Valve has removed the game Piratefi from its Steam online store after security researchers discovered it was embedded with malware designed to steal cryptocurrency wallets. Marius Genheimer of the SECUINFRA Falcon Team revealed to TechCrunch that the malware is a variant of the Vidar information stealer, which can extract passwords, browser session cookies, and private keys from cryptocurrency wallets.
How the Malware Worked
Investigators determined that Piratefi was likely a modified version of an existing game template, allowing the attackers to deploy Vidar with minimal effort. Once installed on a user's system, the malware scans for cryptocurrency wallet files (e.g., those from Bitcoin, Ethereum, and other popular coins), browser-stored credentials, and two-factor authentication tokens. The stolen data is then exfiltrated to command-and-control servers controlled by the attackers.
Broader Threat of Vidar
Vidar is a well-known info-stealer often distributed via phishing emails, cracked software, or fake applications. In recent months, it has been linked to multiple cybercriminal campaigns, including attempts to deploy ransomware. The Piratefi incident highlights how gaming platforms can be exploited as distribution vectors: attackers leverage the trust users place in platforms like Steam to trick them into downloading malicious executables.
What This Means for Crypto Users
Cryptocurrency holders should remain vigilant against malware disguised as games or other applications. Recommended precautions include:
- Only downloading games from official or verified sources
- Avoiding running suspicious executables, especially those claiming to be 'cracked' or 'free' versions
- Using hardware wallets to store significant amounts of cryptocurrency
- Regularly scanning systems with up-to-date anti-malware tools
- Keeping operating systems, browsers, and security software updated
Steam has stated that it has removed the game and is reviewing its submission protocols. However, similar threats are likely to emerge in different forms. Security experts are urging Valve to implement more rigorous code review processes to prevent malicious software from entering the platform. The incident serves as a stark reminder that as digital assets continue to increase in value, attackers will exploit every possible entry point — and user awareness remains the first line of defense.

