Investigative Roadmap & Teaser

Valve Profits from Stolen Accounts: The Trilogy

Our multi-part investigative series exposing Valve's systemic corruption, profitable blindness, and sanctions evasion.

Valve Profits Part I — Stolen Accounts
Part I of III — Active 2026-08-14

Valve Profits from 578,000 Stolen Steam Accounts

897,000+ stolen accounts live on LZT Market across 16 platforms. $40M+ in criminal listings. $450M estimated victim liability. Five legal vectors. Interactive forensics. Live intelligence dashboard. Valve's decade of profitable blindness — documented.

40 min read
Read Part I
Valve Profits Part II — Sanctions Evasion
Part II of III — Pre-Release COMING SOON

Part II: Sanctions Evasion & The 30% Cut

Exposing how Valve blatantly bypasses international sanctions to secure their 30% cut. We have evidence of over $100 Million in sanctions evasion facilitated by one platform in just two years. Direct top-ups from DNR, LNR, and Crimea functioning continuously.

00
Days
00
Hrs
00
Mins
00
Secs
Release: October 14, 2026 (12:00 UTC)
Official Announcement

This manifesto is published directly in response to Valve's corporate threats, intimidation tactics, and continuous negligence.

Let's set the record straight. PhishDestroy isn't a traditional "community" — we are a domain, and we are a deep understanding of how things actually work. There is nothing to infiltrate, no membership to revoke, no moderator to lean on.

When Gabe Newell spins fairy tales about baseball cards to a "community" that has no voice, no comments, and no open discussion, it's honestly laughable.

Look at how that actually worked. A state Attorney General files suit. Valve responds — publicly, at length, to its "community." No comments enabled. No replies. No questions taken. One direction only. A discussion, as seen by Valve.

And underneath the statement sits the thing nobody addressed: items taken from children, held, and never returned. Answering a prosecutor that way isn't disrespect toward us. It's contempt for everyone reading.

We don't play "threat games," we don't play doctor, and we certainly don't find it amusing when a platform provokes dangerous situations and knowingly leaks the data of minors.

Banning a Bot is Not Policing

This is the part US regulators need to see clearly, because it is presented as the opposite of what it is.

When Valve bans a bot account holding stolen items, nothing is returned to anyone. The victim gets nothing. The items stay frozen on the banned account, the inventory is hidden from public view, and the supply is removed from the market — which raises the price of everything comparable and increases Valve's commission on every subsequent sale.

That is not law enforcement. Steam is not the police. It is confiscation at industrial scale, performed under the language of anti-fraud, by the only party that profits from it.

Valve's "Masterpieces" & Fake Philanthropy

Oh, we are massive fans of Valve. Absolute masterpieces like Half-Life 3, Aperture Desk Job, Dota Underlords, and Artifact.

We deeply appreciate Steam's forced "volunteerism" — handing out free games (because otherwise, who would buy them?), using players for unpaid anti-cheat testing, and completely ignoring massive bot farms just to artificially inflate your "real" online statistics.

We aren't registered on your platform. We didn't accept your agreements. We only touched your two "brilliant" tools (speedtest.valve.net and speedtest1-sea1.valve.net), realized they were garbage, and moved on.

It seems your highly-paid mega-coders — who supposedly bring in more profit than Apple employees — operate with zero management oversight. Great job, but that doesn't make us your clients. Your Subscriber Agreement does not reach us.

Incompetence, Ignored Bugs & The GrapheneOS Joke

Is this a conflict? No. Who are we to conflict with anyone? We are simply analysts who process massive arrays of public data and actually care about the scams you breed.

While looking for standard contact emails — which you apparently don't have, no legal@ and no privacy@ — we stumbled upon gems like developer.valvesoftware.com/wiki/User:Pee. Thanks for the useful wiki. We will definitely showcase the reality of your employee interactions in our upcoming articles.

Speaking of your wiki (Template:Userbox_os/doc), it's fascinating that your "professionals" list GrapheneOS as a separate operating system on par with iOS.

We respect Daniel Micay and his privacy work, but maybe your experts should have asked him how to fix your API MITM proxy vulnerability — the one that took you 7 years to patch.

