FBI arrested a 21-year-old after he ordered Uber Eats. The trail started with 80 stolen wallets and a game called PirateFi on Steam. Seventeen thousand downloads. Eight malicious games. One centralized review process that allowed updates to bypass scrutiny. This is not a smart contract exploit. This is a platform trust fracture.
Steam is the largest PC game distribution platform. Millions of users download games daily, trusting Valve's review process. In early 2026, attackers published PirateFi and seven other titles, each carrying the Vidar infostealer. The malicious code waited. Once a user launched the game, it scraped browser-stored passwords, session cookies, and cryptocurrency wallet files. Attackers then emptied wallets via authorized transactions, tricking victims into signing malicious intents.
Context: The attack chain is elegant in its simplicity. Attackers identified high-value wallet holders through automated bots—scanning Discord, Telegram, and X for public addresses or boasts of large holdings. They then privately messaged targets with a link to a "new exclusive game" on Steam. The platform's review process gave it legitimacy. But Valve's documentation reveals a critical gap: initial builds are reviewed, but subsequent updates can be deployed without re-review. Attackers uploaded a clean game, then after approval, pushed an update containing Vidar. This is a classic “Trojan horse” distribution mechanism, modernized for the gaming world.
Core Teardown: Let's dissect the technical failure. Vidar is a commodity infostealer, available for purchase on underground forums. It specifically targets browser-stored data and wallet files. The attack's novelty is not the malware but the delivery method. Valve's review pipeline functions as a single point of trust. Once that trust is granted, all subsequent updates are assumed safe. This is a structural impossibility—no manual review can scale to keep pace with thousands of updates. The attackers understood this. They used the platform's reputation as a force multiplier. The FBI recovered $220,000 across approximately 80 wallets, but the full damage is unknown. Over 8,000 unique installations were recorded across the eight games.
From my audit experience, I have seen this pattern before: centralized platforms granting implicit trust to actors they cannot verify. In the Ethereum Classic fork, exchanges assumed replay protection would be optional. Here, users assumed Steam would protect them. Both assumptions were flawed. The attackers’ operational security was equally flawed. They converted stolen Bitcoin into Uber Eats gift cards via Bitrefill. The delivery address tied directly to the suspect. This is where the irony deepens: blockchain’s transparency, intended for trustless verification, became the forensic tool that dismantled the attackers’ anonymity.
Contrarian Angle: The bull case for this attack format is that it is a one-off, quickly patched. Valve will adjust its update policy, and users will learn. But I argue the opposite. This event exposes a deeper structural weakness: the asymmetry of trust. Centralized platforms are incentivized to minimize review friction for legitimate developers. Attackers exploit this friction gap. The same vulnerability exists on mobile app stores, browser extensions, and even GitHub releases. Furthermore, the perception that blockchain transactions are anonymous is stubbornly persistent. This case proves that any on-chain activity linked to off-chain services (like food delivery) creates a traceable chain. The contrarians who argue that crypto provides anonymity are wrong; it provides pseudonymity, which breaks the moment you touch a regulated service. The real blind spot is not the technology but the human behavior of converting crypto to fungible assets.
Takeaway: This is not the last time we will see a Steam-style attack. The economics are too attractive. Expect copycats targeting competing platforms: Epic Games Store, GOG, even Discord’s own game distribution. The only mitigation is a fundamental shift in user behavior. Treat every downloaded executable as a potential exploit. Use hardware wallets with separate transaction approval. And never assume a platform's review process replaces your own due diligence. Hype burns hot; logic survives the cold burn. I do not fix bugs; I reveal the truth you hid. Every gas leak is a story of human greed. This story is no different.