'50% of transactions were fraudulent' when Steam accepted Bitcoin for payments
pcgamer.com
pcgamer.com
Steam back in the day used to accept 0 confirmation bitcoin spends. This means that the transaction has been gossiped on the bitcoin p2p network but had not yet been mined into a block and thus had minimal finality guarantees. Steam could see that they were going to receive a bitcoin payment (when the transaction was mined into a block) and would credit the users account instantly for a better purchase UX.
Turns out anyone with some deeper understanding of bitcoin could construct another transaction spending the same bitcoin back to themselves before their original transaction was ever put in a block. The bitcoin community moved away from accepting '0 conf' transactions pretty much everywhere because of this reason.
In fact the high fee era (2016-2018) saw many wallets incorporating this "double spend" feature into their wallets. This is known as RBF, "replace by fee" and is really useful when you need to bump your transaction up the queue. You replace your old transaction, that is waiting to be mined, with a new one that offers a higher fee to incentivize miners to add it to a new block.
I think its rather unfortunate that 0 conf transactions were written off so quickly. There are many context where a 0conf tx makes sense, mostly IRL. But, if you are running a business online and you don't trust you customers you should wait 3-6 blocks after the transaction has been mined before delivering your goods.
I'm curious, like what? To me this is more like "someone wrote a cheque but there's no guarantee that they'll give it to you".
I'd be curious to see the percentage likelihood on both, as well, as I suspect they are very different. Would businesses accept checks if half of them were bad?
Which, again maybe showing my complete lack of knowledge of cheques, is how I thought they worked in the first place.
Bank cheque is a bank-guarantee binded by banker self-verification (almost always good) with no takeback (voiding) mechanism. “block-chain confirmed” is always a good transaction with no clawback mechanism so you must wait until it’s confirmed before receiving your merchandise.
“Cash is king.”
In this case, Steam was selling a digital good that they could be fully revoke if the funds never arrived, so the check ability works very well.
It would have been even better on a smart contract platform where the game license would exist on the chain itself and couldn’t be purchased via a double spend, Chain re-orgs would also sort themselves out in a fully on-chain system.
The security and confirmation of a transaction is not a function of number of blocks, but time since inclusion in a block and total amount of work (hashes) piled on top of your transaction. Generally, 6 blocks (1 hour on average) is considered sufficient certainty of immutability for normal functioning of the blockchain (i.e. not under active attack). One hour for final, and completely irreversible, settlement is absurdly fast in the context of the traditional financial system, which takes days at least for final settlement, and can be much longer for some international transfers.
Small, individual scale purchases only really make sense to do on higher layer transaction protocols, like lightning network (non-custodial and open) or some custodial networks (like a bitcoin backed Visa credit card).
The only model that makes sense for bitcoin is the layer one base chain is a settlement network, with payment networks build on top that aggregate many transactions into one on chain transaction. Think OSI model for networking.
Do you think this applies to cyrptocurrencies that has faster confirmations/block generation? Or is only important when there is a lengthy confirmation?
The amount of work (hashes) represents a real world cost (electricity and mining chips) that can't be undone without massive commitment of these real world resources.
This is the foundation of why bitcoin works.
So basically, people who say their blockchain with shorter block times is "faster" are either fools who don't understand what's going on or conmen trying to pump and dump their bags. Layer one transaction confirmation is about settlement finality, not how fast you can pay for coffee.
(You could empirically estimate by how much by looking at abandoned chain history in a real network, though.)
Proof of stake doesn't solve this problem, as the top stakers end up needing to control (or get coopted by) the monopolies on violence. The traditional banking system is effectively an obscured proof of stake system.
Proof of work also has the nice feature that every watt of energy used to acquire and secure bitcoin is a watt that can't be used for violence.
You might like the work of Jason Lowry, a US Space Force Major who's currently studying bitcoin conceptualized as a new kind of military technology, https://twitter.com/JasonPLowery
How so? Assuming (pseudo-)anonymity for stakers is possible.
And anonymity of stakers who have unassailable control of the network consensus is exactly the problem. If you don't know who the king is or where he lives, then the peasants have zero ability to countervail his control authority when he starts abusing his power. No sovereign nation or person will sign up for a system like that without being violently coerced, like the US does to keep the rest of the world on the petrodollar standard.
Your bank abstracts the underlying inter bank settlement complexity and aggregates all the minor transactions and transfers that individuals do to a small number of larger settlement transactions, likely on the SWIFT network.
When you make a payment, that transfer of money isn't instantly settled. The instantaneous feeling is a service that the bank provides you, but it's an illusion. There are similar experiences being built now on top of bitcoin, like http://strike.me, although the lightning network that Strike and CashApp are building upon actually is instant finality, unlike Visa/Paypal.
This is why comparing bitcoin to Visa or PayPal is fundamentally flawed, since those are both layer 2/3 networks on top of SWIFT.
The proper comparison is with other settlement networks that create finality, like SWIFT. Where SWIFT may take days to create final settlement of a transfer, bitcoin takes ~1 hour depending on how much confidence you want. Where SWIFT is secured by nation state monopolies on violence and global banking gatekeeping, bitcoin is secured by the most powerful computer network on the planet that no single nation state has the power to disrupt. Bitcoin is open and permissionless and anyone and everyone can join. SWIFT is tightly permissioned because it relies heavily on exclusive networks of humans who trust each other.
