Live data from Hacker News

'50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

pcgamer.com

161–170 of 333 posts

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#161

Context on what I believe they mean by "fraudulent". Steam back in the day used to accept 0 confirmation bitcoin spends. This means that the transaction has been gossiped on the bitcoin p2p network but had not yet been mined into a block and thus had minimal finality guarantees. Steam could see that they were going to receive a bitcoin payment (when the transaction was mined into a block) and would credit the users a…

> There are many context where a 0conf tx makes sense, mostly IRL. I'm curious, like what? To me this is more like "someone wrote a cheque but there's no guarantee that they'll give it to you".

I only have a layman understanding of bitcoin, and I've never used a cheque in my life, but would it not be more like "someone wrote you a cheque and there's no guarantee it won't bounce when you try to cash it in"?

Which, again maybe showing my complete lack of knowledge of cheques, is how I thought they worked in the first place.

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#162

Context on what I believe they mean by "fraudulent". Steam back in the day used to accept 0 confirmation bitcoin spends. This means that the transaction has been gossiped on the bitcoin p2p network but had not yet been mined into a block and thus had minimal finality guarantees. Steam could see that they were going to receive a bitcoin payment (when the transaction was mined into a block) and would credit the users a…

> Steam back in the day used to accept 0 confirmation bitcoin spends. This means that the transaction has been gossiped on the bitcoin p2p network but had not yet been mined into a block and thus had minimal finality guarantees.

Why? Why would anyone ever accept this?

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#163
post #35
post #20

Earlier quoted context omitted.

The people who buy the game then resell the key on other websites for less than you find it on steam. They can buy many licenses when the game is on sale, so even if there is no chargeback, the devs can lose money through these methods. Otherwise it is still a money laundering tactic. Here’s a blog post where they talk about this eco system. https://factorio.com/blog/post/fff-303

I'm failing to understand why is this considered fraudulent. Buy low sell high, this is how all trade works. People buying multiple keys for resale is just an unintended consequence of underpricing the product.

If the purpose is to avoid KYC laws and turn bitcoin to cash, it isn’t hard to understand why Steam wants to avoid these types of customers.

Also, they aren’t buying low and selling high, they are buying low and selling even lower because they are okay with a lossy conversion.

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#164

Context on what I believe they mean by "fraudulent". Steam back in the day used to accept 0 confirmation bitcoin spends. This means that the transaction has been gossiped on the bitcoin p2p network but had not yet been mined into a block and thus had minimal finality guarantees. Steam could see that they were going to receive a bitcoin payment (when the transaction was mined into a block) and would credit the users a…

> There are many context where a 0conf tx makes sense, mostly IRL. I'm curious, like what? To me this is more like "someone wrote a cheque but there's no guarantee that they'll give it to you".

Anything where the buyer doesn't leave 15-30 mins after making the payment or the purchaser is id'd.

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#165
post #124

Earlier quoted context omitted.

Steam marked me as a "fraud" because I used my European Revolut card to try and make a purchase when I lived in Indonesia. I get that they don't want European people to pay Indonesian prices through a VPN or whatnot, but I was living in Indonesia and living off a local salary; I thought marking me as a "fraud" was rather harsh; with the increased ease of international banking there are loads of cases where this is pe…

I'm on vacation in Croatia and my Spotify Premium expired. I tried to renew it with my Dutch card and was rejected, so I had to use a VPN set to Amsterdam...

Are they getting stricter? I've never had that problem, including when travelling to all ex-yugoslavia countries some years ago. I'm a New Zealander.

Reminder to self: organise VPN before leaving for overseas.

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#166
post #147
post #138

Earlier quoted context omitted.

I doubt steam is doing blockchain analysis, tracing back where the coins came from, and seeing whether the exchange that sold them the coins were defrauded or not.

First off, why not? Why would you doubt that when they're a massive storefront and deal with fraud of all kinds? But also, wouldn't it be fairly easy and beneficial to have this information? Exchanges know what wallets are charged back and fraudulent. Is it not in their interest to work with Steam? Or even, is it not in the exchange's interest to do this analysis and demand the coin from Steam?

> First off, why not? Why would you doubt that when they're a massive storefront and deal with fraud of all kinds?

