Particle.news

Download on the App Store

Steam Pulls 'BlockBlasters' After Malware-Laced Update Drains About $150,000 in Crypto

Researchers say an August 30 update added a cryptodrainer that was pushed to crypto holders through targeted outreach on X.

Overview

  • Latvian streamer Raivo “RastalandTV” Plavnieks lost about $32,000 during a charity broadcast, a loss later covered by a $32,500 transfer from crypto influencer Alex Becker.
  • The free-to-play platformer appeared on Steam on July 30 with hundreds of “Very Positive” reviews and was removed around September 21 after the reports surfaced.
  • Estimated theft totals hover around $150,000, with victim counts ranging from 261 accounts (ZachXBT) to 478 usernames listed by VXUnderground.
  • Forensic analyses describe a dropper batch script, a Python backdoor, and a StealC payload exfiltrating Steam credentials, IP data, and crypto wallet information to a command-and-control server.
  • Valve has not issued detailed public comment as of publication, and researchers advise anyone who installed BlockBlasters to reset Steam credentials and move funds to new wallets.