Bitcoin does not provide sufficient privacy which allows exchanges to freeze tainted coins and authorities to track down real identities.
Seeing as “remember the password” does about nothing in the desktop app on my own machine near which only I ever come—Steam's attitude toward the users is crystal clear, and I'd say it's weird that they lived almost two years with that arrangement.
Why? Why would anyone ever accept this?
In my opinion when he says "fraudulent" he is probably talking about how people would use it to avoid bans. Steam would track banned users that remake accounts by checking their CC. They would also verify the people by making sure the address on the CC was close or the same to the address on the account.
With Bitcoin you could avoid any tracking from remaking an account which leads to more 'bad actors' using Bitcoin. For reference you needed to spend something like $5 - $10 to enable trading on the platform. From their people would phish, scam, and break the TOS on the account.
Doesn't seem like a good user experience. All to get a free hour of gameplay?
There are easier ways of pirating games. The only possible usecase for this kind of fraud would be if you can buy digital items, transfer and then sell those digital items.
But even then, that might be difficult to do all in 10 minutes.
My comment was intended to point out that it's parent comment didn't bother to read the grandparent comment, which had clearly answered the question it was asking.
But then the parent comment author edited themself, I assume to avoid looking foolish. So I guess it's irrelevant now.
Ok, so then I guess it isn't really a problem then. The whole just ban them "ad infinitum", is totally a reasonable solution to all of this.
No, its not. If an account gets banned after an hour, all that happened is that the user got is 1 free hour of playing a video game. There are easier ways of pirating videos games than that.
So really, thats good enough.
You tried to claim "The fraudster scales up their account creation". And I am telling you, that if a fraudster wants to play a video game for free, there are much easier ways of doing so. By just pirating the game, for example.
So that specific point is wrong.
> or so say the guys sitting in the cheap seats
Actually, it seems like you are the one sitting in cheap seats. Because you have already straight up admitted that you don't really know much about the industry. Whereas, people like me, who do work in the games industry, do know about what a good user experience is for people playing video games, actually know more about this than you do.
So, in other words, you actually should "care how well it would work". Because how well it would work, is integral to the attack vector.
> > In practice, it may well be more complicated than that
> No, its not...
You keep assuming that the information you already have is ALL of the relevant information about this issue. You're just a Monday Morning Quarterback, and you have no way to know whether the situation is more complicated than this. So you can't possibly make absolute statements about this... Unless you happen to work at Valve, on something that has given you actual experience with the Steam account system.
I already told you the answer to this.
There are easier ways to pirate a game than this, as getting banned after an hour is not a good user experience, and the user would be better off just pirating the game.
For which you had no response.
The only specific reason that you gave, which was "they could just make more accounts" I refuted by describing how it would be easier to just pirate a game.
And then you refused to address the refutation, because you didn't have a response.
If you didn't have any specifics arguments about that point you could have just said so.
Because I was talking about the actual, specific arguments, about why your previous statement of "make infinity accounts" was wrong, and you are now continuing on being incapable of giving a response to that specific statement.
This website is just surreal.
Most of the “tenacity” parts implied there are automatable, so it's mostly about “can people enjoy the paid-for experience of a game with ephemeral rather than durable accounts”, which, well, really depends on the design of the game.
The BTC acceptance didn't even vend keys, it was just access on the primary steam account.
https://bitcoin.stackexchange.com/questions/2170/how-often-f...
edit: I guess my point is that if you're selling coffee and making 100 $6 transaction, going 1 block deep probably isn't a big deal. If you're selling one car a month, you might not want to risk the small chance of an orphaned block -- but a one hour hold on title is a whole lot better than waiting for a check to clear.
More likely the reason this isn't done is to allow customers to buy more (drinks/dessert, do so in a single transaction, and tip post-service. Not because the amount is unknown.
I say "more than enough" because can't they just revoke the key of whatever was purchased if it gets double-spent? Seems easy enough.
Not in bitcoin land, orphaned blocks happen a few times a day: https://bitcoin.stackexchange.com/questions/2170/how-often-f...
If you're willing to tolerate this risk then by all means go for it.
(I'm with you I think steam should be able to tolerate this risk.)
One of the odd benefits of this is that old forum posts and discussions have a good chance of being relevant.
Although I will say lots of progress has been made in p2p message propagation (since this isn’t directly a part of consensus) which could definitely prevent orphan blocks, so you may be on to something in this case.
Then Steam can accept that lower risk and mitigate further by then revoking game access.
I was imagining it was something on the line of drug cartels and human traffickers laundering money through trading game assets.
This is ridiculous. 1 block confirmation would've prevented near-all transactions from being retracted.
>I don't know what "null cipher" means but it sounds very technical and is probably the best one.
The whole UX excuse is a bit silly considering modern Steam games take an hour to download anyway.
They moved away from 0 conf because of the high fees, making payments sometimes get stuck for days or weeks, making 0 conf much less trustworthy.
What does that even mean?
* did someone try to send something other then bitcoin to a ₿ address?
* did a client claim he payed and did the payment seem to fail on his end?
* did a client not realise that you as payee also pay for the network fee?
