rigidly scripted outsourced workers.

29. The Price of "Efficiency"

Valve boasts the highest profit per employee in the industry. But what is the cost of this profit?

This efficiency is built on denying help. On threatening phishing victims. On closing tickets. On suppressing the truth that Steam is not so much a gaming platform as a global crypto laundromat and distribution hub for infostealers.

While Valve's management considers itself geniuses of business optimization, fighting in court for the right to sell adult visual novels, their platform is daily chewing through the data, money, and safety of real users. The era of duping has long been dead, but Valve continues to use it as an excuse to legally appropriate the property of robbed users. There is no justice in Steam. There are only scripts, outsourced workers, and an endless thirst for profit.

30. Hypocrisy at Every Level: The Corporate Ethics of Valve and Taylor Wessing

If it seems to you that I am exaggerating by mentioning Taylor Wessing (Valve's lawyers) in the context of their internal harassment lawsuits — believe me, it is not a joke. The court case was lost, but the point is not the verdict — it is Taylor Wessing's strategy. They demonstrated not professionalism, but a dirty game of attrition and deliberate delay. Google how many years the case dragged on from the time of the incident at the elite ski resort.

But when it comes to Valve itself, even more questions arise about their vaunted ethics. They have a corporate Welcome Book where they call themselves a "family." All warm and cozy. But when this "family" is rocked by scandal, Valve acts with maximum ruthlessness. Recall the harassment of a transgender employee in support, or the story of Jess Cliffe [13] (the co-creator of Counter-Strike, who had worked at Valve almost since its founding). The man was thrown out of the company without a court verdict, on the basis of accusations alone. Valve, which generates millions by covering up scams, suddenly became afraid for its reputation? The logic is absurd: a company allows millions of dollars to be stolen from its users but instantly distances itself from the person who built this business for decades, just to appear "clean."

As for the lawyers at Taylor Wessing — let's be honest. You pride yourselves on your "centuries-long history," but on your Instagram, you are running a race in support of Pride. Make up your mind: do you honor the history of your Nazi founders who sent gay people to concentration camps, or are you a modern progressive company? This is corporate scamming. You want to appear as ancient aristocracy while having effectively merged into the ecstasy of contemporary hypocrisy. And yes, you have taken on the defense of Russian oligarchs in cases where your reputation was openly screaming: "You are not hired where people are innocent."

31. The Roadmap of Coming Leaks: What Valve Should Prepare For

This is not the first and not the last piece from PhishDestroy about Valve. I will not play cat and mouse with their lawyers — their time, judging by their rates, costs $3,000-$5,000 for reading a couple of paragraphs. Don't waste the money; hire decent support staff instead of a Russian outsource that reads from scripts.

Here is what comes next. My roadmap for upcoming investigations:

Evidence Base on GDPR Impotence: I will publish the originals of the legal boilerplate letters and improperly redacted documents, proving that Valve systematically violates regulations and discloses the confidential data of underage users. I will show the entire chain in which I was already the fifth person to have gained access to someone else's personal data (including individuals with Russian passports). This is direct proof of their lies about storage conditions and mythical "encryption."

NDA Violation and the Dirty Underbelly of Steamworks: We have data from at least two developers whose non-disclosure agreements (NDAs) we will be happy to violate (we never signed them). We will expose the open chaos in update moderation and cases involving locker content that Valve prohibits from being made public under threat of game removal.

Crypto Failures and Money Laundering: How Valve's "Geniuses" Lose Their Millions: Since Valve loves to brag about the billion-dollar profits of their employees, we, as PhishDestroy, will venture into crypto territory. We will conduct a forensic financial analysis of the wallets belonging to elite support staff (early Bitcoin investors) and show how these "professionals," bringing Valve billions on the tears of robbed children, themselves invested in scams and had their addresses flagged with 100% AML risk scores.

The Strange Love of Russia and Who Is "Nikita": We will examine the phenomenon of Valve's tolerance for the CIS region. How does a person with no formal employment become a support supervisor simply because they once created a fan community for Half-Life? We will expose the loopholes and sanctions bypass mechanisms for developers from a terrorist state, as well as direct balance top-ups from the DNR/LNR and Crimea that have been functioning since 2021 and continue to this day.

32. Conclusion

I have no desire to dedicate my life to writing texts about Steam. It is run by an audience of children, scammers, and Putin cultists on the platform (in the form of the Russian outsource). Volunteers are mired in corruption up to their ears. If Gabe Newell considers himself a genius of the gaming industry, then perhaps it is my destiny to be the bastard who writes the truth into history:

Gabe is an excessively petty and greedy monopolist who legalized the theft of money from children. And the promised private jets and vacations from their employee handbook are just colorful pictures designed to keep workers in corporate bondage.

All of this is written for history. For the Web Archive. And for those regulators who will eventually come to dismantle this empire of impunity.

33. Anatomy of the ToS: Corporate Schizophrenia and Legal Cynicism

Let's dissect Steam's Terms of Service (ToS). We will cover at least 25% of this document to show that this is not a legal contract — it is a lie constructed to allow the platform to steal from children while avoiding accountability.

Here is a quote from their rules: "You may not use any scripts, bots, macros or other automated systems ('Automation') to interact with Content and Services on Steam..."

We will analyze this clause in detail in the next part. Spoiler: Steam itself created an API that is used exclusively for automating theft, bypassing limits, and managing bot farms. The platform wrote a rule that it simultaneously allows to be violated on an industrial scale.

And here is another gem of corporate cynicism: "You acknowledge that Valve is not required to provide you with notice prior to terminating your Subscription and/or Account."

This is a lie. Under normal legislation, that is not how it works. But the platform shields itself from everything. Valve's position sounds like this: "We steal from children, we violate sanctions, we allow infostealers to infect your PCs, but if anything — you are at fault, and we will take your account without explanation."

They love to say that "the community decides everything." But for some reason, when it comes to legal accountability, the community suddenly becomes a powerless piece of meat.

33a. Ảo giác trong phòng xử án — Cách Valve lợi dụng sự thiếu hiểu biết về công nghệ của giới tư pháp

Mỗi khi các cơ quan quản lý hoặc tổng chưởng lý cố gắng buộc Valve chịu trách nhiệm về các hộp quà ngẫu nhiên (loot boxes) và hoạt động cờ bạc không được kiểm soát, đội ngũ luật sư hàng đầu của tập đoàn này lại áp dụng cùng một chiêu thức. Họ bước vào phòng xử án với một chồng thẻ bóng chày hoặc một bộ bài Magic: The Gathering và tuyên bố: “Thưa Quý tòa, các vật phẩm ảo của chúng tôi cũng giống như vậy. Đây chỉ là hoạt động sưu tập vô hại, được chuyển sang thế giới kỹ thuật số mà thôi.”

Lời bào chữa này thành công chỉ vì một lý do duy nhất: các luật sư của Valve đã khéo léo lợi dụng sự thiếu hiểu biết về công nghệ của một hệ thống tư pháp đang già cỗi. Nhưng lời dối trá của tập đoàn này sụp đổ ngay lập tức khi một công tố viên có năng lực chuyển hướng cuộc thảo luận từ “đồ chơi” sang hậu cần tài chính và cơ sở hạ tầng tội phạm.

Bài kiểm tra của công tố viên — 3 câu hỏi phá vỡ luận điểm bào chữa của Valve

Nếu skin “chỉ là những tấm thẻ bóng chày”, hãy đặt ba câu hỏi dưới lời tuyên thệ cho các luật sư của Valve:

Câu hỏi 1 — Tiền tệ hình sự & Thu thập thông tin cá nhân

Bạn có thể vào một diễn đàn darknet và mua số An sinh Xã hội của Mỹ bị đánh cắp, phần mềm đánh cắp thông tin hoặc thông tin đăng nhập VPN của doanh nghiệp để đổi lấy một Charizard hiếm không? Không. Không hacker nào chấp nhận thẻ giấy. Nhưng họ chấp nhận skin CS2 hàng ngày. Kho hàng Steam hoạt động như tiền tệ kỹ thuật số tuyệt đối trên các thị trường tội phạm — dùng để mua thông tin cá nhân thực tế, phần mềm độc hại và quyền truy cập vào cơ sở hạ tầng.

