Drooid Logo
Back to story perspectives

Full Breakdown

Malicious Update in Steam Game BlockBlasters Drains $32,000 from Cancer Patient's Crypto Wallet

9/23/2025, 10:15:20 PM

Overview of the Incident

Raivo Plavnieks, a Twitch streamer known as RastalandTV, lost over $32,000 in cryptocurrency after downloading a compromised game titled BlockBlasters from the Steam platform. The game, published by Genesis Interactive, was available from July 30 to September 21, 2025, and had received hundreds of 'Very Positive' reviews. However, a malicious update introduced on August 30 embedded a cryptodrainer component that siphoned funds from users' wallets. The incident came to light during a live fundraising stream for Plavnieks' cancer treatment, where viewers witnessed the theft unfold in real-time.

Technical Details of the Attack

The malware utilized in BlockBlasters was sophisticated, employing a dropper batch script that collected Steam login credentials and user IP addresses, which were then uploaded to a command-and-control server. Security researchers, including Karsten Hahn from GDATA, identified multiple components of the malware, including a Python backdoor and various obfuscated payloads designed to evade antivirus detection. The malicious game was live for nearly a month before being taken down, raising significant concerns about Valve's vetting process for indie games.

Impact on Victims

The attack affected approximately 478 users, with total estimated losses exceeding $150,000 across various accounts. Plavnieks, who is battling stage 4 high-grade sarcoma, had been raising funds through streaming and a GoFundMe campaign, which was at 58% of its goal at the time of the incident. Following the theft, crypto influencer Alex Becker sent $32,500 to Plavnieks to help cover the stolen funds, showcasing a strong community response to the crisis.

Criticism of Steam's Security Measures

The BlockBlasters incident has prompted widespread criticism of Steam's security protocols. Investigators noted that the game had passed Valve's internal checks despite containing malware. The security group VXUnderground highlighted the operational security failures of the attackers, who left their Telegram bot code exposed. This incident is not isolated; similar breaches have occurred with other games on the platform, raising urgent questions about the adequacy of Steam's verification system.

Official Responses and Community Support

In the wake of the incident, the crypto community rallied to support Plavnieks, with his GoFundMe campaign quickly gaining traction. Authorities and cybersecurity experts are collaborating to track the source of the malware, but no legal actions have been reported yet. Valve has not issued a detailed statement regarding the breach, although the incident has sparked discussions about the need for stricter security measures for indie games on the platform.

Verbatim Quotes

  • “For anybody wondering what is going on with $CANCER live stream… my life was saved for the whole 24 hours until someone tuned in my stream and got me to download a verified game on @Steam,” — Raivo Plavnieks, Twitch Streamer
  • “They will face their punishment in due course,” — VXUnderground, Cybersecurity Group

Conclusion

The BlockBlasters incident serves as a stark reminder of the vulnerabilities present on digital platforms and the real-world consequences of cyberattacks. As the community continues to support Plavnieks, the need for enhanced security measures on platforms like Steam becomes increasingly evident.