Nowadays these kind of problems would be easily prevented by using bitcoin lightning payments, because they work in a fraction of a second and specify the exact amount that has to be payed. Also they are almost free of transaction costs.
The stages are Placement, Layering, and Integration.
Here’s one source that may help explain:
https://www.stpaulschambers.com/stages-of-money-laundering-e...
2. Bitcoin is obfuscated by purchasing things online with it
3. Those online assets can be sold for cash
Also Valve will be looking for this too, as required by their bank.
This is an incredibly unrealistic money laundering scheme, entirely fabricated by mr_cyborg.
The truth is that the “fraudulent transactions” here are double-spends, because Steam was accepting 0-conf payments in an unsafe way.
Using stolen money to buy gift cards, using those gift cards to buy real things and then selling those real objects or licenses or accounts after the fact is a well known process. Substituting "bitcoin" or any cryptocurrency for "gift card" is neither unreasonable nor unrealistic.
This does not make any sense in the context of bitcoin.
2. Release some shitty game on steam that no one will play
3. Buy millions of copies of said shitty game with your illegitimate money using Bitcoin
4. Your illegitimate money is now revenue from your shitty game and can be taxed (Profit)
- You steal a credit card.
- Buy BTC with said credit card.
- Use BTC to buy Steam cosmetics that you already own and Steam converts that BTC to USD.
You now have effectively used a stolen credit card to convert its value to cold hard cash that is not traceable, or at least requires several hoops to jump through to figure out who stole the card.
If they already have their assets in BTC they could simply put them in a mixer.
Also - That's just like fraud with extra steps? Why even usee btc?
What do you think a chargeback is?
I know what a chargeback is, and those are utterly irrelevant here.
On top of that, if you use a stolen credit card to buy a steam game and the original owner files a chargeback, your entire steam account gets banned. So yes it's extremely relevant here.
If instead you buy BTC on an exchange and then spend those BTC on steam, it's less likely to be flagged as fraud (at the time) because the BTC is purchased from an American website. Then you spend the BTC on steam. Then once the credit card is reported as stolen and a chargeback filed, it's the crypto exchange who gets hit. The chargeback is never associated with Steam and you can buy Steam games from a lower-priced market without the CC company ever being aware.
My credit card got into a locked state for a while every month, when Vulture did a approved monthly charge.
There are plenty of systems that verify things out of the ordinary.
It's not because you haven't encountered it, that they aren't there.
Additionally, stolen credit cards can be marked as stolen. Which would block any future payment with it.
The BTC that someone is sending you, isn't being charged back. You can't chargeback BTC. That doesn't make any sense.
> There are plenty of systems that verify things out of the ordinary.
There is no system that checks if the BTC is out of the ordinary, no.
> It's not because you haven't encountered it
Feel free to point to anywhere at all, that is doing a verification on the BTC. Not your credit card. Instead the BTC.
> stolen credit cards can be marked as stolen
A credit card can. But BTC is not a credit card.
But Crypto.com allows you to buy up to $30 worth of crypto with a credit card and cards online are pennies on the dollar online if bought in bulk.
An astute con artist would recongnise that the only real verifications credit cards have at their disposal is geolocation and shopping habits. So if one were to buy CC online, create a bot to enter the details onto the crypto.com exchange, route the traffic through a VPN using the CC address as a base, send the $30 worth of crypto you bought off exchange and into a wallet, using Tor and some clean Eth you bought in cash to pay the gas fees, Wrap the BTC in WBTC, throw it on uniswap, swap for some privacy coin, use that privacy coin to send to another wallet within that private ecosystem so the headers on the node are lost and bam. You've got some clean crypto that you've fraudulently bought with a credit card but can never be claimed as fraud!
But also, wouldn't it be fairly easy and beneficial to have this information? Exchanges know what wallets are charged back and fraudulent.
Is it not in their interest to work with Steam?
Or even, is it not in the exchange's interest to do this analysis and demand the coin from Steam?
1. The anti-fraud tech used for credit card fraud (ie. stolen credit cards used for unauthorized transactions) don't really translate well to the fraud described here (ie. stolen cryptocurrency).
2. it makes sense for ecommerence merchants to do anti-fraud stuff, because they're on the hook for fraud. the same does not apply to cryptocurrency transactions.
>But also, wouldn't it be fairly easy and beneficial to have this information? Exchanges know what wallets are charged back and fraudulent.
1. I haven't heard of such blacklists being around, especially in 2017 (when steam stopped accepting payments)
2. such blacklists would likely be ineffective, because of mixers and lack of coordination (see previous point)
3. such blacklists threaten the fungibility of bitcoin, which would probably cause backlash from potential customers.
>Is it not in their interest to work with Steam?
1. it might be in their interest to work with steam, but not the other way around
2. even though steam might have huge sales volume, it's not going to be the primary route criminals cash out. if you stole tens of thousands of dollars in crypto, I doubt you'll spend a significant portion of that on games. You only have so much time, and games are relatively cheap. Meanwhile localbitcoin has people willing to give you literal cash for a few percentage points cut. There's a reason why all the anti-money laundering regulations target banks and other high cash volume businesses (eg. pawn shops), and not bestbuy or mcdonalds.
>Or even, is it not in the exchange's interest to do this analysis and demand the coin from Steam?