Câu hỏi 2 — Hậu cần rửa tiền & Tránh né các lệnh trừng phạt (AML/OFAC)

Hãy thử chuyển 1.000.000 USD dưới dạng thẻ bóng chày cho một băng đảng ma túy hoặc một thực thể bị trừng phạt ở vùng lãnh thổ bị chiếm đóng. Bạn sẽ cần người vận chuyển, hải quan, chuyên gia thẩm định và mất hàng tuần trời. Trong hệ sinh thái của Valve, cùng một triệu đô la dưới dạng skin đó có thể đi khắp hành tinh chỉ trong vài giây — vượt qua mọi rào cản ngân hàng, kiểm soát thuế và hệ thống giám sát giao dịch hiện có.

Câu hỏi 3 — Sổ lệnh toàn cầu (API) & Cơ sở hạ tầng trao đổi tài chính

Các vật phẩm sưu tập bằng bìa cứng không có thị trường mở (API) kết nối với hàng trăm nghìn bot giao dịch. Chúng không có sổ lệnh toàn cầu (global order book) nơi giá cả được xác định bằng thuật toán đến từng xu. Valve không xây dựng một cuốn album dán nhãn — Valve đã xây dựng một sàn giao dịch tài chính có tính thanh khoản cao, kết nối với các cổng tiền điện tử, mà không yêu cầu xác minh danh tính KYC.

Phán quyết pháp lý: Điều mà Valve gọi là “sưu tập”, từ góc độ luật hình sự, là một công cụ gần như hoàn hảo để rửa tiền, trốn thuế và che giấu giao dịch. Ngay khi tòa án ngừng xem xét các skin dao và bắt đầu xem xét tốc độ chuyển khoản, tính thanh khoản và cơ sở hạ tầngAPI , câu chuyện về thẻ bóng chày sẽ trở thành hành vi vi phạm Đạo luật Bí mật Ngân hàng và hành vi tiếp tay cho Hoạt động Dịch vụ Tiền tệ Không có Giấy phép.

34. Sanctions, Terrorism, and Double Standards

A funny question for this corporate hypocrite. The rules state: "If you are a consumer residing in Russia, you can also seek legal protection in local Russian state courts."

Does the court of annexed Crimea count as a Russian court? Or shall we wait for Roskomnadzor — with which Steam integrates so cozily — to answer?

And here is a clause that provokes a roar of laughter: "You agree to comply with all applicable import/export laws and regulations. You agree not to export Content... to any countries that support terrorists... You represent that you are not in such a prohibited country."

So when Valve accepts money directly from accounts registered in zones subject to international sanctions (and we have gigabytes of screenshots and direct proof of transactions from Crimea, the DNR, and LNR dating back to 2021) — it is not Valve violating sanctions. It is the user's fault! The platform quietly edited its ToS over the last six months, shifting all responsibility onto users.

Valve, were you compelled to remove mentions of Russia's allies (Cuba, Iran, Syria) and prohibited from speaking ill of them, or did you calculate the scale and the sum that came directly from those places? If a terrorist state is coercing you into any actions — tell someone, do not be afraid. There is no need to violate current US law because of threats that they will pirate your content; it is not worth that risk. They are terrorists, and you are a US company. If you are being persecuted or blackmailed, contact the FBI Seattle Field Office at +1 (206) 622-0460 [16] or IC3 [17]. I am also confident that specialists from CISA [18] could help you: given the scale and reach of your sphere of influence, it is significant even by US standards.

Since you are removing direct sanctions rules and changing the text — this is a very alarming signal. I am not joking: if you do not trust the agencies named above, then here you will certainly receive help at the highest level — at DOJ NSD [19]. We, for our part, will conduct additional analysis and free consultations with certain specialists, and may also be compelled to report this where appropriate (or nowhere). But this is no joke at all — it is serious.

You removed explicitly enumerated countries from the rules and shifted responsibility onto users. At the same time, you run analytics: there is a tracking pixel on the registration page, and you see the real number of clicks through to the agreement. Nobody reads it, because you have calculatingly disguised it as a question confirming that the user is over 13 years old (the link to the agreement is embedded there as well). Modern society — children and teenagers — has ADHD, and this is a scientifically proven fact: check the data. They do not finish reading text. I, for example, saw the clause about being over 13 and that was it — I looked no further. This is direct manipulation on your part, as is the rewriting of the agreement regarding countries that have consistently appeared on sanctions lists.

Your revision directly indicates that your company's attitude toward those countries (or money from them) has changed. This is a very strange change. Most likely, there is already a problem, or you are complying with Russian courts, and this is one of their non-public demands — such as the banning of certain users, etc., which could undermine belief in the rightness of their terrorist acts on the territory of another country. Or are you simply prostrating yourselves before the Russian government, fulfilling their direct requests to ban undesirable users? I will show you prior versions of your ToS. You may change them as you wish, but these pieces of paper are worthless when it comes to the direct violation of US laws and the sponsoring of terrorist economies.

35. Blackmail and the Scorched-Earth Strategy

Fair warning in advance: any attempts by Valve or their attack dogs from Taylor Wessing [9] to make contact will be treated as pressure and obstruction of the investigation.

Do not try to send us an NDA. PhishDestroy is not registered on your garbage heap. We did not check the box in your clever agreement (which you treat exclusively as confirmation that a child is over 13 years old, so that you can legally rob them).

If your lawyers try to accuse us of "extorting billions of rubles" or "defaming the holy reputation in the interests of a North Korean competitor, Steam 2.0" — good luck. All of our investigations, evidence, and proof are duplicated to independent nodes (including servers at an American university) and the Web Archive. This is not a conflict. This is a statement of facts.

36. The Scam Factory: Carding, Fake Documentation, and Data Theft

You think scamming on Steam is only about stolen passwords? You have no idea of the real scale.

Fake Documentation (Social Engineering): When an account is stolen, support demands the first CD key from 10 years ago. The child doesn't have it. But the scammer from Russian outsource does. Fraudsters commission the fabrication of fake receipts and keys on shadow forums. We have collected over 200+ proven instances of successful fakes that Valve's support staff happily "swallowed," handing the account over to criminals.

Data Theft: More than half a million accounts (including EU citizens) have passed through the shadow market LZT. Steam concealed the fact that their PCs had been infected with stealers. The platform de facto leaked to hackers personal data, correspondence, IP addresses, and home network information.

Industrial Carding: If Valve's lawyers understood how carding works on their platform, their hair would turn white. Issuing a Red Tag for carding while leaving items purchased with stolen credit cards on the account is a remarkable money laundering practice. Do you know who was actually competing with the Prince of Saudi Arabia for the highest Compendium level in Dota 2? We will tell you about that too.

36a. Cỗ máy cờ bạc: Cách Valve xây dựng sòng bạc không được quản lý lớn nhất thế giới dành cho trẻ em

Cờ bạc bằng skin không phải là một tác dụng phụ của Steam. Đó là hệ quả có thể dự đoán được và mang lại lợi nhuận từ kiến trúc có chủ ý của Valve: giao dịch mở API, không có KYC, các vật phẩm ảo có giá trị ổn định trên thị trường thứ cấp, và sự mù quáng hoàn toàn về mặt quy định. Kết quả: một ngành công nghiệp trị giá hơn 1 tỷ USD mỗi năm, nơi các skin CS2 của trẻ em đóng vai trò như chip sòng bạc — không có xác minh độ tuổi, không có sự đồng ý của phụ huynh và Valve chưa bao giờ nộp một báo cáo nghi ngờ rửa tiền (SAR) nào.

