Valve has removed a game titled Piratefi from its online store Steam after security researchers found it contained malware designed to steal sensitive information, including cryptocurrency wallet details. The discovery was made by Marius Genheimer of the SECUINFRA Falcon Team, who revealed to Techcrunch that the game was embedded with Vidar, a known information-stealer that can extract passwords, session cookies, and private keys from digital wallets.
How the Malicious Game Slipped Through
Genheimer noted that Piratefi was likely a repurposed version of an existing game template, allowing the hackers to deploy the malware with minimal effort. The game was published under the developer name Seaworth Interactive, which has no discernible online presence, making attribution nearly impossible. Valve acted quickly after receiving the report, removing the game and banning the associated accounts from the platform.
Vidar Malware: A Persistent Threat to Crypto Users
Vidar is a notorious infostealer often distributed through phishing emails, cracked software, and now, malicious games. Once installed, it exfiltrates browser-stored credentials, auto-fill data, and cryptocurrency wallet files from extensions like MetaMask and Exodus. The malware packages the stolen data and sends it to command-and-control servers. Researchers have linked Vidar to broader cybercriminal operations, including ransomware deployment, as attackers leverage the stolen information for further exploitation.
For cryptocurrency investors, the risk is acute: Vidar can directly compromise wallet seed phrases and private keys, giving attackers full control over digital assets. Security experts recommend using hardware wallets, enabling two-factor authentication, and avoiding downloads from unverified sources.
Industry Implications and User Advice
This is not the first time Steam has faced malicious software submissions. Despite Valve's review system, determined attackers can bypass checks. The Piratefi incident underscores the need for both platforms and users to remain vigilant. As of now, Seaworth Interactive has not responded to requests for comment, and the game files have been purged. The cybersecurity community urges gamers and crypto holders to exercise caution—any game that seems too obscure or offers unusual incentives should be treated with suspicion.