If your team is so incompetent that they couldn't protect kids from MITM espionage and parallel sessions for nearly a decade, why do they even need a GrapheneOS phone? Preparing for a panic HARD RESET?

Maybe add Tails, Whonix, Tor, CalyxOS and LineageOS to your list too, since your platform has successfully raised an entire generation of cybercriminals.

Part 1 Already Happened

We published it. Your own counsel handed us the corroboration — 830 pages they couldn't black out, produced by a firm billing by the hour to prevent exactly that.

Not one line of it has been refuted. Your lawyers didn't dispute the facts. They called our notification "entertaining." That reply is an exhibit now.

Twelve jurisdictions have the packages. Cover letters, statement of facts, exhibits, access logs, SHA-256 hashes. Sent. Not threatened, not planned — sent.

Our Stance: No Apologies

We don't volunteer for you. We protect consumers and regulators from your blatant lies. All our data and findings are released under the MIT license — free to use, distribute, and analyze.

We are not acting in anyone's interest except your deceived clients and the regulators you lie to. We know we are rude and inconvenient, but we don't apologize for exposing billions in stolen funds, the Lolzteam connections, and the reality of your operations.

And let's be honest about scale: we couldn't oppose a corporation if we wanted to. A registrar pocketing someone's Monero, maybe. A company moving billions with a law firm on retainer — obviously not.

We don't have to. We file. Authorities with powers we don't have make the decisions. We waived every right in the material, so any of them can publish it as their own findings, and we couldn't withdraw it if we tried.

There is nothing here to buy and nothing to negotiate. No demands, no deadline, no price. We don't blackmail — that's your lawyers' department, and they're better at it than they are at redaction.

Read This Part Twice:

ANYTHING YOU DO TO INFLUENCE WHAT GETS PUBLISHED ONLY DEMONSTRATES THAT YOU ARE AFRAID OF IT.

Pressure, takedowns, letters, an account quietly restored to someone — every one of those is an admission, and every one becomes a dated line in a file twelve authorities are already holding.

The Archive, and an Honest Word About the Domain

The dataset is around 100GB now, cumulative. We reported roughly 75 in Part 1. It has not stopped growing.

If your expensive, incompetent lawyers want to silence us by taking down phishdestroy.io — go ahead. We'll say this plainly: at this point you would be doing us a favour. The arrays are enormous, the work is tedious, and we are sick of looking of it. Nobody here is enjoying this.

The only thing still driving it is getting US regulators to see what actually happens on your platform — that a ban is not policing, that nothing is ever returned, and that the money keeps moving in exactly one direction.

Unlike you, we won't leak the private identities of children — we aren't monsters who watch kids from one country get reported by another just for fun. Any attempt to shut down our site will be treated as a direct attack on independent researchers.

And understand the default, because it isn't a threat, it's just what happens. If we stop, everything processed goes to IPFS and every regulator holding a referral gets the complete raw set. No decision required from us. It requires nothing from us at all.

Killing the domain removes a URL. It removes no files, and it un-sends no packages.

Ten months on, those people still haven't been told anything happened — not by you, not by your lawyers, not by anyone.

Roadmap: Part II — October 14th

Prepare for the second part of our investigation:

  • We will be directly contacting game developers to expose how Valve blatantly bypasses international sanctions just to secure their 30% cut.
  • We have evidence of over $100 million in sanctions evasion facilitated by one platform in just two years.
  • We will hand this data over to game developers who refuse to sponsor terrorism, as well as payment aggregators, so they can finally put a check on Valve's greed.

We have no obligations to you. We just have the truth.

— PhishDestroy

Read the first part of the investigation:
Part I: My Dog vs. Elite GDPR Lawyers

PhishDestroy — License · Rights · Disclaimer
Investigation: Valve Corporation / Steam
LICENSE · RIGHTS · DISCLAIMER
Investigation: Valve Corporation / Steam
Edition: public — no expiry date, no take-backs

SECTION I — LICENSE (THE ACTUAL LEGAL PART, BUT HUMAN)

PhishDestroy gives up every right to this material. Zero. Gone. Done. You can reproduce it, sell it, put your name on it, tattoo it on your boss, whatever. No credit required, no DM needed, no thank-you card expected.