1. The anti-fraud tech used for credit card fraud (ie. stolen credit cards used for unauthorized transactions) don't really translate well to the fraud described here (ie. stolen cryptocurrency).

2. it makes sense for ecommerence merchants to do anti-fraud stuff, because they're on the hook for fraud. the same does not apply to cryptocurrency transactions.

>But also, wouldn't it be fairly easy and beneficial to have this information? Exchanges know what wallets are charged back and fraudulent.

1. I haven't heard of such blacklists being around, especially in 2017 (when steam stopped accepting payments)

2. such blacklists would likely be ineffective, because of mixers and lack of coordination (see previous point)

3. such blacklists threaten the fungibility of bitcoin, which would probably cause backlash from potential customers.

>Is it not in their interest to work with Steam?

1. it might be in their interest to work with steam, but not the other way around

2. even though steam might have huge sales volume, it's not going to be the primary route criminals cash out. if you stole tens of thousands of dollars in crypto, I doubt you'll spend a significant portion of that on games. You only have so much time, and games are relatively cheap. Meanwhile localbitcoin has people willing to give you literal cash for a few percentage points cut. There's a reason why all the anti-money laundering regulations target banks and other high cash volume businesses (eg. pawn shops), and not bestbuy or mcdonalds.

>Or even, is it not in the exchange's interest to do this analysis and demand the coin from Steam?

If [random exchange] messaged me and said that some coins I hold were 10% tainted from 10 transactions ago, and wanted me to return them, I'd tell them to fuck off.

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#167

Context on what I believe they mean by "fraudulent". Steam back in the day used to accept 0 confirmation bitcoin spends. This means that the transaction has been gossiped on the bitcoin p2p network but had not yet been mined into a block and thus had minimal finality guarantees. Steam could see that they were going to receive a bitcoin payment (when the transaction was mined into a block) and would credit the users a…

> Steam back in the day used to accept 0 confirmation bitcoin spends. This means that the transaction has been gossiped on the bitcoin p2p network but had not yet been mined into a block and thus had minimal finality guarantees. Why? Why would anyone ever accept this?

Because I am pretty sure it isn't true. I am one of the few people who used bitcoin on steam during this time and I don't remember it ever being instant. I would like to see clarification to the top point because I don't think it is true...

In my opinion when he says "fraudulent" he is probably talking about how people would use it to avoid bans. Steam would track banned users that remake accounts by checking their CC. They would also verify the people by making sure the address on the CC was close or the same to the address on the account.

With Bitcoin you could avoid any tracking from remaking an account which leads to more 'bad actors' using Bitcoin. For reference you needed to spend something like $5 - $10 to enable trading on the platform. From their people would phish, scam, and break the TOS on the account.

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#168

Earlier quoted context omitted.

> There are many context where a 0conf tx makes sense, mostly IRL. I'm curious, like what? To me this is more like "someone wrote a cheque but there's no guarantee that they'll give it to you".

I think more like "someone wrote a check and there's no guarantee it won't bounce". So really, it's quite analogous to how 0conf works in practice.

There are laws in place that specifically handle writing bad checks. While I'm sure double-spending Bitcoin transactiosn is illegal in some way, it is probably covered under a more nebulous fraud-type statute.

I'd be curious to see the percentage likelihood on both, as well, as I suspect they are very different. Would businesses accept checks if half of them were bad?

Re: '50% of transactions were fraudulent' when Steam accepted Bitcoin for payments

#169
post #158

Context on what I believe they mean by "fraudulent". Steam back in the day used to accept 0 confirmation bitcoin spends. This means that the transaction has been gossiped on the bitcoin p2p network but had not yet been mined into a block and thus had minimal finality guarantees. Steam could see that they were going to receive a bitcoin payment (when the transaction was mined into a block) and would credit the users a…

> and you don't trust you customers Seeing as “remember the password” does about nothing in the desktop app on my own machine near which only I ever come—Steam's attitude toward the users is crystal clear, and I'd say it's weird that they lived almost two years with that arrangement.

Convenience and security are always in tension - and steam account takeovers are very common, as they can have tradable assets worth hundreds or thousand of dollars.
Post reply on HN