Hơn 1 tỷ USD
Khối lượng cá cược
skin hàng năm ở mức đỉnh
15%
Phí hoa hồng của Valve trên
mỗi skin được nạp vào
0
Steam yêu cầu xác minh
độ tuổi
CƠ CHẾ — cách skin của trẻ em trở thành chip sòng bạc
1
Trẻ em nhận
được skin CS2
(nhận được trong trò chơi)
2
Skin có giá trị thực
trên thị trường
(API của Steam)
3
Trang
web cờ bạc chấp nhận skin
làm tiền gửi
4
Trẻ em thua cuộc.
Trang web giữ
lại skin.
5
Valve thu
được 15% từ mỗi
lần chuyển nhượng skin

Không có bước nào trong chuỗi này yêu cầu Valve phải hành động. Hệ thống Giao dịch (API) của Steam là cơ sở hạ tầng hỗ trợ. Nền kinh tế skin là lớp tiền tệ. Valve đã thiết kế cả hai, kiếm tiền từ cả hai, và không nộp báo cáo hoạt động đáng ngờ (SAR), không áp dụng cơ chế xác minh độ tuổi, cũng không gửi cảnh báo nào cho phụ huynh.

PhishDestroy Trường hợp — “Lệnh cấm” cờ bạc của Steam trong thực tế

Chúng ta biết cuộc chiến trông như thế nào. Chúng ta chống lại lừa đảo. Nếu chúng ta chống lại nó theo cách Valve “chống lại” cờ bạc, chúng ta đơn giản là sẽ không chiến đấu gì cả. Đây là cách nó thực sự hoạt động.

Hãy lấy ví dụ csgoempire.com/roulette — một nền tảng mà Valve đã tuyên bố một cách rầm rộ là sẽ hạn chế. Để đăng nhập Steam OpenID hoạt động, một tên miền phải được phép thông qua API của họ. Valve có thể chặn tên miền chính. Vậy nhà điều hành trang web cờ bạc sẽ làm gì? Họ đăng ký một tên miền đăng nhập song song. Điểm cuối xác thực Steam thực tế hiện đang được CSGOEmpire sử dụng được định tuyến qua:

steamcommunity.com /openid/loginform/?goto=...openid .return_to=https://csgoempirelogin2.com /api/v2/login...
Tên miền
csgoempirelogin2.com
Đăng ký
20/07/2020
Hết hạn
20/07/2028
Máy chủ tên
Cloudflare

Tên miền này đã hoạt động được hơn 6 năm. Chỉ cần nhìn vào tên của nó — csgoempirelogin2 .com — là bạn đã hiểu tất cả: nó được đăng ký đặc biệt để vượt qua một hạn chế mà Valve áp đặt (hoặc giả vờ áp đặt) lên tên miền chính. Chữ số “2” chính là cách vượt qua hạn chế đó. Nó được mua để lách luật cấm. Giống như các luật sư của Valve — không thực thi, mà chỉ diễn kịch việc thực thi.

Chỉ riêng trong năm 2026, tên miền này đã bị báo cáo lên hệ thống báo cáo của PhishDestroy hơn 20 lần. Điều đó có nghĩa là người dùng đã báo cáo nó — đến PhishDestroy, và gần như chắc chắn là đến bộ phận hỗ trợ của Steam. Steam biết điều đó. Steam không quan tâm. Cơ sở hạ tầng cờ bạc vẫn tiếp tục hoạt động. Valve cấm các bot (lợi nhuận chảy vào túi họ), đưa ra tuyên bố công khai về việc “bảo vệ cộng đồng”, rồi lại không làm gì với tên miền lách luật đã hoạt động từ năm 2020.

Mô hình tương tự cũng áp dụng cho các nền tảng khác mà Valve đã “đóng cửa” một cách rầm rộ. PhishDestroy đã cấm CSGOFast và những trang khác mà chúng tôi có bằng chứng. Các nền tảng khác có thể chưa bị xử lý. Nhưng cơ sở hạ tầng — các tên miền bỏ qua đăng nhập, các khóa “API”, các mạng bot — vẫn tiếp tục hoạt động, bởi vì mô hình kinh doanh của Steam yêu cầu các skin phải được giao dịch, chứ không phải nằm im trong kho hàng đóng băng mà không tạo ra hoa hồng nào.

Lệnh cấm bot năm 2023: Không phải là hình phạt. Mà là cơ chế sinh lợi.

Năm 2023, Valve đã cấm hàng chục nghìn tài khoản bot do các trang web cờ bạc điều hành — CSGOFast, CSGORoll, Stake.com (dành cho skin) và các trang khác. Báo chí về game đã ca ngợi việc này như là Valve đang “đàn áp” cờ bạc. Cách hiểu này là sai về mặt thực tế.

LỆNH CẤM BOT NĂM 2023 — ai thực sự phải trả giá
NHỮNG GÌ CÁC SÒNG BẠC MẤT
  • Tài khoản bot — những tài khoản mới được tạo ra chỉ trong vài ngày
  • Sự gián đoạn tạm thời đối với các luồng nạp tiền tự động
  • Thiệt hại tài chính ròng: gần như bằng không. Họ đã chuyển sang các phương thức mới.
AI THỰC SỰ PHẢI CHỊU THIỆT HẠI
  • Những trẻ em có skin nằm trong các tài khoản bot tại thời điểm lệnh cấm được áp dụng
  • Hàng tồn kho bị Valve tịch thu — không được trả lại cho chủ sở hữu ban đầu
  • Valve đã giữ lại mọi skin trong mọi bot bị cấm: Thu nhập từ việc phá hủy
  • Đứa trẻ đã gửi AWP | Dragon Lore của mình làm tiền cược: không nhận lại được gì
Tính toán: Hàng chục nghìn tài khoản bot. Mỗi tài khoản sở hữu từ hàng trăm đến hàng nghìn skin. Tổng giá trị kho đồ: hàng chục triệu đô la. Valve đã cấm các bot và giữ lại mọi skin. Các trang web cá cược không trả gì cả. Các nhà điều hành sòng bạc không trả gì cả. Những đứa trẻ đã nạp tiền là những người phải chịu mọi chi phí. Và Valve đã thu khoản hoa hồng tiêu chuẩn 15% trên mỗi skin trong suốt quá trình này trước khi tịch thu số dư cuối cùng.
VỊ TRÍ QUY ĐỊNH: FTC / Ủy ban Cờ bạc Vương quốc Anh / Ủy ban Châu Âu
Steam đã hoạt động trong nhiều năm như một cơ sở hạ tầng thanh toán cho một hệ sinh thái cờ bạc không được quản lý nhắm vào trẻ vị thành niên — thu hoa hồng ở mọi bước và tịch thu số dư khi “thực thi”. Theo luật pháp Hoa Kỳ (UIGEA + Mục 5 của FTC), việc tạo điều kiện thuận lợi cho các giao dịch cờ bạc mà không xác minh tuổi và không nộp báo cáo hoạt động đáng ngờ (SAR) có thể dẫn đến trách nhiệm hình sự. Ủy ban Cờ bạc Vương quốc Anh có thẩm quyền đối với bất kỳ sản phẩm cờ bạc nào mà cư dân Vương quốc Anh có thể tiếp cận. Đạo luật Dịch vụ Kỹ thuật số của EU yêu cầu các nền tảng phải ngăn chặn nội dung bất hợp pháp — bao gồm quảng cáo cờ bạc bất hợp pháp và việc trẻ vị thành niên tiếp cận cờ bạc — tiếp cận trẻ vị thành niên.

37. Epilogue: A Training Ground for Cybercrime

Since, according to Valve's perverse logic, virtual items "have no real value," the theft of $10,000 worth of skins is not legally theft. This is a perfect gray zone.