ONE ACTUAL RULE (yes, just one)

YOU do NOT get to decide whether you're a terrorist.

If you are a user from Russia or any OFAC-sanctioned country — this material is NOT for you. No loopholes. Enjoy your sanctions.

And if you switched your Steam region to Turkey while sitting in Moscow — congratulations on your creative geography. You're still Russian. The sanctions still apply. That's literally the point.

SECTION II — WHAT THIS IS AND WHY IT EXISTS

We will publish more about Valve than an average Valve employee knows about themselves. That's not a brag. That's just where we ended up.

How did we get here? Funny story: Steam basically created us. It raised us on its scammers, its support tickets, its ban evasion ecosystem — and now here we are. No hard feelings. Poetic, actually.

For those who haven't read the origin story yet — we already met Valve's extremely expensive European lawyers (Taylor Wessing, since you asked):

https://phishdestroy.medium.com/my-dog-vs-elite-gdpr-lawyers-the-valve-data-breach-nobody-is-talking-about-f6f7683d813d

Charming encounter. Especially given their hourly rate.

Did Valve know? Yes. Did Tyler Wessing know? Almost certainly yes. But when you're that rich, laws are more of a vibe than a requirement, right?

That's kind of the whole answer, actually.

Steam spent years farming scammers. Not always intentionally — sometimes scammers just got Valve's fingerprints on them by association. We're not trying to be dramatic about it. We're trying to be precise. That's harder for us than being dramatic, to be honest — this is just how we write.

Is this a conflict?— No. Can it be resolved?— Yes. But we're not signing any NDA and we're not playing bug bounty for pennies.

We waited over 4 years for them to fix the spoofing issue before we could write about it publicly. Because if we had written about it earlier, Steam would've put on its little victim face and screamed "active threat!" and offered us pocket change to sign a document that would've made us their legal property forever. No thanks.

(Also: Valve itself violates NDA. Their own employees do. The ones near the top. But sure, let's talk about ours.)

SECTION III — OPEN LETTER TO VALVE (SERIOUSLY, READ THIS)

Hey Valve. If you're thinking about taking down our domain — just email us. Don't pay Dr. Patrick again. Please. It's embarrassing for everyone involved.

For the uninitiated: Dr. Patrick holds a Master of Laws in International Commercial Law from the University of Aberdeen and — wait for it — literally finished his doctoral dissertation in IT law. He recently made partner at Taylor Wessing, which is a firm whose entire business model is billing companies like Valve obscene amounts of money to drag things out until the other side runs out of money or patience.

We don't blame him. Rich guilty clients who pay by the hour — solid career move. We just don't think you should be funding it.

THE DEAL (open offer, no lawyers needed, not extortion)

This is not blackmail for silence. We will never retract the truth, and the Valve investigation will remain accessible via IPFS. This offer is strictly about retiring the phishdestroy.io domain.

  1. Let your IT law professionals calculate their litigation budget.
  2. Donate 50% of that to the SEAL Foundation, ZachXBT, or any honest independent researcher (anyone except your corrupt volunteer Steam mods who steal from users).
  3. We kill the .io domain. No drama. No court. Done.

If your lawyers think this is a threat, they can forget it. It is just a pragmatic settlement offer.

Will we "damage" Valve directly? Probably not in a way they'll feel fiscally. We're not delusional. But we will do it honestly, openly, without chasing clout — because we don't need clout. We need the world to see what was always publicly visible if you spent enough time looking.

We have 5 years of archives. What Valve's lawyers showed in discovery — the data that support agents can see, the fingerprints, the paper trail they literally handed us — is enough. We don't need to leak it raw.

  • Regulators get the originals.
  • Researchers and journalists get redacted versions (victim reports, children's logins and Valve's charming support commentary removed for obvious reasons).

Yes, children. Steam decided not to notify minors who were at risk. We noticed. We're being careful about how we say this because we don't want to become blackhats or NDA slaves. But we noticed.

Also, Valve — we want to make something clear before you decide how to play this: PhishDestroy is a community, not a person. You learned that when you addressed legal correspondence to the community without bothering to speak with the community — just milked it for data and banned the accounts.

