Monero / decentralised web3 mirror · IPFS · valve.xmr · steamdestroy.eth

VALVE CORP
INVESTIGATION.
NO APOLOGIES.

We bought valve.xmr to preserve the complete, uncensored investigative findings of PhishDestroy. This archive documents Valve Corporation's profits from stolen CS2 / Steam accounts, the Steam Web API key scam, Lolzteam market automation, years of unpatched exposure, GDPR failures by Valve's lawyers, and legal intimidation aimed at security researchers. If the main site goes dark, this copy does not.

9
dossiers
55,597
words preserved
39
evidence images
12
channel posts
18
archived source files
2026-09-11
build date (UTC)
MIT LicensePublic-domain waiverSubmitted to regulatorsNo external requestsEd25519-signed build
Official statement // unregistered rights

Our stance: no apologies

We don't volunteer for you. We protect consumers and regulators from your blatant lies. All our data and findings are released under the MIT license — free to use, distribute, and analyze.

We are not acting in anyone's interest except your deceived clients and the regulators you lie to. We know we are rude and inconvenient, but we don't apologize for exposing billions in stolen funds, the Lolzteam connections, and the reality of your operations.

And let's be honest about scale: we couldn't oppose a corporation if we wanted to. A registrar pocketing someone's Monero, maybe. A company moving billions with a law firm on retainer — obviously not.

We don't have to. We file. Authorities with powers we don't have make the decisions. We waived every right in the material, so any of them can publish it as their own findings, and we couldn't withdraw it if we tried.

There is nothing here to buy and nothing to negotiate. No demands, no deadline, no price. We don't blackmail — that's your lawyers' department, and they're better at it than they are at redaction.

Full text · unabridged · 9 investigations

Dossiers

Investigation

Valve Profits from 70M+ Stolen Steam Accounts

A 15% cut on every stolen skin, $450M in victim liability, COPPA violations and OFAC exposure. Live data on how Valve monetises account theft.

24,669 words·~112 min
Investigation

The Steam API Scam Symbiosis: Deception & Negligence

How the Steam Web API key scam works, why it drains millions of dollars of inventories, and why Valve keeps the mechanism alive.

14,088 words·~64 min
Investigation

Steam Shadow Economy: Pricing, Scams and GDPR

Regional pricing games, outsourced support, the skin-market casino, the CEVA data breach and the GDPR options open to EU users.

3,919 words·~17 min
Malware on Steam

Profit Over Players: The BlockBlasters Cover-Up

Valve let BlockBlasters ship a crypto-drainer through Steam and stayed silent while players lost hundreds of thousands of dollars.

1,677 words·~7 min
Legal / GDPR

Taylor Wessing GDPR Data Breach: How Elite Lawyers Leaked Valve User Data

Part 1. Forensic analysis of the Taylor Wessing GDPR data breach on behalf of Valve: failed PDF redactions by Dr. Patrick Zurheide and Dr. Tobias Schelinski leaked Steam users’ data. English and German.

4,324 words·~19 min
Legal / GDPR

Taylor Wessing GDPR Data Breach (Part 2): The 5-Year PDF Vulnerability Exposing Global Corporations

Part 2. The automated Aspose.PDF pipeline behind Taylor Wessing’s visual-only redactions stayed exploitable for five years, exposing clients such as Pfizer, Just Eat, Chubb, SAP and Valve. English and German.

2,426 words·~11 min
Legal / GDPR

Taylor Wessing GDPR Data Breach (Part 3): The Right to be Forgotten Trap & Academic Repository Evidence

Part 3. How GDPR “right to be forgotten” requests were used to scrub search results about the breach, and why the evidence now lives in academic repositories that cannot be deleted. English and German.

2,125 words·~9 min
Toolkit

The Taylor Wessing Data Breach Toolkit

Templates and procedures for affected users: GDPR requests, regulator complaints and evidence preservation.