If [random exchange] messaged me and said that some coins I hold were 10% tainted from 10 transactions ago, and wanted me to return them, I'd tell them to fuck off.
They wouldn't be blacklists. You only learn after the fact so its more about the analytics.
>I'd tell them to fuck off.
Well that's nice but if you get paid with stolen money, you don't just get to keep the money and tell them to fuck off. Steam would be liable to return the funds.
I mean, that goes back to my original question, why would they do this? Does bestbuy run analytics on the cash they receive to see how much % of their cash purchases were "fraudulent"?
>Well that's nice but if you get paid with stolen money, you don't just get to keep the money and tell them to fuck off. Steam would be liable to return the funds.
IANAL, but I thought this only applied to stolen goods, not cash? I heard of authorities seizing cash when they raid a drug house, but not randomly seizing people's cash because they happened to carry a bill that was involved in a bank robbery.
Credit card companies do, yes.
The credit card company and/or cryptocurrency exchange would eat the fraud.
>and why would they not push against the others for restitution if it's all trackable?
This is moving the goalposts. We're not discussing whether such a scheme would benefit banks/credit card companies/crypto exchanges, we're discussing whether valve implemented such a scheme for steam. I'm sure the aforementioned parties appreciate such a scheme, just as banks would appreciate a scheme where stores were checking the bills they accept were stolen or not. However, that says nothing about whether such a scheme exists, or whether steam was voluntarily doing so with no apparent benefit to itself. Nor does it change the fact that such a push was non-existent (or at least non-visible) in 2017.
Does anyone actually sell bitcoin via credit card transactions?
That would not even register right? Different coins are completely separate and it wouldn't even have registered anywhere and show up in the statistic. As far as I know the addresses are also distinct between coins (so it's not even physically possible) but there are so many now and I've been out of that world for a few years now so that might have changed.
> * did a client claim he payed and did the payment seem to fail on his end?
You mean like opening a support case, claiming they have paid?
> * did a client not realise that you as payee also pay for the network fee?
That sounds possible. In this case, Steam's bitcoin client would indeed detect the transaction but it would never be mined and thus never really spent.
My first thought was a double spend, though, or perhaps that the source money was illegitimately obtained (e.g. later determined to be laundered money or so).
It's probably illegitimate money.
But nothing prevents a minority attacker from branching the chain with their own alternate history at any point, although if they did it to a 'historical' block - one deep behind in the chain - then they're doomed from the start, they could never build an alternate chain longer with the main network racing them. Their only hope is waiting for a spend to become in a valid block then immediately start another branch with a double spend, hoping they could convince enough of the network to accept their version of the blockchain where the second double spend is actually the legit one. This gets harder and harder the more blocks build on the main branch, if 5 or 6 blocks build on a block, it's pretty much impossible for all intents and purposes to invalidate that block. (Unless, again, the attacker cares enough to secure computing firepower greater than or equal to 51% of the overall network)
*: "Eventually" is a probalistic statment, theoritically an alien super computer with unimaginable power could rewrite the whole blockchain from 2009 till now in the time it takes one of ours to boot, the blockchain protocol constantly adjusts a parameter that makes mining a valid block always takes, on average, 10 minutes. Assuming no sudden computing advances, this will always compensates for increases in gradual computing power such that you always need the majority's support for dictating what's the longest branch.
Given the way people talk about LN, and the (quite understandable!) desire to avoid credit card transaction fees, why don't we see more businesses accepting it?
(Asking this in good faith; I am admittedly ignorant about LN and have not tried making a transaction with it.)
Essentially, since arbitrage bots are a constant you don't need an outside oracle to ensure there's very little slippage between assets. Addititionnally, since you are swapping inside the pool it does not incur a trade fee as you aren't trading some outside entity with a confirmation time.
Obviously it gets deep in math, but what you get it the ability to pay for anything with anything with no trading fees and a % APR for keeping your assets in the omni pool.
Solona and dot already beat visa in transaction speed, latency and confirmation time. DOT at technology maturity is looking to be able to process around 10X the transaction volumes of visa.
Strictu sensu, it is "decentralized". In practice, it has all the disadvantages of blockchains and none of the advantages of the traditional banking networks.
imagine i wanted to buy Tesla. I have no money but i do have GM Stock. This allows mee to trade GM directly for Tesla stock with no actual trade fee, because the trade never occurs until i pull all my money out out of the pool.
So i am exposed to the asset without having to do the centralized exchange way of selling the asset (Incurring trade fee) buying usd. selling USD for the next asset (Incurring a trade fee) then eventually selling it back to USD when i want to utilize that asset.(Incurring a trade fee).
So, like i explained before it is a much more efficient mechanism of trading any asset. Since trading is literally the bedrock of civilization and effective capital allocation through trading is what drives prosperity, creating a more efficient trading algorithmn in crypto is one of the finest achievement of our generation even though most haven't undeerstood it's significance yet.
The soverign individual was a good book for me to recognize the need for crypto in the world.
* LN is technically complex, and hard for a normal person to run.
* LN requires making an on-chain transaction to open a channel. It's still vulnerable to high BTC fees and limited by the chain's low capacity.
