Market Prices

BTC Bitcoin
$62,985.2 +0.07%
ETH Ethereum
$1,854.8 -0.60%
SOL Solana
$72.53 -0.73%
BNB BNB Chain
$576.2 -2.11%
XRP XRP Ledger
$1.07 +0.25%
DOGE Dogecoin
$0.0696 -0.63%
ADA Cardano
$0.1754 +3.79%
AVAX Avalanche
$6.22 -2.77%
DOT Polkadot
$0.7918 +3.97%
LINK Chainlink
$8.15 -0.51%

Event Calendar

{{年份}}
12
05
halving BCH Halving

Block reward halving event

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

28
03
unlock Arbitrum Token Unlock

92 million ARB released

18
03
unlock Sui Token Unlock

Team and early investor shares released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0xa90a...3a4d
Institutional Custody
+$2.6M
78%
0x30b2...e99b
Market Maker
+$1.9M
89%
0x5948...97a3
Experienced On-chain Trader
+$3.7M
83%

🧮 Tools

All →
Guide

The Steam Backdoor: How Vidar Infostealer Exploited Platform Trust to Drain Crypto Wallets

StackShark
Eight games. Zero wallets safe. In February 2025, the FBI arrested 21-year-old Zyaire Wilkins for operating a malicious game distribution network on Steam. The damage: $220,000 in stolen crypto, 80 wallets compromised, 8,000 infected devices. The vector was not a flash loan or a DeFi exploit. It was a game called PirateFi, carrying the Vidar infostealer, that bypassed Steam’s review process because its initial build was clean. The ledger never lies, only the interpreter does. PirateFi appeared as a standard free-to-play title on the world’s largest PC gaming platform. Users downloaded it, launched it, and the malware silently extracted browser credentials, session cookies, and crypto wallet files. The attackers did not stop there. They deployed bots on Discord, Telegram, and even LinkedIn to identify high-value targets, then sent personalized messages directing them to the game. This was not random spray—it was a surgical strike. The core mechanism deserves full deconstruction. Valve’s documentation for Steamworks states that "initial builds are reviewed by a moderation team, but subsequent updates can be submitted without further approval." This single sentence is the vulnerability. The attackers submitted a clean PirateFi build. Once approved, they pushed an update containing Vidar—a well-known infostealer that has been circulating since 2018. No additional review occurred. The platform’s trust model became the attack surface. On-chain data tells the rest. The stolen funds—primarily Bitcoin—moved through a series of addresses before hitting Bitrefill, a service that converts crypto into gift cards. The attacker purchased Uber Eats vouchers and used them for deliveries tied to an address linked to Wilkins. The blockchain’s transparency made the trail undeniable. Whales don’t swim in shallow waters; but bait can lure them into a current. Here, the bait was a free game, the current was an automated theft pipeline. Based on my experience auditing the Parity Wallet multisig contract in 2017, I learned that a single exploitable function can unlock millions. That bug was in code. This bug is in process. The Parity incident taught me to verify every assumption about permission boundaries. Steam assumed the developer would not weaponize an update. The attacker proved that assumption wrong. The financial outcome—80 wallets at $220,000—is small by crypto standards, but it is a proof of concept. What happens when the target is a high-frequency trading firm’s hot wallet instead of individual gamers? The contrarian angle cuts against two popular narratives. The first: “Blockchain is anonymous.” This case demolishes that. The FBI tracked a 21-year-old in his bedroom through a pizza delivery. Correlation is a whisper; causation is the shout. The second narrative: “Hardware wallets are invincible.” They are not. The malware captured browser-stored keys and clipboard data during transactions. If a user had a hardware wallet but signed a blind approval, the result is the same. The attacker’s internal discussions, revealed in the complaint, explicitly strategized about how to trick users into authorizing malicious smart contract interactions. Social engineering circumvents hardware security. This blind spot extends beyond individual users. The industry’s focus on DeFi exploits and bridge hacks has ignored the supply chain risk of gaming platforms. Steam hosts over 100,000 games. If even 0.01% carry malware, that is ten active attack vectors. The Telegram channel where the attackers coordinated shows they viewed this as a scalable business. They even discussed purchasing malware variants that specifically target Atomic Wallet and MetaMask injection points. In the absence of noise, the signal screams. The signal is clear: platform security trust is the weakest link. The review process is a gate, not a wall. Every update is a potential bypass. The attacker did not need zero-day exploits. They used a standard infostealer and a free-to-play template. The cost of entry for this attack was near zero. The return, for an individual, was enough to fund real-world spending via Uber Eats. The takeaway for users is stark. Treat every downloaded executable as an unknown entity, even from “trusted” stores. Run game installs in isolated environments—virtual machines or dedicated hardware. Never store private keys on the same device used for gaming. For transaction signing, use a hardware wallet that displays the exact payload, and verify it against a known safe source. The attacker’s success depended on users who clicked “approve” without reading. The next campaign will target decentralized app browsers or mobile game stores. The pattern repeats. For the industry, this is a call for process audits. Valve must implement continuous review, not point-in-time checks. The cost of re-inspection is trivial compared to the reputational damage. Other platforms will follow, only after they are burned. The ledger never lies, only the interpreter does—and the interpreter here is the update policy. Expect the FBI to announce more victims in the coming weeks. Expect copycat attacks on other distribution platforms. The modus operandi is already documented on darknet forums. The only defense is a mindset shift: cure ignorance with skepticism, replace trust with verification, and let the data—not the platform—be your final authority.

The Steam Backdoor: How Vidar Infostealer Exploited Platform Trust to Drain Crypto Wallets

Fear & Greed

27

Fear

Market Sentiment

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$62,985.2
1
Ethereum ETH
$1,854.8
1
Solana SOL
$72.53
1
BNB Chain BNB
$576.2
1
XRP Ledger XRP
$1.07
1
Dogecoin DOGE
$0.0696
1
Cardano ADA
$0.1754
1
Avalanche AVAX
$6.22
1
Polkadot DOT
$0.7918
1
Chainlink LINK
$8.15

🐋 Whale Tracker

🔴
0xf4d2...c1e8
3h ago
Out
1,256.10 BTC
🟢
0x11a8...60e0
6h ago
In
204,369 DOGE
🔵
0x551f...3f3b
1h ago
Stake
30,092 BNB