891 words·~4 min
Roadmap

Valve Profits from Stolen Accounts: The Trilogy (Roadmap Part II)

What PhishDestroy publishes next on Valve, in what order, and why nothing in it is for sale.

1,478 words·~6 min
Telegram channel log · 12 posts · 14 Aug 2026 → 08 Sep 2026 · verbatim

Dispatches

Open channel ↗

Posts are reproduced exactly as published in the channel, including tone and typos. The raw export is archived as raw/telegram-dispatches.txt.

@PhishDestroy Alerts#01

If the laws where you live mandate alternative dispute resolution options, you may seek a remedy under those options. If you are a consumer who lives in Russia, you may also seek a remedy with local Russian state courts.

Show the full post

You agree to comply with all applicable import/export laws and regulations. You agree not to export the Content and Services or Hardware or allow use of your Account by individuals of any terrorist supporting countries to which encryption exports are at the time of exportation restricted by the U.S. Bureau of Export Administration. You represent and warrant that you are not located in, under the control of, or a national or resident of any such prohibited country.

Steam has rewritten the terms of service, and I really like the part about “we submit to the jurisdiction of any court in any country”—and how gently we shift the responsibility onto the user—the user now decides for themselves whether they’re a terrorist, or if it’s just a payment or IP check—well, they say, “decide for yourself.”

Well, we always knew this moment would come, Phishdestroy — Steam and their anti-phishing measures were created, and we think it’s either they kill us or we kill them—the game has begun—it’ll be available soon—and yes, we have a lot of information, ranging from their employees to direct data, for example, why there’s a mention of Russia, how long they’ve been integrating government services, and how they carry out orders from government agencies in a terrorist country - Yeah, we understand that this might be our last honest review of a platform that thinks it gets to write the laws—and not the other way around—if it comes to that, we don’t give a shit, and we’ll inflict damage; it’s inevitable, and Namesilo and Steam, especially, will feel the weight of Phishdestroy, even if Steam kills it - It gave birth to it, so let it kill it, but it seems I’m about to pull off a billion-scale integration🤩🤩🤩

Soon.. steamdestroy.eth

permalink
@PhishDestroy Alerts#02

I would tell you how Valve simply took documents with poorly redacted PDFs and handed them over to a wealthy and extremely aggressive individual, effectively exposing the personal data of 1,000+ children from Russia to someone from Ukraine. This account was blocked for political reasons, and frankly, I am surprised—well, unless he didn't use the data for anything other than user profiling. But if he had, Valve would have felt the weight of responsibility for the lives they handed over. And yes, they never notified anyone that they leaked this to a resourceful individual, exposing thousands of kids who had been spamming him with reports, death wishes, and toxic comments.

Show the full post

However, our actual investigation will be about something else entirely. We will expose the reality of Steam’s support structure: agent corruption, direct financial benefits from gambling, the protection of Lolzteam, and, of course, their cooperation with Roskomnadzor. We are convinced that Valve has lost its mind and that we are forced to do what we must.

PhishDestroy’s introduction to Steam happened around 2018 when we sent support a list of phishing domains, only to be told: "Send one more link and your account gets banned." That is pretty much how they created us.

As for the data leak mentioned above, it wasn't just Valve acting alone—it was handled by expensive corporate lawyers charging 1,500 euros an hour. Taylor Wessing, for the record—great lawyers, the kind companies only hire when they are absolutely, 100% not guilty.