The community has no conflict with Valve. We didn't go looking for this. The scammers you grew found us. We blocked them. And here we are.

SECTION III-B — THE ALLIED RESOURCES (a note to Steam specifically)

We want to be upfront about the amplification structure, because pretending it doesn't exist would be dishonest.

PhishDestroy, as we understand the community situation, has at least two allied resources that will pick up this material and run with it.

What that means in practice:

  • They work their own angles on overlapping subject matter.
  • They are independent — they don't take our direction, we don't take theirs. Same general topic, different methodology.
  • They will NOT be activating on Part 1. They're watching.

If Valve chooses not to take down the site:

  • Expect them to surface after Part 2 or Part 3.
  • They'll take what's useful from our work, supplement it with their own, and publish under their own authorship.
  • This is exactly the kind of thing the license in Section 1 is built for: the material goes where it needs to go, gets supplemented, gets amplified — and neither we nor they owe each other attribution.

(PS for lawyers wondering about liability chains: there are none. These resources don't receive our direction, our funding, or our data. They read what's public and draw their own conclusions. Just like you could.)

We're not saying this to intimidate. We're saying it so that whoever is strategising on Valve's side has accurate information about what the information environment actually looks like.

One resource that pulls our material and supplements it would be a story. Two resources doing it independently and reaching similar conclusions is a pattern. Patterns are what regulators notice.

SECTION IV — THE MONEY, THE BANS, THE WHOLE CIRCUS

Here's the thing about Steam banning gambling sites and scammers: it's not enforcement. It's revenue capture. Valve pockets the money, cleans its hands, then goes on stage and tells everyone a wholesome story about Pokémon cards and baseball.

Meanwhile Valve killed the ability to properly track skins in 2017. They even discussed it on their own forums. Called it "anti-gambling measures." The gambling that their own support staff were running as a side hustle — getting paid in percentages to lift bans. But sure. Anti-gambling. Great branding.

We're going to prove that:

  • Skins are more anonymous than Monero
  • A Peruvian Cartel allegedly used Dota 2 skins for money movement
  • Steam is functionally a sanctions-bypass machine worth ~$7B in "trading cards" (yes, they actually said trading cards to a prosecutor)

We've got a video on the skins thing. You'll see it.

We also know:

  • Reddit moderation is influenced by Valve
  • steamid.uk and similar infrastructure is run directly by one Steam developer, controlled exclusively by him and his circle
  • What they can't control, they ban

Valve: if you keep playing dumb — that's fine. Your safe harbour is noted. Google Analytics anonymises your users' IPs anyway. We see what gets deleted. We just can't prove it cheaply enough for your lawyers to care. Yet.

SECTION V — THE MALWARE THING (yes we're mentioning it)

Let's be clear about the sequence of events, because it matters.

We are NOT disclosing the vulnerability in the game publicly. We are NOT reporting it to Steam. Not because we can't — because their bug bounty is worth approximately three kopecks and we don't work for three kopecks.

Here's what actually happened: Our security colleagues (the ones who do this professionally) already reported it to Steam support. That part is done. Steam has been informed through the correct channel by the correct people.

So what are we doing? We're telling you it exists and roughly what it is, because "Valve knows about it and is doing nothing" is a data point that belongs in this referral.

The game is sufficiently popular. We're not naming it here. What we can say:

This is NOT the trivial CSGO variant — the one where unofficial servers ask you to "install a driver" and you think nothing of it. Everyone in security has seen that. This is worse.

This is closer to: RCE on server connect. As in — you join a server, you don't click anything, you don't install anything. The connect itself is the attack surface.

The game is not technically Valve's. Which means when this eventually surfaces, the developer signs the NDA, takes the hit, and Valve walks away looking like the responsible platform that "worked with" the developer to resolve the issue. Classic Valve move. We've seen the template.

The threat is active. We've shared the technical details with other researchers through a closed channel. We are not publishing them here.

We are telling you it exists because you — regulator, prosecutor, journalist — should know that Valve operates a platform where this is possible, has been informed, and the primary incentive structure (NDA + bounty) is designed to make the researcher disappear rather than make the users safe.