* LN still runs on top of BTC, and has all the economic characteristics BTC has. So if it's stupid to buy pizza for $10K BTC because it appreciates, or stupid to sell a game for 0.0012 BTC because the price might fall tomorrow, then LN changes nothing about that and in some cases makes it worse. LN allows a non-cooperative party to delay things, which could be used maliciously during price swings.
* It's all still happening inside the crypto ecosystem, which is unpleasant to deal with. Think of say how people tried to buy their Tesla in BTC, then asked for their money back when the price rose. Why would a merchant want to deal with that kind of thing?
LN to me is a bit like putting lipstick on a pig -- it still leaves many significant problems in place, and adds some new ones on top in exchange for the benefits it provides.
- You still need to open (and close) a channel, paying BTC fees.
- To accept a payment, you need to first lock up balance.
- You need to always be online, otherwise your channel is closed.
- Sometimes your payment can fail, if you cannot find a route. This risk increases with the payment amount.
- Sometimes, you cannot even find a payment route, so you need to open another channel.
- Sometimes, the other person on the other side of your channel might close your channel.
- Despite all this, payments might still have a relatively expensive fee (in addition to the BTC fees).
People are trying to create solutions for these problems, but they're often either quite complex, introduce third-party dependency or both.
Running an independent node does take some management above that of a normal bitcoin node and merchant tooling and open source integrations are still coming together (though there are some good and dependable options). A merchant will need to keep an eye on their incoming liquidity, or use a service provider that does.
That being said, once you’re actually using it it’s a great experience, and for the individual enthusiast running a node can be great fun.
One service provider is Bitrefill, where you can buy Steam credits (and much else) over Lightning with a throwaway email faster than it takes for me to dig and type out a credit card out of my wallet or go through the SMS2FA BS of whatever virtual credit card-supporting bank I can find in the country I happen to be living in. Just copy and paste an invoice or scan a QR, depending on your wallet interface.
I do hope we see Lightning support in Coinbase Commerce et al soon. Unfortunately BitPay, one of the oldest and I think the most widely used payment service provider for Bitcoin, has become pretty much unusable as of lately and even if they did add lightning support it wouldn’t be interesting.
So the game item and the transaction are fake, as in they’re not actually there to play games.
But the source of the money used to buy the games is illegitimate.
Let's say, I stole $100,000. Now, I can't use this money until I find a way to explain how I have it.
If I wanted to wash it with Steam, I could go to the store, buy Steam cards or gift cards with the cash. Set up several Steam accounts, then use those cards to buy my game.
Now I'll lose some money to taxes, Steam's cut, and paying people to buy cards and games, but now I have $50,000 dollars I can use and no one is going to question where I got it.
You may be wondering why I can use the money to buy gift cards but not just deposit it in my bank, but no one is asking why someone has $100. That money is not traceable to anyone.
Like what? Cottage cheese?
Transaction failures and and fees are not fraud. The quote is specific.
Regarding lightning: https://twitter.com/nikzh/status/1356335970300416001?s=20&t=...
All I can imagine is a case where the user claims they didn't make the purchase, "please refund", but that would be easy to disprove.
When you make a purchase with a credit card, you claim that you are an authorized user of the card, and that you will pay the bill in accordance with the account agreement.
If that's not true, it's fraud. You've knowingly made an untrue claim in order to receive something of value.
Should Steam used a different form of validation? Yeah, that would have let them reject some (most? all?) of these fraudulent transactions. But anyone exploiting that situation to double-spend coins was committing fraud just as much as if they had written a worthless check, used a stolen credit card, or tried to pass off a counterfeit $100 bill.
Edit: I guess not? https://news.ycombinator.com/item?id=30480133
Most commonly btc via lightning network to a place that doesn't support it or bch. It happens all the time.
That makes no sense - how would that happen in practice?
BCH, though, yeah. Though less so over time since newer address types aren't compatible.
If Valve didn't want to see any forex risk on the sale, they end up incurring it on refund. If people are using it as an easy way to store money in USD and then convert back to BTC when the rate goes up, that can get expensive in a hurry.
It could also be that they used Coinbase or some other provider to act as a processor, and Coinbase charged the merchant if there were chargebacks on Coinbase's accounts.
Why would anyone do this? In what universe is buying games and then requesting refunds easier than clicking buy/sell on coinbase/kraken/etc.
Crypto companies follows much the same pattern and in some cases you can buy crypto but can’t cash out. If you could buy a game with bitcoin and get cash-money in a refund, this is quite viable.
We haven’t even started talking about money laundering…
I get that they don't want European people to pay Indonesian prices through a VPN or whatnot, but I was living in Indonesia and living off a local salary; I thought marking me as a "fraud" was rather harsh; with the increased ease of international banking there are loads of cases where this is perfectly legit (Spotify also doesn't allow it, but is far less harsh in how they communicate it – Netflix posed no problems; it's also circumventable by using gift cards, which is how I used Spotify, but I never tried this for Steam).
Anyway, I'd wager a significant chunk of the "fraud" cases is stuff like this: circumvention of regional pricing.
#expatlife
Otherwise, this level of fraud detection and response should be considered normal (and good).
I didn’t mind the cards getting frozen. It could have been fraud for all they knew. What I did not appreciate was the fact that it took two weeks & multiple calls to my credit union to resolve proof of address. I was lucky that I had my social security and with me, and that I had a backup credit card from a different bank, otherwise it’s don’t k is what I would have done.