permalink
@PhishDestroy Alerts#03

I know that Law and GDPR are usually very serious topics, but I was re-reading the Valve case files before bed, and I just couldn't stop laughing. Realizing how much money Valve paid for the absolute disaster that is about to hit them... I couldn't resist writing a slightly more "fun" and ironic article for our Medium. 🐕‍🦺
Just a quick reminder: Taylor Wessing is a top-tier international law firm. They defend giants like Pfizer. They act like a highly prestigious hospital where everyone has a "Dr." prefix, charging astronomical hourly rates.
But here is the absolute funniest detail we realized while looking at their leaked documents: to censor the 830-page PDF, they didn’t use a bulk tool or even copy-paste the black squares. They manually drew a new square on every single page.
Hundreds of billable corporate hours spent on digital arts and crafts... just to forget to delete the text underneath them anyway. 🤦‍♂️
Read the full story of how my dog proved to be a better Data Protection Officer than a Doctor of IT Law 👇
🔗 https://phishdestroy.medium.com/my-dog-vs-elite-gdpr-lawyers-the-valve-data-breach-nobody-is-talking-about-f6f7683d813d

Show the full post
permalink
@PhishDestroy Alerts#04

📎Security Advisory: Verifying Improper PDF Redactions in Legal Documents

Show the full post

Overview Recent technical analysis confirms that certain top-tier law firms continue to use fundamentally flawed methodologies for redacting sensitive information in legal PDFs.

Instead of correctly sanitizing the document and deleting the underlying text layer (BT/ET operators), some organizations use outdated software to simply draw black vector rectangles (re/f operators) over text coordinates. This creates a purely cosmetic mask, leaving the raw, highly sensitive data 100% intact and readable beneath it.

Action Required If you or your company have ever received "redacted" PDF documents from 🎓Taylor Wessing or absolutely any other legal counsel, we strongly recommend auditing these files. We certainly hope there are no other "specialists" of this caliber left in the legal tech industry, but it is very easy to check and verify for yourself.

⚡️ No-Install Lifehacks (The Easiest Ways to Check) You don't necessarily need specialized software to expose this vulnerability. Try these basic tricks using just your web browser (Chrome, Edge, Firefox):

The "Select All" Hack: Open the PDF in your browser and wait for the file to load completely (browsers render text layers dynamically). Press Ctrl+A (Select All), then Ctrl+C (Copy), and paste it (Ctrl+V) into a plain Notepad. If the redaction is fake, the "hidden" text will simply paste along with the rest of the document.

The "Blind Search" Hack (Ctrl+F): Even if you don't know what is hidden under the black box, you can test if the text layer exists. Let the PDF load, press Ctrl+F, and search for extremely common characters based on the expected data type. For example, search for the vowel "a" (for names/text) or the number "1" (for financial data/dates). If the browser registers a hit and highlights the black redaction box (or the invisible space beneath it) — the text layer is still alive and the redaction has failed.

How to Check Visually (Safe Offline Software) To actually see and remove the vector shapes, use trusted, official open-source software:

LibreOffice Draw (Official: libreoffice.org) — Open the PDF, click the black box, and press Del
Inkscape (Official: inkscape.org) — Import the PDF and delete the vector masks covering the text.
Adobe Acrobat Pro — Use the "Edit PDF" tool to move or delete the black shapes.

⚠️WARNING REGARDING ONLINE TOOLS Do NOT upload sensitive legal documents to random online PDF editors (like ilovepdf, smallpdf, or "PDF unlockers"). By uploading confidential files to third-party servers, you might be committing a data breach. Only use local, offline software or the browser-based lifehacks mentioned above.

✨ Upcoming Update Manually checking hundreds of pages can be tedious. In an upcoming update to this post, we will release a standalone script and a 100% client-side web tool. This tool will run entirely locally in your browser (no data will be uploaded to any server) to automatically scan PDFs and detect if they contain fake vector-mask redactions.

https://github.com/phishdestroy/taylor-wessing-data-breach-toolkit
https://phishdestroy.github.io/taylor-wessing-data-breach-toolkit/

⚠️ Disclaimer This information is provided strictly for defensive auditing, risk assessment, and educational purposes. You are responsible for complying with your local data privacy laws (GDPR, etc.) and reporting any discovered breaches to the relevant authorities.

permalink
@PhishDestroy Alerts#05

Hey, corporate attack dogs.🐕💰

Show the full post

We are your target, not the companies. Why did you leak the data of the very corporations you were supposed to protect?

