This year has come with a few too many reminders that even verified storefronts like Steam can't fully protect you from malware. Where , a new malware has stolen hundreds of thousands of dollars. One of those worst affected by this latest scheme was someone raising money to fight cancer.
As reported by , a streamer named went live earlier this week, looking to raise $5,000 to fight stage 4 cancer. After being prompted to download a Steam game named BlockBlasters from his chat, he lost $32,000. It turns out, on August 30, that the Steam game had been injected with malware, and upwards of $100,000 was reported stolen by streamers, creators, and crypto owners.
For anybody wondering
what is going on with $CANCER live stream... my life was saved for whole 24 hours untill someone tuned in
my stream and got me to download verified game on @Steam After this I was drained for over 32,000$ USD of my creator fees earned on @pumpdotfun and… pic.twitter.com/8YH4njd46E
broke down how exactly this happened and pointed to the injection of a 'game2.bat' file that was added to the [[link]] game in August. G Data points out this is "a very sobering reminder that malware does real damage to real people and is far more than just some abstract number in some abstract and faraway place."
According to , around 6k users own BlockBlasters, and suggests hundreds had the game installed. Being free-to-play [[link]] (and with an 88% review score before it was taken down this week), it was easy to get access to and being on Steam comes with the implied assurance that the game itself is safe.
A different streamer from them, and another points out that .
A soon came out about the malware, produced by multiple investigators and experts. In it, multiple counterhackers not only linked the malware to specific updates made to the game, but they also noted that contact was made with the hackers via Telegram. The report shows a hacker saying they will send back the money, "which they didn’t and proceeded to nuke everything."
"They will face their punishment in due course," the forensic report warns.
Within a single day, one of the people behind BlockBlasters was found. , one person involved in the reporting, shared that a Telegram was linked to the stolen data, and the Telegram ID of one person involved in making the malware was then linked to "several fraud chatrooms", an advertisement "looking for a video game programmer to make a basic 2D game", and another advert "needing help with some malware stuff."
This same Telegram ID was linked back to photos next to expensive cars and a Linktree with a YouTube, Twitter, and other forms of social media. Another were reaching out to prominent cryptobros to get them to try the game.
⚠️ Urgent https://t.co/2XwOuQcC0z and @Steam warning! ⚠️There is maliscious software hosted by steam. The title below just drained me for $15,000 and god knows what other information from my computer. Please take action daddy Gabe Below i have provide the hackers address… pic.twitter.com/ihaCSpptYt
In this particular case, there is a relatively happy ending. After flagging the problem, RastalandTV was reimbursed for $30,000 from crypto content creator , the hacker was [[link]] identified, and Rastaland will now be able to afford the treatment he was saving towards.
Earlier this year, a free-to-play web 3 game was taken down for containing "" after over 7,000 players downloaded it. It managed to steal people's Steam accounts and even spent money from users' Steam wallets, though it didn't appear to get access to more than that.
Then, in July, an early access survival crafting game named Chemia. The fact that any malware can get onto Steam is certainly worrying, and the fact that so much money can be taken for simply downloading a free-to-play game makes me a tad cautious of game recommendations from strangers going forward. We have reached out to Valve for comment on what more can be done to protect users from malware on Steam.

1. Best gaming laptop:
2. Best gaming PC:
3. Best handheld gaming PC:
4. Best mini PC:
5. Best VR headset:
👉👈