Reminder to self: organise VPN before leaving for overseas.
Stuff like this is why I just started keeping the accounts around as I move about instead of closing them.
My Spotify's country was set to the Netherlands but after 2 weeks abroad it forced me to change my country to Croatia (maybe due to music copyright laws? No idea).
And? They don't report to you. So they don't have to explain anything to you. They don't have to defend their decisions to you.
In the case of crypto, there is no actual bank or payment provider through which to make a claim or facilitate a reimbursement.
In the case of the EU, the law imposes guaranteed minimal protection for online purchases. For example, any online purchase is fully reversible (including network fees) within the first 14 days following the transaction.
I don't think there are reasonable ways to meet this level of consumer service with crypto.
One method is to create lower-than-shovelware games, buy them with shadily acquired cryptocurrency, stolen credit cards or scammed gift cards and take real money payment from Valve. Egregious example: https://mmofallout.com/valve-bans-yet-another-laundering-gam...
If you run a business that can be used in a money laundering scheme, even if you are not a victim, you have a legal responsibility to try to limit/prevent that actually.
The crypto crowd may not like that, but it's not up to them.
“Money laundering” wasn’t mentioned by anyone but you. Stop inventing things.
This is about valve getting fucked because they were accepting bitcoin payments with zero confirmations.
It works the other way around, people launder funds from steam into cryptocurrency. Either by buying items with stolen credit cards or by stealing steam accounts.
Terrible rate of return, but the rate of return doesn't matter that much if you can't spend the money otherwise.
First, it destroys the traceability of notes (because they go into the FOBT machine with one set of serial numbers and the machine is going to pay out other notes and coins in different denominations). And any cash that investigators are going to track through seizures targeting an organisation gets slowly distributed through a community via its gamblers.
Secondly and more importantly, it provides provenance to the money. The gambling money mules (inveterate gamblers who are often addicts, lower ranking gang members, or the dealers themselves) can now move very large amounts of cash around on the street, because if they are stopped by police with large amounts of cash, they have a receipt to show it is what the machine paid out! The money they are carrying is the proceeds of legal gambling, not the proceeds of drugs. It's cleaned.
Here's one article about it:
https://www.theguardian.com/uk-news/2013/nov/08/gambling-mac...
Things have got a lot simpler for police, because FOBTs are now subject to more restrictions.
(And about time: in the 2015/16 year, individuals lost more than £1000 at FOBTs in a single sitting more than 233,000 times)
You brought up the point about zero confirmations. Zero-conf itself is fairly reliable, it certainly doesn't account for 50% transactions being fraudulent. Bitcoin introduced replace by fee in 2016. In 2017, bitcoin transition fees were high, and there was large increase in the bitcoin mempool, which led to a backlog of stuck low-fee transactions.
Replace by fee adds a major loophole to zeroconf, low-fee, stuck transactions could be rebroadcast with a higher fee and sent somewhere else even after they were "received" but not yet "confirmed" by Steam. Users could sign up, pay with Bitcoin, steam sees the payment but doesn't want the user to wait 3 days for confirmation, so steam completes the signup. After that the user rebroadcasts the transaction back to themselves with a higher fee and quicker confirmation. The original transaction doesn't go through.
Here's and discussion on how reliable zero-conf is when RBF is not part of the protocol and instead bigger blocks are mined.
> Zero-conf itself is fairly reliable, it certainly doesn't account for 50% transactions being fraudulent
Of course it does. Someone using this to spend the same bitcoin multiple times will generate many times more transactions than a regular user.
I consider "obtained somebody's credentials or private key through illegal means and then used that to purchase a good with stolen BTC" to be fraud. That the network considers this to be a normal transaction is not relevant.
Don't let bob create a new account with zero games and double spend his way to a free game because he has nothing to lose.
If Sam who has 100 games in his account with 10 year longevity cheats you insist he make good on his transaction or ban his account and don't ever let him create a new one with the same name and billing address. Sam is highly unlikely to value playing a singular game more than his account.
This seems absolutely trivial to avoid problems with.
I think you'll find many of the "crypto crowd" strongly disagree with your assessment.
In fact, reality on the ground highly suggests it is indeed at least partly up to them.
This is probably where the fundamental "talking past each other" happens on forums like HN.
> Another thing was that the vast majority of those transactions, for whatever reason, were fraudulent, where people were repudiating transactions or using illegal sources of funds and things like that. And that's just out of control, right? You want that number, realistically, in a couple of percent, not half of all transactions turning out to be fraudulent transactions. Similarly, with the actors that are currently in this NFT space, they're just not people you really are wanting to be doing business with. That doesn't say anything about the underlying technology, it's just a reflection of the people right now who are viewing it as an opportunity to rip customers off, or engage in money laundering, or other things like that.
1. https://www.rockpapershotgun.com/gabe-newell-interview-steam...
I feel like that when I speak with bitcoin enthusiasts. Lots of ideology that I don’t necessarily disagree with… but the ecosystem is something else…
Many saw something that wasn’t done and go contribute
Others saw something as static
Others saw something as stagnant and went to contribute to another network that experiences the same path towards its ideals
- previously flagged wallets moving through mixers
- purchases and refunds to facilitate money laundering
- converting to and from steam wallet to crypto etc.