We just dropped Part 2 of our investigation into the "elite" lawyers at Taylor Wessing. We proved it: the 830-page Steam data leak wasn't a one-off manual mistake by a single lawyer. It is an automated, systemic, firm-wide catastrophe.

To save money on proper software, they spent years running documents through a flawed script that only visually masked the text with vector shapes, leaving the raw, highly sensitive data completely exposed underneath.

Now we have one question for their corporate clients: how safe is your data? If Taylor Wessing has been doing this since 2019, the blast radius goes far beyond Valve. The highly confidential documents of giants like Pfizer, Just Eat, SAP, and Chubb Insurance are now in the impact zone. They paid for protection, and got exposed instead.

They tried to threaten us with the criminal code, and ended up shooting their own clients in the foot. Inside the article: proof of the vulnerability, a breakdown of their cheap software, and instructions on how to check any documents they’ve ever sent you.

👉 Read https://phishdestroy.medium.com/my-dog-vs-elite-lawyers-part-2-the-5-year-pdf-vulnerability-exposing-global-corporations-81cdad269253

Good boy. 🐾

permalink
@PhishDestroy Alerts#06

A quick IT Security lesson for "Elite" Corporate Lawyers.

Show the full post

Let’s talk about the metadata we extracted from your hilarious 830-page GDPR response.

Your batch script left a permanent footprint: Aspose.PDF for .NET 20.8.
For those not billing €1,500/hour, let us translate: you are processing sensitive user data through a PDF generator from August 2020.

Do you "Doctors of IT Law" even realize what you’ve exposed yourselves to?
Version 20.8 has publicly known RCE (Remote Code Execution) vulnerabilities. Your automated script blindly parses raw, unescaped Steam data to draw those cute black rectangles over it.

⚠️Disclaimer: The flowchart below is NOT a tutorial or an instruction manual. It is a visual threat model demonstrating a critical architectural flaw. We are publicly warning you about the danger.

The Threat Model:
A malicious payload injected into a Steam username, a chat log, or a support ticket. Your 5-year-old, unpatched software processes that text to generate the PDF... and boom.
Their software -> Our payload.

This is a very dangerous game. Now that your exact backend version is public knowledge on GitHub, every blackhat sees your infrastructure as an open door.

We know that a standard GDPR request handled by Taylor Wessing takes months of bureaucratic ping-pong. We sincerely hope that buying and deploying the 2026 software update takes you a bit less time. Stop charging Valve millions while being too cheap to renew a license you bought in 2020.

Go patch your servers. You’re welcome. 🫵

https://github.com/phishdestroy/taylor-wessing-data-breach-toolkit

permalink
@PhishDestroy Alerts#07

🦖For now, we are looking for allies for a big bonfire, Taylor Wessing, but do we understand correctly that you are defending russia's interests again? Alright, we'll talk about that through the media.

Show the full post

🔍🔎The bonfire will be massive and bright, because just from the first part, we have already found a critical vulnerability and reviewed the documents written by Taylor Wessing. Well, you'll hear the opinions of the targeted journalists later. Perhaps you shouldn't have passed the case from one lawyer to another, or maybe Patrick should have read what you wrote earlier. You completely contradict yourselves there, and if you look at Valve's responses, it turns out you are saying they are lying. In short, an "Elite" law firm.

🔥This is just the beginning. We are collaborating with and distributing all the information to journalists and regulators. Join us if you want a bonfire of hypocrisy, snobbery, lies, intimidation, and cowardice.
🕷️And even if you just don't like them, write to us—we'll provide you with more information, or if you'd like to request GDPR-related information from the corporation that operates the circus—or if you're already familiar with the clowns

✅Contact us at [email protected]

⚔️P.S. I am not exaggerating. Many people write to me saying no, they don't feel sorry for them. You just haven't seen what they were doing, in whose interests, and what they wrote in response to a standard GDPR request—and these people are still teaching in universities for now...

permalink
@PhishDestroy Alerts#08

Since we know that the geniuses from Tyler Wessing want us to leak the documents — well, the ones they leaked themselves — well, that would be stupid, we aren't brain-dead. But yes, regarding the Tyler Wessing documents — this reveals the fact of the data collected by Steam and so on, as well as an analysis of their emails. So, did we hand the documents over to some free AI? No, we handed them over to the regulator, and it's possible Anthropic Claude Mythos was used here.