But Steam is not merely ignoring theft. Steam has raised an entire generation of cybercriminals. Today's creators of infostealers and crypto scammers started out stealing inventories in CS:GO. Gabe Newell's platform became the primary incubator for global cybercrime, teaching underage hackers the main rule: you can steal on the internet with impunity, as long as you pay the corporation's commission.

Everyone will answer for their actions. Even if they hide behind a Terms of Service they wrote themselves. Expect part two.

38. Sanctions, Censorship, and Steam's Stockholm Syndrome

Evidence: Sanctions Bypass Openly Hosted on Steam Servers

These are not dark web links. These are discussions and official Guides hosted on Valve's own servers, indexed by Google and Bing, publicly accessible to non-logged-in users. Valve moderates this platform. Every post is reviewed. None of these were removed.

Schrödinger's VPN: Valve's Selective Enforcement

Steam ToS explicitly bans VPN use. At the same time, Steam's own servers host thousands of guides on how to change region via VPN. Under FTC Section 5 (UDAP) this is a deceptive practice. Under Estoppel doctrine, Valve has waived the right to enforce this clause after systematically ignoring it for years — meaning they cannot selectively apply it to deny help to theft victims while allowing bot networks to run freely. Under OFAC Willful Blindness doctrine, hosting and indexing this content is not passive — it is facilitation.

Sanctions bypass pipeline: MOCKBA → proxy chain → TURKEY → STEAM SERVER
InfrastructureDocumented sanctioned payments routed MOCKBA → TURKEY → STEAM SERVER.Valve hosts the tutorials for this on their own servers. Nothing was removed.

Steam's hypocrisy reaches its apex when the subject turns to geopolitics. You may laugh at the fact that a corporate monster generating billions has simply gotten confused in its own algorithms. But let's look at the facts.

In 2022, as the sanctions noose began to tighten, developers from Russia rushed en masse to bypass the blocks. And where did they find the most detailed guides on evading international OFAC sanctions? Right inside Steam itself. In the official Community, there are step-by-step instructions on how to use a VPN (which is formally prohibited by the ToS) to change regions and withdraw money to sanctioned banks (such as Tinkoff Bank) [25].

Here is a quote from an official (or, at least, Valve-moderated) guide that perfectly describes their position: "We kindly ask you to maintain professionalism and refrain from commenting on political matters... Such statements will be removed, and the most active violators will lose the ability to leave comments..."

Translate from corporate speak into plain language: Valve prohibits calling the war a war. Valve prohibits calling the aggressor country a terrorist. Aggressive moderation (hello, Russian-language outsource) scrubs any criticism, protecting an audience that is killing people in a neighboring country from "political disputes." This is not mere negligence. This is complicity in censorship, driven by fear of losing revenue from the CIS market.

I formally invite Valve's management and their vaunted lawyers to come to Mariupol or Melitopol, to see from what exactly "political disputes" they are so carefully shielding their Russian-language community.

39. Sanctions Bypass as a Platform Service

Evidence: Sanctions Bypass Openly Hosted on Steam Servers

These are not dark web links. These are discussions and official Guides hosted on Valve's own servers, indexed by Google and Bing, publicly accessible to non-logged-in users. Valve moderates this platform. Every post is reviewed. None of these were removed.

Schrödinger's VPN: Valve's Selective Enforcement

Steam ToS explicitly bans VPN use. At the same time, Steam's own servers host thousands of guides on how to change region via VPN. Under FTC Section 5 (UDAP) this is a deceptive practice. Under Estoppel doctrine, Valve has waived the right to enforce this clause after systematically ignoring it for years — meaning they cannot selectively apply it to deny help to theft victims while allowing bot networks to run freely. Under OFAC Willful Blindness doctrine, hosting and indexing this content is not passive — it is facilitation.

Sanctions bypass pipeline: MOCKBA → proxy chain → TURKEY → STEAM SERVER
InfrastructureDocumented sanctioned payments routed MOCKBA → TURKEY → STEAM SERVER.Valve hosts the tutorials for this on their own servers. Nothing was removed.

Steam states that users are obligated to comply with US export laws. But at the same time, the platform serves as the primary hub for publishing manuals on how to bypass them. The guides have been up for years. Switching region to Kazakhstan or Turkey to bypass blocks has become not just a widespread phenomenon, but an industry standard that Valve silently approves.

Why? Because Steam's policy goes like this: "The user ticked the box saying they are not a terrorist and are not under sanctions, so there are no claims against us."

But we will go further. If anyone has raw analytical user databases from Steam, we are ready to put them to work. We will find lists of accounts that have bypassed blocks to purchase games from publishers who officially withdrew from Russia (such as the creators of STALKER 2 [30] or GTA [30]). We will pass this data directly to those publishers, along with the question: "Are you aware that Steam is sabotaging your exit from the market and openly providing users with loopholes to purchase your games in rubles through a chain of intermediaries?"

We already have contacts with insiders bound by NDA. We know of a case where Valve unilaterally terminated cooperation with a developer and simply appropriated their money, covering it with a non-disclosure agreement. But we did not sign any NDA. We will tell everything.

40. Where Are the US Regulators Looking?

The main question: does Valve understand what OFAC [20] (the US Office of Foreign Assets Control) is?

When a platform allows mass sanctions evasion via VPN (from minor purchases to fund withdrawals by developers); when it allows money laundering through shadow skin markets while turning a blind eye; when the platform's moderation integrates Roskomnadzor [23] restrictions and removes "undesirable" posts — this is no longer the jurisdiction of a terms of service agreement. This is the territory of direct violation of US sovereignty and laws.

Expect the continuation. PhishDestroy will not stop until this architecture of lies collapses. All proof and links are saved. And no Taylor Wessing [9] will intimidate us.

For Valve, geopolitical differences are not just a matter of regional pricing (where Valve decides who is wealthier and who is "Russia"). It is also about laws, rules, and control. Here is a perfect example — the VPN geolocation is visible at the top. So the New York prosecutor simply doesn't use a VPN. But I think she could have never imagined that Valve is such a hypocritical rat, operating completely different rules and controls depending on where you are accessing the platform from.

Valve's Geopolitical Hypocrisy and VPN selective compliance
Double StandardsSchrödinger's VPN: Valve serves completely different content and rules depending on your geolocating proxy.The New York prosecutor simply didn't use a VPN — but she could have never imagined how deep Valve's hypocrisy runs.

Given all these factors, our recommendation is simple: do not yield to Steam's legal framing. If a user is an actual terrorist, they are under no obligation to testify against themselves. It is Steam's absolute legal duty to verify the origin of these funds, rather than granting the user the absurd privilege to self-certify whether they are a terrorist or not. This logic applies directly to Valve's territorial operations. If Valve has suddenly forgotten how the internet works — and its direct bans on VPNs — let's follow their logic: a terrorist from Crimea, Cuba, or Syria goes online to launder money. This user does not know English and has zero intention of reading the convoluted legal nonsense in the user agreement. But they are definitely over 13 years old (in fact, they might have already killed 13 people). Does the platform seriously think it can shift the legal liability onto the terrorist to decide their own status? By shifting this responsibility, Valve is making a direct legal statement: they automatically recognize everyone as a "non-terrorist" on their end. Meanwhile, the actual terrorist, who completely ignores the boilerplate text disguised as a simple age check, simply launders their money using a sanctions-bypass guide hosted directly on Steam's own community platform. Outstanding compliance, isn't it?

Are you out of your minds? You fed the personal data of minors to a person with a grievance, essentially saying, "Here is the cause of your problems, fetch." If that individual ever acts on that data, the blood and legal responsibility rest entirely on the hands of Valve and Taylor Wessing.