It is NOT at all ambiguous which is what you are insinuating as the basis for not reading past the headline and discouraging others from doing so.
Bitcoin is a public ledger where all transactions are PERMANENTLY recorded. The law enforcement agencies have much better deobfuscation tools than 10 years ago and the tools will just continue to improve as they have INFINITE resources.
> But if a criminal has access to someone else’s Bitcoin, it’s already “cashed out”.
You are describing one type of crime that has existed far long before crypto as basis to discredit Gabe's claims and its an unconvincing argument/poorly baked logic that they tell in maximalist echo chambers.
Rather I ask, what is it that you fear so much whenever criticisms are raised? Did you transfer your savings to purchase jpegs and other insane APY that seasoned hedge fund managers can't produce?
>- previously flagged wallets moving through mixers
So if someone robbed a bank, used that money to buy drugs, that money ended up in my hands somehow (eg. I bought from the same drug dealer), and I used that to buy a big mac, my big mac purchase is "fraudulent" as well?
>- purchases and refunds to facilitate money laundering
How does that even work? You can only refund to the same person. It's not like you can buy a game, gift it to someone, and have that person "refund" the game to cash out
>- converting to and from steam wallet to crypto etc.
There isn't an official way to convert steam wallet to crypto
>It is NOT at all ambiguous which is what you are insinuating as the basis for not reading past the headline and discouraging others from doing so.
1. You say it's "NOT at all ambiguous" but you yourself listed 3 very different possible reasons. That sounds pretty ambiguous to me.
2. I skimmed the article and there isn't really much in the body either.
Quit putting words in my mouth. I made no such claim.
>and not to be trusted :D
Yes, if by "not to be trusted" you mean "not to be taken at face value".
People and countries who are prevented from accessing the banking system or making money transfers would beg to differ.
>I have no doubt that it's going to collapse, but I wouldn't dare to put a date on it. I was pointing out the absurdity of it 10 years ago and it's still sucking people in.
The same can be said about every fiat currency. Which will collapse first? Or, more importantly, which will collapse faster?
They are irreversible and if the Bitcoin is stolen that's not the merchant's problem.
The whole point of Bitcoin is to eliminate the possibility of chargebacks and thus the need for merchant to care about whether the buyer is in good faith and whether the money is stolen.
It is if half the transactions at the merchant eventually get refunded.
> The whole point of Bitcoin is to eliminate the possibility of chargeback
I'm sorry I'm having trouble keeping up with the "the point" of Bitcoin is this week. So it's chargeback avoidance now?
This seems consistent with the bitcoin ethos but incompatible how the economy and legal system work. If someone buys a physical item from your physical store with a hot check, a stolen credit card, or marked bills that were just stolen from a bank, you don't get to keep the money, even if police aren't able to recover the item you sold. This is normally referred to as being defrauded.
> At least in the US, the police can seize the cash as evidence, and their duty is to return it to the rightful owner, not whoever happened to have it at the time of seizure.
They do this with cash found in possession of criminals or suspects but do they do this with third parties not involved in crime? If someone unknowingly sells a car or a house to a criminal, can the cash they received for it be seized? What about legal fees. If a lawyer was found to have been paid with "dirty" money, can the cash be seized? What about cash spent at supermarkets? At the hospital? Etc. I've never heard of such a thing which is why I was asking for an example.
The important thing to remember here is that possession of stolen goods or cash is a crime (cf for example https://www.law.cornell.edu/uscode/text/18/2315), so if it becomes known to you that stolen cash is in your possession, you have a legal obligation to give it back. Given how fungible cash is, this probably won't be enforced if somebody uses stolen cash to pay their bill in a restaurant, but it probably would be if someone bought a car with cash that could be traced directly back to a bank robbery.
Since bitcoin is infinitely more traceable than cash, the argument of "but how do you know this particular dollar bill was stolen?" wouldn't really be applicable.
This is obviously false. There is absolutely nothing that compels normal payments companies to honor chargebacks. Since you don't need Bitcoin to complete this goal, this goal cannot be Bitcoins purpose.
The reason that they do it is because being consumer friendly is more important than being merchant friendly. Even merchants would attest to this fact
If you're in the space, going "well actually" in every article critical of blockchain based finance doesn't help your mission at all. Ultimately you're just making up excuses for the toxic parts of the system.
It provides macro value to coinbros and wantrapreneurs who think that bragging on social media about fake money is the same thing as owning real money. I guess that's something.
Bitcoin at $5,000 a coin was extremely useful for transactions. Bitcoin at $50,000 make it less useful because of scaling issues.
Is there a way I could use the lightening network directly if my exchange doesn't use it behind the scene?
On an exchange you're vulnerable to compromise both from your end and on the exchange's end
Using Lightning is even cheaper.
Just take a look at the most recent blocks, and check the one to one or one to two transactions. https://blockchair.com/bitcoin/transactions?s=fee_usd(asc)&q...
You will see that those transactions cost ~0.10 USD :)
Doesn’t make sense. Why would anyone wire your bank account money to a crypto exchange, convert it to crypto, transfer the crypto to a different bank in another country, then withdraw it when they could just wire the money directly to the other country’s bank?
