Get all your news in one place.
100's of premium titles.
One app.
Start reading
Player One
Player One
Entertainment
Bella Javier Liamzon

Researchers Say Steam's 'Teraleak' Came From A Public Endpoint, Not A Hack

An official Steam client screenshot published by Valve in 2010, during the Steam2 era covered by the archive. Alt: Steam desktop client interface in 2010. (Credit: Valve)

The huge Steam archive that surfaced over the weekend may not have come from a conventional hack at all. Researchers tracing the files say they were obtainable through a publicly accessible endpoint, but there is still an important unanswered question: when were the files actually collected?

Valve-focused researcher Gabe Follower wrote on X that he had verified there was "no hacking involved" and that the material was obtained through a publicly accessible endpoint. That is the clearest public claim about the archive's origin so far.

The archive itself contains more than 12TB of old Steam content dating roughly from 2003 through 2013, according to Ars Technica's reporting. That period lines up with Steam2, Valve's older content-delivery system, before the company transitioned to SteamPipe.

But the strongest reporting also adds a caveat that should stay in the story. It is not yet clear whether the data was pulled from that public endpoint recently or whether somebody downloaded and archived it years ago and only released it now.

That distinction changes how the incident should be described. There is no public evidence of attackers breaking into Valve's current production systems. There is also not enough evidence to state as fact that Valve left a forgotten live server exposed until this weekend.

No current Steam account credentials, payment records or other present-day customer data have been reported as part of the archive. Public descriptions of the material center on old game and software depots rather than a dump of Valve's current user database.

Valve had not issued a public statement about the archive as of Sept. 1. That should be checked again immediately before publication.

For players, the practical distinction is important: the story is currently about old content infrastructure and how archival game files became publicly accessible, not evidence that today's Steam accounts were breached.

For Valve, the unanswered question is still uncomfortable. If the files were gathered recently, the company will need to explain why legacy material remained reachable. If they were collected years ago, the story becomes less about a current exposure and more about a massive archive finally being released.

Until that timeline is established, "public endpoint" is supported. "Old server left exposed until now" is not.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.