The IPFS Dead Man's Switch

We have vastly more information than what is published here. If Steam, Taylor Wessing, or any affiliated entity attempts to take aggressive action against our project, we will not waste time in court. We will execute a full, raw data dump on the InterPlanetary File System (IPFS).

Yes, releasing unredacted data will have consequences. Yes, it will mean the absolute death of the phishdestroy.io domain and its massive traffic. Let us save your lawyers some time: We do not care. The domain was created as a joke to mock the Steam scammers who claimed we "didn't even have a website." We do not chase reputation, we are not trying to be corporate heroes, and we are not afraid to lose a URL.

If the domain dies, you will find the answers at: steamdestroy.eth

Who We Are

PhishDestroy is a non-commercial anti-fraud operation. There are four of us — certified cybersecurity professionals operating across multiple countries. One of our original five members is deceased; that is why you will never find all of us.

40a. Giao thức Công khai Mở: Thông báo chính thức gửi đến Công ty Valve

NGHIỆP VỤ CÔNG KHAI THÔNG TIN — PhishDestroy · Tháng 8 năm 2026

PhishDestroy không tham gia vào các thỏa thuận giải quyết kín, không ký thỏa thuận bảo mật thông tin (NDA) hay tham gia vào các hành vi tống tiền doanh nghiệp. Mục tiêu của chúng tôi là tính minh bạch và sự thật về mặt kỹ thuật. Cuộc điều tra này — bao gồm dữ liệu đo từ xa thô (đã ẩn danh), tập lệnh tái tạo lỗ hổng bảo mật và phân tích giao dịch trên blockchain — được công bố dưới dạng kho lưu trữ mở. Đồng thời, chúng tôi cũng gửi thư ngỏ chính thức này đến ban lãnh đạo và bộ phận pháp lý của Valve Corporation để yêu cầu làm rõ những mâu thuẫn về mặt kỹ thuật và pháp lý đã được ghi nhận.

NGHI THỨC XÁC MINH — tất cả các thông tin liên lạc đều được chứng thực bằng mật mã
Trước khi công bố: Mọi yêu cầu gửi đi đều được tải lên kho lưu trữ mở của chúng tôi trước khi được gửi đi.
.eml được ký bằng PGP Tất cả các yêu cầu gửi đi và phản hồi nhận được đều được công bố dưới định dạng .eml và được xác minh mật mã bằng chữ ký PGP.
Học thuyết “Mù có chủ ý” (Willful Blindness Doctrine): Các thư được gửi đồng thời đến tất cả các địa chỉ email của công ty, pháp lý và công khai — nhằm xác nhận việc nhận thư.
BA CÂU HỎI YÊU CẦU PHẢN HỒI CÔNG KHAI CÓ CƠ SỞ KỸ THUẬT VÀ PHÁP LÝ:
CÂU HỎI 1: Việc tịch thu tài sản ẩn và sự phi lý của hệ thống chống gian lận

Valve có hệ thống che giấu lý do thực sự đằng sau các lệnh cấm cộng đồng và việc đóng băng kho hàng bằng cách viện dẫn lý do chung chung là “chúng tôi không thể tiết lộ các thuật toán chống gian lận (VAC)”. Điều này là vô lý cả về mặt kỹ thuật lẫn pháp lý: VAC không có liên quan gì đến việc đóng băng giao dịch. Ước tính của chúng tôi cho thấy tài sản bị giữ trái phép trên các tài khoản bot bị cấm (Breakage Income) vào khoảng 300–500 triệu USD. Khối lượng thực tế của kho hàng hiện đang bị đóng băng là bao nhiêu? Tại sao chủ sở hữu tài sản bị tịch thu lại bị từ chối quyền được biết lý do thực sự, chi tiết cho việc khóa tài khoản mà không có những tham chiếu không liên quan đến chống gian lận?

PhishDestroyBằng chứng phản bác: PhishDestroy duy trì hệ thống phân tích theo dõi độc lập đối với các tài khoản bot đã được công khai và các tác nhân đe dọa có hồ sơ hoạt động trên LZT Market. Dữ liệu của chúng tôi cho thấy khoảng 90% kẻ lừa đảo Steam đã biết vẫn chưa bị cấm — không phải vì việc phát hiện kỹ thuật khó khăn, mà vì việc cấm họ sẽ làm mất đi một nguồn thu nhập. Câu trả lời “chúng tôi không thể tiết lộ thuật toán chống gian lận” không phải là một hạn chế. Đó là một lá chắn pháp lý. Chúng tôi có khả năng tiết lộ các phương pháp thực sự: đại đa số những kẻ lừa đảo CIS trên Steam đều đã được ghi nhận, hoạt động công khai, với lịch sử giao dịch kéo dài nhiều năm. Valve không thiếu dữ liệu. Valve thiếu động lực.
CÂU HỎI 2: Nghịch lý Tự động hóa & Việc tạo điều kiện cho thị trường ngầm

Điều khoản Dịch vụ (ToS) của Steam nghiêm cấm tuyệt đối mọi hình thức tự động hóa. Thực tế lại chứng minh điều ngược lại: Valve đã tạo ra và duy trì một Hệ thống Giao dịch Gói (API) được sử dụng độc quyền cho mục đích trộm cắp. Các thị trường ngầm tạo ra hàng triệu yêu cầu API mỗi ngày để xác thực các phiên JWT/SSFN bị đánh cắp. Dữ liệu theo dõi của chúng tôi cho thấy có 300.000 trang trại bot, đăng ký tự động không gặp trở ngại thông qua số điện thoại VoIP, khả năng phân tích proxy/Tor, và hàng triệu tin nhắn lừa đảo giống hệt nhau mỗi ngày. Thời gian từ khi đánh cắp mã thông báo đến khi niêm yết trên thị trường đen: chỉ vài mili giây. Tại sao chức năng API chính thức của Steam lại hoạt động như một đường dây tội phạm trong khi Valve phớt lờ sự tự động hóa công nghiệp có thể chứng minh 100%?

CÂU HỎI 3: Hợp pháp hóa việc vượt qua các lệnh trừng phạt (VPN của Schrödinger)

Điều khoản Dịch vụ (ToS) của Steam cấm rõ ràng việc sử dụng VPN để vượt qua các hạn chế khu vực. Tuy nhiên, trên các miền chính thức của Cộng đồng Steam — được điều hành bởi nhân viên Valve — hàng nghìn hướng dẫn về chuyển đổi khu vực và nạp tiền vào ví (bao gồm cả các khu vực bị OFAC trừng phạt) đã được đăng tải trong nhiều năm và được Google và Bing lập chỉ mục. Việc cung cấp máy chủ Steam để lưu trữ các hướng dẫn vượt qua các lệnh trừng phạt có phải là quan điểm chính thức của công ty không, và tại sao lệnh cấm VPN lại chỉ được thi hành khi điều đó mang lại lợi ích cho Valve?