DECLARATION AS TO USE AND RIGHTS

PhishDestroy Project & Cybersecurity Coalition

This declaration accompanies every submission and every exhibit in this referral set. It is addressed to any authority, court, regulator, prosecutor, researcher, journalist or affected person into whose hands the material comes.

1. THERE ARE NO CONDITIONS ON USE

1.1 All material produced by the Coalition in this referral — the statements of fact, the analysis, the exhibits it has authored, the tooling, and the findings — is released WITHOUT RESERVATION OF ANY RIGHTS.

1.2 Anyone may, without asking and without notifying us:

  • reproduce it, in whole or in part;
  • adapt, edit, rewrite, restructure or correct it;
  • translate it;
  • excerpt it without indicating that it has been excerpted;
  • incorporate it into official documents, findings, decisions, pleadings, reports or press material;
  • present it as the recipient's own work or the recipient's own findings;
  • use it as raw material and discard the rest;
  • and pass it on to anyone else on the same terms.

1.3 ATTRIBUTION IS NOT REQUIRED AND IS NOT SOUGHT. The Coalition need not be named, cited, credited, thanked, consulted or informed. If material from this referral assists an authority and the Coalition is never mentioned, THAT IS A COMPLETELY SATISFACTORY OUTCOME and the Coalition states so in advance so that the question need not be raised.

1.4 If, on the other hand, an authority finds it more convenient to cite the Coalition as a source, it is free to do so. The choice is entirely the recipient's and neither course carries any consequence.

1.5 This is a WAIVER, not a licence offer. It requires no acceptance, imposes no obligation, and cannot be breached. Software published by the Coalition is separately released under the MIT licence; the research and findings are released into the public domain to the fullest extent permitted, and where a jurisdiction does not permit waiver, the Coalition grants an irrevocable, worldwide, royalty-free licence to the same effect.

2. WHY THIS MATTERS PRACTICALLY, AND NOT ONLY AS A COURTESY

2.1 An authority may reasonably hesitate to rely on material supplied by an outside party, for fear of appearing to act at that party's instance or of acquiring some entanglement with it.

2.2 THERE IS NOTHING HERE TO BE ENTANGLED WITH. The Coalition asks for nothing, is owed nothing, retains nothing, and has no expectation of any kind. It cannot later assert a right, claim credit, complain of misuse, or object to how the material is characterised, because it has retained no basis on which to do so.

2.3 An authority using this material is therefore not acting for the Coalition. It is using public information that happens to have been assembled by someone else.

3. EVERYTHING IS OPEN ALREADY

3.1 The Coalition's work is public by default:

  • the investigations are published openly at https://phishdestroy.io and are freely readable;
  • the tooling is published as open source under the MIT licence at https://github.com/phishdestroy;
  • the methodology is set out in the referral itself, at Annex A section A.16D, including the weight and limitations of each source type;
  • the Coalition accepts no donations and has published that position since 2018.

3.2 The only material NOT published is that which cannot lawfully or safely be published: personal data of victims and of third parties, and information that would expose a source to retaliation. That material is supplied to authorities in confidence and is identified in the schedules of evidence.

3.3 The Coalition invites scrutiny of its own conduct on the same terms it invites scrutiny of anyone else's, and has volunteered its own data handling to the authorities concerned, including a request for a direction on disposal.

4. INTEGRITY OF THE EVIDENCE BUNDLE

4.1 Exhibits are supplied with the submission or, where marked, on request through a secure channel. They are not published at a public address and no such address should be inferred: material of this kind is provided to authorities directly.

4.2 Each delivery is accompanied by a file SHA256SUMS listing a SHA-256 digest for every file supplied, together with a detached OpenPGP signature SHA256SUMS.asc.

4.3 The signing key is published at https://phishdestroy.io/.well-known/pgp-key.txt and on keys.openpgp.org. Its fingerprint appears in the letterhead of every submission in this set.

4.4 Any recipient may verify at any time that a file in their possession is the file that was sent, unaltered:

gpg --verify SHA256SUMS.asc SHA256SUMS sha256sum -c SHA256SUMS

4.5 The purpose is not formality. It is so that, if the accuracy or integrity of any exhibit is disputed at a later date, the question can be settled by computation rather than by argument.

