The FBI issued an official alert on March 11, 2026: Steam Malware were hidden in seven games to steal your credentials, banking data, and crypto wallets. Affected players are invited to report directly to the federal agency via a secure form.
Seven games, one suspect
The Seattle division of the FBI identified seven titles distributed on Steam between May 2024 and January 2026 as carrying malware: BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi, and Tokenova. What's striking about this case is the explicit mention in the press release published on single actor in the press release published on FBI.gov : the agency believes these seven games were all designed or compromised by the same person or group, suggesting a coordinated campaign rather than a series of isolated incidents. Valve has confirmed its cooperation with federal authorities and sent direct notifications to some affected players, many of whom initially mistook these messages for phishing before realizing they were authentic.
An unprecedented method: striking via the update
What distinguishes this campaign from typical attacks is the technique employed. BlockBlasters was released on July 30, 2025, without any malicious code, thus passing all of Valve's checks and antivirus scans. A month later, on August 30, a silent update injected a cryptodrainer component into the game without triggering any alerts: antivirus programs do not re-scan a file they have already validated, and players who already had the game installed trusted a title they were familiar with. According to information reported by games.gg, the identified malware belongs to the StealC family, capable of collecting passwords, autofill data, session cookies, and crypto wallets, while also modifying Microsoft Defender settings to avoid detection. BlockBlasters had nevertheless been flagged as suspicious by SteamDB a week before the incident, but Steam did not react quickly enough.
RastalandTV, victim live
BlockBlasters became the emblematic case of this entire affair. Raivo Plavnieks, a Latvian streamer known by the alias RastalandTV, downloaded the game on September 21, 2025, during a Twitch stream organized to fund his treatment for a stage 4 cancer. In a few minutes, $32,000 disappeared from his crypto wallet before the eyes of his viewers. The streamer reacted publicly by writing on X: "My life was saved for 24 hours, until someone in my stream led me to download a verified game on @SteamSteam." ("my life was saved for whole 24 hours until someone tuned in my stream and got me to download verified game on @Steam*. ". According to Kotaku, the scammers behind BlockBlasters had cynically stated in their private exchanges that RastalandTV "is recovering in a few hours," a phrase that amplified the indignation of the online gaming community. In total, according to the FBI's press release, 261 Steam accounts were affected for a estimated damage of $150,000.
Damage that lasts after deletion
Valve removed these titles from the store as soon as they were reported. PirateFi, for example, was detected in February 2024 and quickly removed. But the removal of a game does not neutralize the data already stolen: authentication tokens, session cookies, and exfiltrated credentials continue to circulate on black markets, sometimes resold or reused months after the initial incident. The FBI specifies in its press release that victims of infostealer expose themselves to prolonged risks on their email accounts, their gaming platforms, their digital wallets, and all services sharing the same credentials. With 132 million monthly active users on Steam in 2025, even a tiny contamination rate potentially represents thousands of exposed individuals, many of whom are still unaware they have been affected.
How to report and protect yourself
If you installed any of the seven games listed between May 2024 and January 2026, the FBI urges you to report it as soon as possible. The form is accessible directly on FBI.gov, and an email contact is available at [email protected]. All identities communicated will be treated confidentially, and victims may benefit from financial restitution under U.S. federal law. Here are the steps to follow if you think you are affected:
- Check your Steam download history to identify one of the seven suspicious titles.
- Immediately change the passwords for your Steam, messaging, and crypto wallet accounts.
- Revoke active sessions and authentication tokens on your online services.
- Report yourself to the FBI via the form at FBI.gov or by email at [email protected].
- Enable two-factor authentication on all your sensitive accounts.
This case highlights a structural flaw in Steam's validation process: a game can be published clean, accumulate positive reviews, and then be compromised via an update without any automated mechanism detecting it. Valve has not yet specified whether changes to its verification procedures are planned to fix this vulnerability. Pending an official response from the company, the most basic precaution is to only download games from recognized studios and to closely monitor your account activity after each new installation.



No comments yet — start the discussion!