QUY TRÌNH NÂNG CẤP — Chuyển tiếp theo quy định khi không có phản hồi

Chúng tôi thừa nhận quyền im lặng của Valve Corporation. Tuy nhiên, trong môi trường pháp lý, việc không phản hồi trước bằng chứng kỹ thuật được ghi chép sẽ được coi là Sự thừa nhận ngầm. Sau khi hết thời hạn tiết lộ có trách nhiệm, các tài liệu từ kho lưu trữ của chúng tôi sẽ được gửi đến các cơ quan quản lý sau đây:

OFAC + DOJ NSDCrimea/DNR/LNR giao dịch, “Mù quáng có chủ ý”, hướng dẫn vượt qua các biện pháp trừng phạt được lưu trữ
FinCEN + IRS: MSB không có giấy phép, tịch thu ngầm dưới dạng thu nhập không khai báo, vi phạm KYC/AML
FTC (COPPA): Thu thập dữ liệu của trẻ em dưới 13 tuổi, rò rỉ thông tin cá nhân (PII) của trẻ vị thành niên qua JWT sang các thị trường đen, mức phạt $50.000/vi phạm
CISA + IC3/FBI: Các nền tảng P2P hoạt động như công cụ đánh cắp thông tin hoặc botnet miễn phí tấn công mạng doanh nghiệp Mỹ
Các cơ quan bảo vệ dữ liệu của EU (DPAs): Taylor WessingGDPR: Yêu cầu truy cập dữ liệu cá nhân (DSAR) — các tài liệu bị che mờ không đúng quy định tiết lộ thông tin cá nhân (PII) của trẻ em
Các nhà phát hành: CD Projekt Red, EA, Ubisoft — can thiệp trái phép thông qua việc hỗ trợ sử dụng VPN và chuyển đổi khu vực
Kho lưu trữ đã được mở. Bằng chứng có thể kiểm chứng được. Mọi hành động đều được ghi lại. Nếu Valve quyết định không hợp tác với các nhà nghiên cứu độc lập, cuộc đối thoại này sẽ được tiếp tục bởi các cơ quan quản lý, truyền thông và các đối tác tổ chức, những người sẽ đặt ra những câu hỏi tương tự tại tòa án. Chúng tôi đang chờ phản hồi từ quý vị.
BÁO CÁO VỚI CÁC CƠ QUAN CHỨC NĂNG ĐỊA PHƯƠNG

PhishDestroy đang tích cực tìm kiếm các quốc gia và cơ quan quản lý, những người không thờ ơ trước việc công dân của họ — và con cái của họ — đang bị đánh cắp tài sản, bị lôi kéo một cách có hệ thống vào nghiện cờ bạc, và bị phơi nhiễm trước những gì có thể là, ít nhất là thông qua sự chấp thuận ngầm của Valve, một phương thức đã được ghi nhận để xâm nhập thiết bị trên quy mô lớn.

Chọn quốc gia của quý vị để xem các kênh báo cáo chính thức đã được xác minh. Không có thông tin nào được gửi tự động — hãy xem xét từng sự kiện và tự mình gửi thông qua kênh chính thức.

Không có thông tin nào được gửi tự động. PhishDestroy chỉ cung cấp các địa chỉ liên hệ báo cáo đã được xác minh. Vui lòng tự gửi khiếu nại qua kênh chính thức.

41. The Ultimatum

One question requires a public answer on the record: According to Valve's Terms of Service, does a court in the annexed territory of Crimea qualify as "any local Russian state court"? Without a direct, public answer to this question, do not contact us.

If a "peaceful settlement" is what you want, enforce your own rules:

Ban every account that has ever used a VPN to access Steam (you have the database).

Block every account that has used automation on the platform, including CSGOFast.

Admit that Valve or its proxies conducted a cyberattack against Source 1.

The minimum standard of fairness: return every asset stolen through trade substitution (API scam). Start with every account ever listed on Lolzteam Market. We understand your architecture — we saw your internal device identification logic in those unredacted GDPR documents. "Technically impossible" is not an answer. If your staff cannot do it, replace them. The outcome does not change regardless of what you try. We have no money to seize, no names to expose, and no corporate reputation to ruin. We are armed only with the truth.

A Global Warning: The Infostealer Epidemic and Corporate Collateral

I am addressing every country on Planet Earth — except the terrorist states, since Steam is already getting along with them just fine.

If you care at all that an unaccountable corporation has decided it has the right to steal your children's digital property, listen closely. If you care that they deliberately fail to notify users about infected devices — thereby compromising critical corporate networks worldwide — then pay attention.

In Part 2 of our investigation, we will present a perfect example of what Steam's negligence has actually spawned. We will provide hard evidence proving that Steam is the primary economic fuel for the global infostealer industry. Steam accounts are the top gaming query for malware operators. Without the financial return provided by Steam's thriving shadow market, these massive, indiscriminate infostealer distribution campaigns would simply be economically unviable.

There is already a public case on the record where a $2 stolen log resulted in a corporate lockdown, a $17 million ransom payout, and total damages exceeding $100 million. Thank you, Valve, for your unparalleled commitment to global "security."

We will not hide this intelligence. Information flows to us naturally, and we will publish it all. And let this be our official declaration: if, God forbid, the evidence reveals that Valve or its proxies have been conducting targeted cyberattacks against specific users to silence them, the international community will not play along. The rest of the world will not entertain your cute little legal games about exclusive jurisdiction in the courts of Washington State.

42. Phán quyết cuối cùng

PHÁN QUYẾT CUỐI CÙNG — BA SỰ KIỆN ĐƯỢC GHI CHÉP RÕ RÀNG
I. Steam đã giết chết những đứa trẻ mà nó đã tiết lộ thông tin. Dữ liệu đã tồn tại. Các công cụ đã tồn tại. Quyết định không hành động luôn là một sự lựa chọn — chứ không phải là một hạn chế.
II. Steam ăn cắp tiền của trẻ em dưới chiêu bài chống lại những “bản sao” mà chính đội ngũ hỗ trợ của họ tạo ra. Thu nhập từ Breakage không phải là lỗi. Đó là một nguồn thu nhập.
III. Steam nói dối về việc giấu lý do cấm tài khoản dưới vỏ bọc “chống gian lận”. Lệnh cấm cộng đồng không liên quan gì đến VAC. Việc giấu lý do là thuận tiện về mặt pháp lý, chứ không phải cần thiết về mặt kỹ thuật.
Những tuyên bố này được hỗ trợ bởi tám năm bằng chứng được ghi chép, các thông báo chính thức từ “GDPR”, dữ liệu theo dõi từ LZT Market và các tài liệu pháp lý được ghi nhận chính thức. Đây không phải là những cáo buộc. Đây là những kết luận dựa trên sự thật.

Dù sao thì bot đó cũng không còn nằm dưới sự quản lý của chúng tôi nữa. Tôi không cảm thấy xấu hổ, và tôi không tin rằng mình đang làm điều sai trái. Tôi chắc chắn rằng chúng tôi không còn lựa chọn nào khác. Nguồn 1 đã tự dừng lại kịp thời, nhưng theo quan điểm của chúng tôi, các bạn đã giết những đứa trẻ mà dữ liệu của chúng đã bị rò rỉ cho anh ta. Do đó, chúng tôi sẽ không đàm phán. Steam mới là kẻ khủng bố ở đây.

Hãy đánh giá lại những gì các bạn đã làm, và những gì Nguồn 1 đã làm sau khi các luật sư của các bạn giao dữ liệu đó cho anh ta. "Nikita" của các bạn đến từ đâu? Còn bốn nhân viên hỗ trợ ngoài biên chế đang ở Nga thì sao? Tôi chắc chắn rằng bạn nghĩ đây là một sự cố riêng lẻ, nhưng chúng tôi biết về nhiều vụ việc và những “quyết định” của bạn.

Chúng tôi không phải là các bạn. Chúng tôi không che giấu những tội ác tiềm ẩn. Chúng tôi sẽ dần dần công bố mọi thứ kèm theo bằng chứng và hợp tác với bất kỳ cơ quan quản lý nào — ngoại trừ những cơ quan mà các bạn dường như ưa chuộng. Các cơ quan chức năng Nga thường xuyên gửi thư cho chúng tôi; chúng tôi thường bảo họ "cút đi", nhưng có lẽ chúng tôi sẽ bắt đầu trả lời. Chúng tôi không chơi những trò ngu ngốc với những phản hồi công ty khó hiểu nhằm gây nhầm lẫn, giống như thỏa thuận người dùng của các bạn.

Tôi hy vọng lập trường của chúng tôi hoàn toàn rõ ràng:

Steam đã giết chết những đứa trẻ mà chính họ đã tiết lộ thông tin.

