Steam game BlockBlasters steals $150,000 from 261 users
Summary
Hide β²
Show βΌ
A verified Steam game named BlockBlasters was discovered to have been modified to include a cryptocurrency drainer. The game was available on Steam between July 30 and September 21, 2025. The malicious component was added on August 30, 2025. The game drained $32,000 from a streamer's cryptocurrency wallet, who was raising funds for cancer treatment. The total amount stolen from 261 Steam accounts is estimated to be $150,000. The game was published by Genesis Interactive and was removed from Steam on September 21, 2025. The attack targeted users managing significant cryptocurrency amounts, identified via Twitter.
Timeline
-
22.09.2025 12:28 π° 1 articles Β· β± 5h ago
Steam game BlockBlasters modified to include cryptocurrency drainer
BlockBlasters, a 2D platformer game, was available on Steam from July 30, 2025, to September 21, 2025. The game was modified on August 30, 2025, to include a cryptocurrency drainer. The game drained $32,000 from a streamer's cryptocurrency wallet and a total of $150,000 from 261 Steam accounts. The attack targeted users managing significant cryptocurrency amounts, identified via Twitter. The malicious component was a batch script that collected Steam login information and IP addresses, uploading the data to a C2 system. The attack involved a Python backdoor and a StealC payload, and the attackers left their Telegram bot code and tokens exposed.
Show sources
- Verified Steam game steals streamer's cancer treatment donations β www.bleepingcomputer.com β 22.09.2025 12:28
Information Snippets
-
BlockBlasters was a free-to-play 2D platformer game available on Steam from July 30, 2025, to September 21, 2025.
First reported: 22.09.2025 12:28π° 1 source, 1 articleShow sources
- Verified Steam game steals streamer's cancer treatment donations β www.bleepingcomputer.com β 22.09.2025 12:28
-
The game was modified on August 30, 2025, to include a cryptocurrency drainer.
First reported: 22.09.2025 12:28π° 1 source, 1 articleShow sources
- Verified Steam game steals streamer's cancer treatment donations β www.bleepingcomputer.com β 22.09.2025 12:28
-
The game was published by Genesis Interactive and was removed from Steam on September 21, 2025.
First reported: 22.09.2025 12:28π° 1 source, 1 articleShow sources
- Verified Steam game steals streamer's cancer treatment donations β www.bleepingcomputer.com β 22.09.2025 12:28
-
The game drained $32,000 from a streamer's cryptocurrency wallet.
First reported: 22.09.2025 12:28π° 1 source, 1 articleShow sources
- Verified Steam game steals streamer's cancer treatment donations β www.bleepingcomputer.com β 22.09.2025 12:28
-
The total amount stolen from 261 Steam accounts is estimated to be $150,000.
First reported: 22.09.2025 12:28π° 1 source, 1 articleShow sources
- Verified Steam game steals streamer's cancer treatment donations β www.bleepingcomputer.com β 22.09.2025 12:28
-
The attack targeted users managing significant cryptocurrency amounts, identified via Twitter.
First reported: 22.09.2025 12:28π° 1 source, 1 articleShow sources
- Verified Steam game steals streamer's cancer treatment donations β www.bleepingcomputer.com β 22.09.2025 12:28
-
The malicious component in the game was a batch script that performs environment checks before collecting Steam login information and the victimβs IP address.
First reported: 22.09.2025 12:28π° 1 source, 1 articleShow sources
- Verified Steam game steals streamer's cancer treatment donations β www.bleepingcomputer.com β 22.09.2025 12:28
-
The data collected by the batch script was uploaded to a command and control (C2) system.
First reported: 22.09.2025 12:28π° 1 source, 1 articleShow sources
- Verified Steam game steals streamer's cancer treatment donations β www.bleepingcomputer.com β 22.09.2025 12:28
-
A Python backdoor and a StealC payload were used alongside the batch stealer.
First reported: 22.09.2025 12:28π° 1 source, 1 articleShow sources
- Verified Steam game steals streamer's cancer treatment donations β www.bleepingcomputer.com β 22.09.2025 12:28
-
The attackers left their Telegram bot code and tokens exposed, indicating an operational security failure.
First reported: 22.09.2025 12:28π° 1 source, 1 articleShow sources
- Verified Steam game steals streamer's cancer treatment donations β www.bleepingcomputer.com β 22.09.2025 12:28
-
There are unconfirmed reports identifying the threat actor as an Argentinian immigrant living in Miami, Florida.
First reported: 22.09.2025 12:28π° 1 source, 1 articleShow sources
- Verified Steam game steals streamer's cancer treatment donations β www.bleepingcomputer.com β 22.09.2025 12:28
-
Similar incidents involving Steam games Chemia, Sniper: Phantomβs Resolution, and PirateFi have occurred earlier in 2025.
First reported: 22.09.2025 12:28π° 1 source, 1 articleShow sources
- Verified Steam game steals streamer's cancer treatment donations β www.bleepingcomputer.com β 22.09.2025 12:28