Show the full post

https://gist.githubusercontent.com/phishdestroy/84fdd67165ee7544a2443bf887cac924/raw/a10006688f59f4351a47f321cf5c0090b282daa8/gistfile1.txt

The analysis response was not edited — it clearly shows what Valve collects, and this data is held by those outsourced support teams which we will discuss later. Now think about it: is the refusal to restore your account because you don't have the key they want just an excuse or not?)

Yes, we know that Tyler Wessing uses not the law for their actions, but an inflated ego and a God complex. I think this is a clear answer as to why we used a closed AI and a regulator?

This is not blackmail — it is openly bringing to accountability those who, for some reason, think they are above the law and can get away with anything. And yes, we are not you, we perfectly understand why we cannot leak the data openly — no, not because it contains children's data (the corporation doesn't give a fuck about that) — but because in the margins of the letter is their Name, a logo that is strictly their trademark. But yes, in case of attempts to pressure us, IPFS won't give a fuck whose trademark it is, got it?

Attack, you 🐕, we are waiting. Looks like 72 hours have passed, but it's the weekend — we'll submit it on a timer anyway — we do love automation. Patrick, thanks for the reply — we wrote in German so you could prove 1 theory, but yeah, we knew you speak English.

permalink
@PhishDestroy Alerts#09

🚨 Valve, the clock is ticking. The countdown to global exposure has begun.

Show the full post

On August 31 at 13:37, a comprehensive dossier of internal logs and technical evidence regarding Valve's lies and complicity in trade hijacking (offer substitution) will be dispatched to 18 global regulators, including the FTC and the European Commission.

‼️We gave them 7 days to publicly refute our technical claims, but they won't be able to. The dispatch of these packets is inevitable.

The Truth: With the unintentional "assistance" of Valve’s own external lawyers (Taylor Wessing👋), we now possess irrefutable proof. Steam is deliberately facilitating the theft of users' in-game items.

👻Valve’s standard excuse is a blatant lie. A child never creates or hands over an API key. These keys are generated silently by hackers exploiting Steam's maliciously designed architecture, operating under Valve's full visibility. You simply cannot fail to notice 7 straight years of massive, automated theft. This isn’t a bug; it’s a conscious business decision.

👾We will not give Valve another 7 years to foster a cybercriminal ecosystem. We will no longer allow the money of innocent children to sponsor international cyber-syndicates and terrorism.

⚡️The system is configured, and the evidence is packed for August 31. But make no mistake — this is not the end. This is just the beginning. We have many more ongoing investigations and massive amounts of information yet to be revealed. Stay tuned. ⏱️

Read the full manifesto and technical breakdown here:
🚀 https://phishdestroy.io/steam-api-scam-exposed

#Steam #Valve #Phishdestroy #CyberSecurity

permalink
@PhishDestroy Alerts#10

💩 WE ARE CUTTING CONTACT WITH SOURCE 1

Show the full post

From the outset Source 1 had no role in this investigation and no editorial
voice in it. He accepted that in writing. He has nonetheless been commenting
on the case and using internal material from our chat.

From today: contact ended, access to our data closed.

The material he provided stays. Obtained lawfully, valuable, already filed.

Why now. Valve's counsel exposed to him the identities of other users — some
of them children — after telling him those users were the reason his account
was gone. Valve's own gateways then read the public account of that exposure
four times over ten months, and Valve told no one. We have since spoken with
one of those users: it was that person's parents who alerted Valve to the
restricted page in the first place.