Steam ăn cắp của trẻ em dưới chiêu bài chống lại các “bản sao” mà hoàn toàn do chính nhân viên hỗ trợ của họ tạo ra.

Steam nói dối về việc giấu lý do cấm dưới vỏ bọc "chống gian lận" chỉ vì điều đó thuận tiện về mặt pháp lý. (Chống gian lận thì có liên quan quái gì đến việc cấm tham gia cộng đồng chứ?)

Các bạn thực sự tự tin đến mức cho rằng tòa án của các bạn hay châu Âu sẽ nhắm mắt làm ngơ sao? Chúng ta sẽ xem sao.

---

42. Conclusion

The bot is no longer under our management anyway. I feel no shame, and I do not believe I am doing a bad thing. I am certain we have no other choice. Source 1 stopped himself in time, but as far as we are concerned, you killed the children whose data you leaked to him. Therefore, we will not negotiate. Steam is the terrorist here.

Re-evaluate what you did, and what Source 1 was doing after your lawyers handed him that data. Where did your "Nikita" come from? And what about the four off-staff support agents sitting in Russia? I am sure you think this is an isolated incident, but we know about many of your cases and your "decisions."

We are not you. We do not cover up potential crimes. We will gradually release everything with proof and cooperate with any regulator — except the ones you seem to favor. Russian authorities write to us frequently; we usually tell them to fuck off, but maybe we will start answering. We don't play stupid games with unintelligible corporate responses designed to confuse, much like your user agreement.

I hope our position is absolutely clear:

Steam killed the children it leaked.

Steam steals from children under the guise of fighting "dupes" that were generated entirely by its own support staff.

Steam lies about withholding ban reasons under the guise of "anti-cheat" strictly because it is legally convenient. (What the fuck does anti-cheat have to do with a Community Ban?)

Are you really that confident your courts or Europe will just turn a blind eye? We will see.

---

References & Sources

[1] Netcraft Anti-Phishing Service and Reporter Prizes Program https://www.netcraft.com/anti-phishing/

Netcraft is a leading internet security company that tracks and reports phishing sites. The Reporter Prizes program rewards verified submissions. Valve's refusal to cooperate with Netcraft is documented through public anti-phishing statistics.

[2] Cloudflare Abuse Reporting Portal https://www.cloudflare.com/abuse/

Used for escalating phishing campaigns employing cloaking techniques against Cloudflare-protected infrastructure.

[3] Valve Internal Data Disclosure (2024) — Employee Count and Revenue Per Employee

Sources: Kotaku, Ars Technica, IGN, The Verge, PCGamer (May 2024)

https://kotaku.com/ [search: "Valve employees 2024"]

https://arstechnica.com/ [search: "Valve internal data leak"]

Internal documents revealed Valve's total headcount (~336) and the number of employees directly working on the Steam platform (~79), along with boasts about profit-per-employee exceeding Google, Amazon, and Microsoft.

[4] LZT Market (Lolzteam) — Shadow Marketplace Statistics https://lolz.live / https://lzt.market

Russian-language clearnet marketplace for stolen accounts and cybercrime services. Item IDs (e.g., item_id 252853378) confirm cumulative listing history exceeding 250 million lots. Account counts cited reflect live marketplace data at time of documentation. Covered by: Group-IB, KELA Cyber Intelligence, and other threat intelligence providers.

[5] BlockBlasters Malware Incident on Steam (September 2024)

Security community reports and Steam community threads (September-October 2024):

https://www.reddit.com/r/GlobalOffensive/ [search: "BlockBlasters stealer"]

https://steamcommunity.com/

A game titled BlockBlasters was listed on Steam and distributed an information stealer. Reports submitted to Steam support beginning September 2, 2024 included open Telegram API endpoints embedded in game code. The game remained available for approximately one month before malicious builds were removed.

[6] Raivo Plavnieks — Content Creator and Whistleblower

Twitch streamer whose coverage of the BlockBlasters incident brought the malware to wider public attention. Documented through VODs, community posts, and security researcher reports (September 2024).

[7] ChainAbuse — Cryptocurrency Abuse Reporting Platform https://www.chainabuse.com

Community-maintained database of cryptocurrency addresses associated with scams, ransomware, and fraud. Victims of the BlockBlasters stealer submitted reports to ChainAbuse documenting wallet addresses used to receive stolen cryptocurrency.

[8] IRS Form W-8BEN — Certificate of Foreign Status of Beneficial Owner https://www.irs.gov/forms-pubs/about-form-w-8ben

Required from non-US developers earning income through US entities (including Steam). This KYC document ties the developer's legal identity directly to their Steamworks publisher account, refuting Valve's "hacked anonymous developer" narrative.

[9] Taylor Wessing — International Law Firm https://www.taylorwessing.com

Offices in Hamburg, Munich, London, and other cities. Represents Valve Software in European legal matters including GDPR data subject access requests (DSARs). The firm's historical founding and its predecessor entities' documented connections to the Third Reich era have been the subject of academic and journalistic inquiry into German law firm histories.

[10] EU General Data Protection Regulation (GDPR) — Regulation 2016/679 https://eur-lex.europa.eu/eli/reg/2016/679/oj

https://gdpr.eu/

Under Article 15 GDPR, data subjects may request full disclosure of personal data held. Valve's compliance with DSARs has been processed through Taylor Wessing, and documented cases show improperly redacted responses disclosing data of third parties — including minors.

[11] RedLine Infostealer — Operation Magnus (October 28, 2024)

Europol Press Release: https://www.europol.europa.eu/media-press/newsroom/news/operation-magnus-redline-and-meta-infostealers-dismantled

FBI and Dutch National Police (Politie) participated in the takedown of RedLine and META stealer infrastructure. RedLine was the dominant tool for stealing Steam session files (SSFN) and browser cookies during 2021-2024, sold as Malware-as-a-Service (MaaS) on Russian-language forums.

Additional coverage: BleepingComputer (October 2024), The Record, Krebs on Security.

[12] SteamRep — Community Trading Reputation Database https://steamrep.com

Volunteer-run platform that tracked scammers in Steam trading communities. Internal controversies, including alleged bribery for scammer tag removal and administrative corruption, were documented in community forum threads circa 2016-2020. Valve severed formal cooperation with SteamRep-affiliated moderators by 2022.

[13] Jess Cliffe — Counter-Strike Co-Creator

Reported by: Kotaku, Polygon, PC Gamer, The Verge (September 7-8, 2016)

https://kotaku.com/ [search: "Jess Cliffe Valve"]

Valve placed Jess Cliffe (credited alongside Minh Le for creating Counter-Strike) on administrative leave in 2016 following his arrest on charges of commercial sexual abuse of a minor. He was subsequently terminated without a court conviction.

[14] Valve Steam Trade Hold Policy

Steam Blog announcement on trade holds (December 9, 2015):

https://steamcommunity.com/games/593110/announcements/detail/

The 7-day hold on traded items was formally introduced in December 2015. Earlier escrow mechanisms were introduced starting 2012. The policy change was intended to reduce fraud but in practice created the linear theft pipeline described in this report.

[15] Valve Anti-Cheat (VAC) System

Official documentation: https://support.steampowered.com/kb_article.php?ref=7849-Radz-6869

VAC bans are account-wide, permanent, and tied to the hardware/phone number used during the violation. The asymmetric application of VAC bans (aggressive for cheating, absent for mass phishing activity) is documented through community tracking at vacbanned.com and similar resources.

[16] FBI Seattle Field Office

Address: 1110 3rd Ave, Seattle, WA 98101

Phone: +1 (206) 622-0460

https://www.fbi.gov/contact-us/field-offices/seattle

Valve Software is headquartered at 10400 NE 4th St, Bellevue, WA 98004 — within the FBI Seattle field office jurisdiction.

