Twitch streamer raising money for cancer treatment has funds stolen by malware-ridden Steam game — BlockBlasters title stole $150,000 from hundreds of players

Bitcoin, Ethereum, and other cryptocurrencies as physical coins, because that's more tangible or something
(Image credit: Shutterstock)

It has been 0 days since the Steam marketplace has been used to deliver malware to unsuspecting gamers who download titles from Valve's long-running platform.

Twitch streamer Raivo "RastalandTV" Plavnieks said on Sept. 30 that over $32,000 worth of cryptocurrency—which had been donated to him to help pay for cancer treatments—was stolen after he installed a Steam game called "BlockBlasters" when someone in his stream chat recommended it to him.

Follow Tom's Hardware on Google News, or add us as a preferred source, to get our up-to-date news, analysis, and reviews in your feeds. Make sure to click the Follow button!

Nathaniel Mott
Freelance News & Features Writer

Nathaniel Mott is a freelance news and features writer for Tom's Hardware US, covering breaking news, security, and the silliest aspects of the tech industry.

  • vanadiel007
    For Valve it's all about revenue.
    There are many games on their platform that use the "early access" method, generate revenue and then stop development but keep the money.

    I have a whole bunch of early access games in my library that are non-functioning. Never see your money back...
    Reply
  • RxBrad
    Call me a skeptical a-hole, but "Twitch streamer raising $32k in cr y pto" was the first red flag I saw.

    I feel like we haven't heard the entire story.

    (Heck, even Toms moderation thinks it's shifty, because I had to censor my comment to post it)
    Reply
  • DS426
    vanadiel007 said:
    For Valve it's all about revenue.
    There are many games on their platform that use the "early access" method, generate revenue and then stop development but keep the money.

    I have a whole bunch of early access games in my library that are non-functioning. Never see your money back...
    Yeah, this appears to be a very popular business model at this point. PlayWay for example has put out dozens of these games. Develop the games just long enough to get some reviews, community chatter, etc. to get the title noticeable, and then move on to something else.

    As for the topic of malware-infused games on Steam, I'm actually surprised this isn't a bigger issue. As I say that, I'm sure there's a handful of games that have injecting info stealers. Those are types of malware that are notoriously hard to detect. Valve doesn't evaluate every line of code; anyone thinking that Valve can completely prevent Steam games for being malware-infused don't have a sufficient grasp of computer security.

    As the article mentioned, I don't think there' s a "Steam-verified" badge for games, just verification for things like compatibility with the Steam Deck.
    Reply
  • jlake3
    "This is appalling levels of vetting," the researchers who investigated this incident said. "How can you let such brazen malware exist on your platform?"
    This is part of the double-edged sword to the opening up of Steam back in 2017 through “Steam Direct” (although problems were already starting to show under the earlier “Steam Greenlight” program). People had been complaining about upstart indie studios and solo devs being shut out from Steam’s growing market for lack of resources and connections, and how unfair they thought it was for indie games to be judged on quality when big studios put out some buggy, derivative games without having to prove their worthiness. As a result Steam lowered the barrier to entry to almost zero and opened the floodgates, and the system has been hammered with asset flips and scams ever since.

    If malware is added in a patch rather than the initial submission, isn’t in an existing database, and only triggers if a wallet program or cookies from a crypto site are present on the victim machine (which a test machine likely wouldn’t have), I can see how it would skate through. Support should have probably acted faster, but the number is small compared to the scope of Steam and I imagine not everyone made the connection and had the evidence to back it up.
    Reply