So there is an open question about a possible offence against minors, and
about whether Valve knew and concealed it. While it is open we cannot be
associated with him, and we cannot advance his interest against the company.

This is not about trust. The standard is evidence, and we do not have it
either way. Given the data was handed to him right after he was told those
users caused his loss, we cannot conclude by logic that he did nothing. Nor
that he did.

Until it is refuted, Source 1 and Valve Corporation occupy the same position
in our eyes.

The refutation is available: polygraph, any licensed examiner, any
jurisdiction, at our expense — was the data used to deanonymise anyone, was
anyone paid, was pressure or contact applied to those users or people around
them. Fourteen days. If he clears it we publish that as loudly as this.

More than Valve has offered anyone it has banned.

This is not friendly fire. The objective has to be reached, and he understands
that better than anyone.

— PhishDestroy

permalink
@PhishDestroy Alerts#11

Dr. Zurheide exercised the right to be forgotten, but he is no private citizen — the game has begun.

permalink
@PhishDestroy Alerts#12

We can pretend that Valve developers are too cool and supposedly weren't monitoring the situation before we got involved, but why did you visit the Source 1 website after the New York case started? But it's cool that you're sensing a real threat—and I don't think it's a false alarm. We aren't going to write anything until the release of the 2nd part; we can't be bothered. Going on about how your employees use Graphene OS (thinking it's a separate OS) and use TOR, thinking they're so cool—maybe we could, but I'm too lazy. Especially since you're playing dumb and pretending you don't see anything. But don't worry, on our website, even Google Analytics anonymizes IPs.

Show the full post

As for the cover-up—it wasn't a traffic leak; it was a fuck-up by the lawyers and the concealment of a user data leak, which put minors at risk. It's amusing that you chose to hide it. You think skins have no value, but I remember one precedent. Just across the bridge from your office, there was already a case like this. Someone there also thought they were the smartest in the room and that sanctions didn't apply to them. As the saying goes, '4'

permalink
Verify, don't trust

Integrity & provenance

Content-addressed

On IPFS the address of this site is the hash of its contents. If a single byte changes, the address changes. Any gateway or node returns byte-identical files for the same CID.

Raw sources archived

Every rendered dossier sits next to its unmodified source in raw/: the original HTML from phishdestroy.io, the Medium feed payload, the Telegram export, and plain-text and Markdown variants where they exist.

SHA-256 manifest

manifest.json lists every file with its SHA-256. Manifest digest: 5bfb52534a1b868450455a7f6e1d1bfd…

ipfs get <CID> -o valve-mirror
cd valve-mirror && sha256sum -c SHA256SUMS
Ed25519 signature

SHA256SUMS and manifest.json are signed. Public key: pubkey.pem, fingerprint be7dc02ea086de41d868e18df3a44f8e…. Confirm the fingerprint through a second channel (phishdestroy.io, the Telegram channel, an ENS text record) before trusting it.

openssl pkeyutl -verify -pubin -inkey pubkey.pem -rawin \
  -in SHA256SUMS -sigfile SHA256SUMS.sig
Zero dependencies

No CDN, no third-party fonts, no analytics, no scripts that phone home. The page renders identically from any IPFS gateway, a local node, or a USB stick. Machine-readable copies: llms.txt, llms-full.txt, Atom feed, sitemap.xml.

Legal

MIT License & public-domain waiver

Copyright (c) PhishDestroy & the valve.xmr independent archive

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Materials"), to deal in the Materials without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Materials, and to permit persons to whom the Materials are furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Materials.

THE MATERIALS ARE PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE MATERIALS OR THE USE OR OTHER DEALINGS IN THE MATERIALS.

Public-domain waiver: to the extent permitted by law, the authors additionally waive all copyright and related rights in the Materials (CC0-style), so that journalists, regulators and users can republish them without attribution or permission.