[17] IC3 — Internet Crime Complaint Center (FBI) https://www.ic3.gov

The FBI's official portal for reporting cybercrime, including account theft, fraud, and sanctions violations. Accepts reports from individuals, businesses, and third parties.

[18] CISA — Cybersecurity and Infrastructure Security Agency https://www.cisa.gov

US federal agency responsible for critical infrastructure cybersecurity. CISA's Stop Ransomware and Known Exploited Vulnerabilities programs are relevant to the infostealer ecosystem documented here.

[19] DOJ NSD — Department of Justice, National Security Division https://www.justice.gov/nsd

Oversees national security cases including sanctions violations (OFAC referrals), foreign influence operations, and cyber threats tied to nation-state actors. The potential nexus between state-adjacent structures controlling LZT Market and Steam's platform policy warrants NSD attention.

[20] OFAC — Office of Foreign Assets Control (U.S. Treasury) https://ofac.treasury.gov

Russia-related sanctions programs: https://ofac.treasury.gov/sanctions-programs-and-country-information/russia-related-sanctions

Ukraine-EO13685 (Crimea), and subsequent executive orders cover the DNR/LNR regions. Accepting payments originating from sanctioned persons or territories — whether directly or through intermediaries — may constitute sanctions violations subject to civil and criminal penalties.

[21] JSON Web Token (JWT) — RFC 7519 https://datatracker.ietf.org/doc/html/rfc7519

Industry-standard method for representing claims between parties. Steam adopted JWT-based session tokens as a replacement for legacy SSFN files. The off-platform validation capability of JWTs (verifiable without querying Steam servers) is a documented property of the specification.

[22] Steam Direct — Developer Application and KYC https://partner.steamgames.com/steamdirect

Valve charges $100 per game submission and requires developers to submit legal identification, tax forms (W-8BEN for non-US), and banking information. This KYC process creates a paper trail that directly contradicts the "anonymous hacker" narrative.

[23] Roskomnadzor — Federal Service for Supervision of Communications, Information Technology and Mass Media (Russia) https://rkn.gov.ru

The Russian federal regulator has issued multiple administrative decisions against LZT Market (Lolzteam) ordering its blocking. These decisions have been publicly available in Russian regulatory databases. The market's continued operation despite five such decisions points to legal maneuvering and possible political protection.

[24] FunPay — Russian Peer-to-Peer Trading Platform https://funpay.com

Widely used platform in CIS regions for trading in-game goods, including Steam balance top-ups and region-switching services. Transaction counts cited (500,000+) reflect documented seller statistics visible on the platform's seller profiles.

[25] Tinkoff Bank — Sanctioned Russian Financial Institution

Tinkoff Bank (now T-Bank) was added to OFAC SDN list and subjected to EU sanctions following Russia's 2022 invasion of Ukraine.

OFAC SDN list: https://ofac.treasury.gov/specially-designated-nationals-and-blocked-persons-list-sdn-human-readable-lists

Steam accounts were documented receiving top-ups from Tinkoff-issued cards in the CIS region after the imposition of sanctions.

[26] Uniswap Protocol — Decentralized Exchange https://uniswap.org

Uniswap and broader DeFi protocols have been targeted by phishing operations whose techniques and personnel originated in the Steam scam ecosystem. Security reports from Chainalysis, CertiK, and SlowMist document the migration of CIS-region fraudsters from gaming scams to Web3 drainer attacks.

[27] Steam Session Files (SSFN) — Technical Documentation

Community and security researcher documentation:

https://steamdb.info / https://github.com/nicklvsa (various Steam security research repos)

SSFN (SteamSentryFile) files stored Steam Guard authentication tokens locally. When stolen by infostealers, they allowed session reuse without re-authentication. Valve deprecated SSFN in favor of JWT-based sessions during 2023-2024.

[28] Binance / Bybit / Gate.io — Cryptocurrency Exchanges https://www.binance.com | https://www.bybit.com | https://www.gate.io

Major centralized exchanges whose Telegram payment bots and P2P trading infrastructure are used by LZT Market and similar platforms to process payments for stolen account transactions, circumventing traditional AML controls.

[29] Steam Phishing via Google Ads — Documented Campaigns (2023-2024)

Reported by: BleepingComputer, Malwarebytes, Group-IB

https://www.bleepingcomputer.com/ [search: "Steam phishing Google Ads"]

https://www.malwarebytes.com/ [search: "Steam phishing ads"]

Attackers purchased Google Ads targeting Steam-related search queries, substituting display URLs to appear as legitimate Steam domains. The scale of the 2024 campaign documented by PhishDestroy ($300,000 estimated net proceeds) aligns with Google Ads abuse patterns documented by multiple cybersecurity firms.

[30] STALKER 2 / GTA — Games Whose Publishers Withdrew from Russian Market

GSC Game World (STALKER 2) officially suspended sales in Russia following the 2022 invasion of Ukraine.

Rockstar Games / Take-Two Interactive restricted GTA sales in Russia following sanctions.

Despite publisher intent, Steam continued to provide mechanisms allowing Russian users to purchase these titles via region-switching, as documented by community researchers and gaming press (Eurogamer, RPS, IGN, 2022-2024).

---

ADDITIONAL CONTEXT: REGULATORY AND LEGAL FRAMEWORK

Steam's Terms of Service (ToS), Version History:

The Steam Subscriber Agreement is archived by the Internet Archive Wayback Machine:

https://web.archive.org/web/*/https://store.steampowered.com/subscriber_agreement/

Comparison of versions shows modification of sanctions-related language, including the removal of explicitly named countries (Cuba, Iran, Syria) from prohibited territory lists.

AML / FATF Guidelines on Virtual Assets:

Financial Action Task Force (FATF) guidance on virtual assets and virtual asset service providers:

https://www.fatf-gafi.org/en/topics/virtual-assets.html

Skin trading platforms and Steam Wallet function as virtual asset ecosystems subject to FATF Recommendation 15.

Europol — Internet Organised Crime Threat Assessment (IOCTA):

https://www.europol.europa.eu/publications-events/main-reports/iocta-report

Annual reports document the role of gaming platforms in cybercrime recruitment and infostealer distribution.

Group-IB — Hi-Tech Crime Trends Report:

https://www.group-ib.com/resources/research/

Documents the evolution of CIS-region cybercrime from gaming-platform fraud to ransomware and financial crime.

Chainalysis Crypto Crime Report:

https://www.chainalysis.com/blog/crypto-crime-report/

Annual report documenting laundering of cybercrime proceeds through decentralized exchanges and peer-to-peer platforms, including those accepting Steam-ecosystem stolen goods.

---

NOTE ON SOURCES

All market statistics cited (LZT Market account counts, transaction volumes, JWT token prices) reflect data documented at specific points in time by PhishDestroy through direct platform observation. Shadow market data is inherently dynamic; figures cited represent point-in-time measurements and directional trends, not static permanent values. Where possible, archived copies of relevant pages have been preserved on the Wayback Machine (web.archive.org) and independent archival nodes.

All regulatory contact information (FBI, IC3, CISA, DOJ NSD, OFAC) reflects publicly available official contact data as of the date of this publication.

PhishDestroy Demands

Valve must be held financially accountable for accounts stolen through their deliberate negligence. The minimum estimated liability: $450,000,000 — representing the documented victim real spend on accounts currently listed on LZT Market across all categories, and the value of inventories frozen on banned bots that were never returned to victims.

This is not an estimate of criminal market value. This is the documented money victims spent on their accounts — money that Steam's negligence, outsourced corruption, and deliberate API blindness allowed to be stolen and re-monetized on criminal markets while Valve collected commission on both the original sale and every subsequent stolen skin transaction.

Valve wrote the policy that prevents item restoration. Valve's outsource staff committed the thefts. Valve's API enabled the marketplace. Valve's 15% commission runs on the same skins. The accountability is structural, not incidental.

Back to News & Investigations