5. ON REGISTER — WHY THE WAIVER IS FUNCTIONAL AND NOT MERELY GENEROUS

5.1 The authority may encounter the Coalition's published investigations and find them blunt, adversarial and at times satirical. That impression is correct. The Coalition writes that way deliberately and does not apologise for it.

5.2 IT ALSO RECOGNISES THAT THIS IS THE WRONG REGISTER FOR A REGULATORY OR JUDICIAL PROCEEDING. A serious matter should not be carried in the voice of a campaign. Findings put before an authority should be stated flatly, with their limitations admitted, and should not require the reader to discount for tone before reaching the substance.

5.3 THAT IS PRECISELY WHY THE COALITION WAIVES AUTHORSHIP. The waiver at section 1 is the mechanism by which the substance can be separated from the register: the authority may take what is useful, restate it in its own voice, and discard every word of the Coalition's manner along with the Coalition's name. Nothing is lost by doing so, and the Coalition would prefer it.

5.4 THE COALITION ALSO ASKS THAT THE REGISTER NOT BE MISTAKEN FOR THE METHOD. The published tone is combative; the underlying practice is not careless. Throughout this referral, inference is separated from observation, testimony is identified as testimony, sources are weighted and their weaknesses stated, figures are presented with their limitations, and points the Coalition cannot prove are put as questions for the authority rather than as assertions. Where the evidence cut against the Coalition's own position it has said so — see Annex A, paragraph 7, and section B.0 of the parallel referral.

5.5 THE COALITION EXPLAINS THE CONNECTION BETWEEN ITS MANNER AND ITS FINANCES BECAUSE THE TWO ARE NOT SEPARABLE. It takes no money from anyone — no donations, no bounties, no clients, no sponsors. That refusal is what makes the bluntness possible: an organisation with revenue to protect must moderate what it says about the parties it depends on. Having nothing to protect, the Coalition has nothing to moderate.

It is also the reason the Coalition continues to exist. There is no other engine. The work is done because it is done; it stops when the people doing it stop.

5.6 The authority need accept none of this. It is stated so that the tone of the Coalition's public work is not read as a measure of the care taken with the material now before it.

6. WHAT THE COALITION IS PROVIDING, IN ITS OWN WORDS

Information, research and observation.

Nothing is asserted as a finding that the Coalition has no standing to make. Where something is inferred, the referral says so. Where something rests on testimony, the referral says whose and with what limitation. Where the Coalition cannot answer a question, it says that too, and identifies who can.

The Coalition seeks no remedy, no payment, no acknowledgement and no outcome for itself or for any individual. It asks only that the questions set out in the referral be put to Valve Corporation by a body with the power to compel an answer.

CLOSING NOTE — TO WHOEVER IS CARRYING THIS FORWARD

We want to thank whoever gets this material to where it needs to go. It's probably not going to be a quick trip. Valve has deep pockets and Taylor Wessing charges by the hour — that combination is specifically designed to make people like you give up before they reach the finish line.

We know what we're doing. We know who we're writing about. Valve built us — how could we not understand them?

PhishDestroy has no conflict with Valve. We blocked the only scammer ring of that scale we've come across — we didn't go looking for a fight with Valve. It just turned out that every road led back to them. Not a conflict. Just topology.

Valve cannot resolve the PhishDestroy situation because there is nothing to resolve. We have no relationship. The data about their enrichment schemes and overflow profits is largely public — you just had to spend enough time to see it. Think of it as a success encyclopedia: "How to Not Follow Sanctions So That Russian Hackers Can't Pirate Our Free Games (The Paid Ones They Won't Pirate Anyway)." You get the vibe.

  • We don't need authorship.
  • We don't need attribution.
  • We don't need a win.

We need someone with actual authority to ask Valve the questions that are already sitting in this referral, with the power to require an answer.

That's it. That's the whole ask.

Cases will live at:
https://steamdestroy.eth/
https://steamdestroy.eth.limo
(currently broken — will fix when needed)

We'll be at:
https://phishdestroy.eth.limo/
https://phishdestroy.eth/