Valve awards $7.5k bounty to a researcher who discovered a flaw with Steam's wallet system
"We have changed the severity assessment to Critical, reflecting the potential cost to the business"
Weekly digests, tales from the communities you love, and more
You are now subscribed
Your newsletter sign-up was successful
Want to add more newsletters?
Every Friday
GamesRadar+
Your weekly update on everything you could ever want to know about the games you already love, games we know you're going to love in the near future, and tales from the communities that surround them.
Every Thursday
GTA 6 O'clock
Our special GTA 6 newsletter, with breaking news, insider info, and rumor analysis from the award-winning GTA 6 O'clock experts.
Every Friday
Knowledge
From the creators of Edge: A weekly videogame industry newsletter with analysis from expert writers, guidance from professionals, and insight into what's on the horizon.
Every Thursday
The Setup
Hardware nerds unite, sign up to our free tech newsletter for a weekly digest of the hottest new tech, the latest gadgets on the test bench, and much more.
Every Wednesday
Switch 2 Spotlight
Sign up to our new Switch 2 newsletter, where we bring you the latest talking points on Nintendo's new console each week, bring you up to date on the news, and recommend what games to play.
Every Saturday
The Watchlist
Subscribe for a weekly digest of the movie and TV news that matters, direct to your inbox. From first-look trailers, interviews, reviews and explainers, we've got you covered.
Once a month
SFX
Get sneak previews, exclusive competitions and details of special events each month!
Valve has had to fix a Steam exploit that allowed players to generate false credits to their Steam wallet balance.
While there's no word yet on whether or not unscrupulous players were able to successfully make use of the exploit, the issue came to light earlier this week on HackerOne courtesy of a security researcher who'd discovered that if a user had "amount100" as part of their Steam account email address, payments via Smart2Pay could be intercepted and amended, changing $1 deposits to, say, $100 while the payment debited from the bank account remained at $1.
As reported by The Daily Swig, after testing the API "in-flight" interception, Valve's JonP thanked the reporter, moved swiftly with the team to triage the issue, and confirmed that the researcher was correct and asked them to "please stand by" while Valve "assessed [the] severity" of the exploit.
Later that same day, the researcher was asked to retest the system, after which JonP felt compelled to reclassify the exploit as a "critical" one and awarded the researcher a $7500 bounty in thanks for reporting the issue.
"Thank you for this report," JonP said (thanks, NME). "This was clearly written and helpful in identifying a real business risk. We have changed the severity assessment to Critical, reflecting the potential cost to the business, and applied a bounty accordingly. We hope to hear more from you in the future."
ICYMI, Microsoft's streaming service, xCloud, will work on Valve's Steam Deck. The announcement came courtesy of Xbox boss Phil Spencer, who teased that earlier this week, he'd spent time with the team at Valve, experimenting with Steam Deck and confirming that "Halo" and "Age" "feel good" on Valve's new handheld system.
While Spencer stopped short of confirming how, exactly, the streaming service will work on Steam Deck, it's the first time we've had confirmation that Microsoft's streaming service is compatible with Steam Deck.
Weekly digests, tales from the communities you love, and more
Missed the big announcement of Valve's all-new Steam Deck? Compared by many to be the PC equivalent of the Nintendo Switch, the Steam Deck is a handheld PC that enables you to carry your Steam library with you wherever you go, and has been balanced to perform equally well regardless of whether it's docked or on the move.
Check out how the Steam Deck specs compare to the Nintendo Switch, PS5, and Xbox Series X in our breakdown.

Vikki Blake is GamesRadar+'s Weekend Reporter. Vikki works tirelessly to ensure that you have something to read on the days of the week beginning with 'S', and can also be found contributing to outlets including the BBC, Eurogamer, and GameIndustry.biz. Vikki also runs a weekly games column at NME, and can be frequently found talking about Destiny 2 and Silent Hill on Twitter.