If you can’t wire money out of your bank account to somewhere else, you probably can’t exchange it for crypto either.
Now he wants to leave Russia, but Russia is being banned from the SWIFT network, so he can't get any of his savings out. Enter Bitcoin again.
I am specifically thinking of the drama between payment processors and porn sites. I don't really think that Visa's position is "porn = bad" or that they would deliberately sever a profitable relationship with customers unless they were experiencing or anticipating something bad for business.
Valve seems to be thinking in the same vein here, where it is just not even worth trying to play the crypto game (pun intended...).
Bitcoin is only resilient to fraud only if you define fraud as "violating the rules of the blockchain". Any definition of fraud that involves meatspace is possible.
I don't see how that is even remotely possible with Crypto. How did Steam lose money ? My guess is they might be accepting it through some payment provider (so not a true crypto) who has in their T&C to be able to reverse transactions (which must be happening in Cash on the Steam facing side).
Seems like it was multiple things and "fraud" is just a catch-all term and Gabe didn't bother to list everything that they considered to be fraud.
Criminal creates a shit game and then uses the crypto to buy that game (with alt accounts) and since *very* few developers would be happy with getting paid in crypto, Valve has to convert it into fiat(?) currency.
Because they don't want to process illegal transactions with illegally acquired money, because they don't want to abide or facilitate criminal conduct, wherever possible. Life and business is not merely nor always about the potential to lose money through legal ramifications.
How did they know the payments were fraudulent?
Yes there are a ton of pitfalls and shams and bad things happening in the crypocurrency world, but this "article" is the media equivalent to the garbage projects in the crypto world. It is designed not to provide something useful, but rather to make money with questionable promises.
Means rather Gabe didn't figure it out, the team didn't understand how it works, and for burned. The reasons for distributed ledger are actually quite obvious.
Just like the electricity cost of bank transaction cannot be easily quantified, so the problem does not exist.
Those problems only exist in Bitcoin. /s
Because it is.
Bitcoin by its very nature wants to expand to consume every possible unit of energy it can.
For example, you can't buy a gift card in an Apple Store without signing a statement promising that you're not buying the gift card because a stranger online told you to.
Sounds ineffective on the surface, especially to jaded tech-types, but it's enough to give real people in the process of being scammed an opportunity to think about what they're doing.
If someone steals 100k of cash, there is a very low probability that the serial number of those bills were recorded somewhere. And even if they were, you couldn't easily trace the money though complex systems.
Bitcoin on the other hand is a complete and open ledger. When these large heists that constantly happen, it is trivial to identify the transactions that happen afterwards.
Cash is actually anonymous and Bitcoin is only pseudo-anonymous.
If I buy you lunch today, you can pay me back next week. We're not "cash handling business[es]", so we wouldn't have to scan.
Second, I don't think it's technically possible. For companies that do business across state lines, sure, but within a state's border, interstate commerce laws don't apply. Each state would have to enact a similar law. And best of luck with that.
Here’s a blog post where they talk about this eco system.
Also, they aren’t buying low and selling high, they are buying low and selling even lower because they are okay with a lossy conversion.
Criminal creates shit game, buys game using crypto and gets paid out in fiat because *very* few developers would accept being paid in crypto.
The only context I have heard "dirty" coins in is if they have been stolen from a crypto platform, or I think stolen by a influential crypto bro.
Yep, also links to darknet markets and any other “bad actors” whose addresses are known.
For example, someone in africa could pay .001 BTC($40 currently) for a game and all steam would see on their end is a debit transaction for $40(cash not bitcoin) in their account. It allows for bitcoin to be held by those who don't mind the volatile nature of its market value, AND allows for those wanting to accept without holding it in the short term. Win Win for both parties :)
Transaction fees and exchange fees will diminish that received value and force the customer to pay a fee to pay for something.
The net cost of Bitcoin transaction fees and exchange fees is higher than just using a random, common credit card processing company. It’s also slower for users.
Let’s be real: Gamers don’t really want to pay extra transaction fees for the privilege of sending Bitcoin and waiting as much as an hour or more for the transaction (my latest Bitcoin payment took longer than an hour) before they can play their game. Not when they can type in a credit number and get it done right away for 0 fees (or negative fees with reward cards)
I don't understand this sentiment. A) 50% of btc transaction were fraudulent makes zero sense. The technology behind BTC ensures it can't be fraudulent. So unless someone wants to explain to me how the hackers broke BTC's consensus to buy... videogames? it makes noe sense.
Not every organization accepts debit cards. Look it up.
I don't even remember the last time i carried cash?
I guess maybe a crypto debit card is good for people who lead plain lives. Like hanging around town and going to the movies and the candy store. But I require both cash and a real credit card for my life. Debit cards have failed me too often.
Because at that point i can go on a tangent and say well, the USD is actually accepted at less places than BTC because i can use my debit card in mexico but you can't use USD.
in mexico but you can't use USD
This is completely the opposite of my experience in Mexico, which is mostly in Chihuahua and TJ. I've never had any problems using USD in Mexico, and some people actually preferred it. And while plastic was widely accepted, cash was absolutely king.
I haven't been to Mexico since just before the pandemic started, but I don't believe the situation has changed all that much in that short a time.