Product1 distinct publisher3 min readPublished
Dataminer Gabe Follower says the Steam2 archive came out through a publicly reachable legacy endpoint rather than an intrusion. That makes every superseded system still answering reads an inventory problem.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
The mechanism behind the leak is ordinary: a retired pipeline that kept answering requests. Steam2 packaged Valve's game content into older formats [3], and SteamPipe took over in 2013, which is why the archive's contents stop that year [4]. Nothing new went through it after that. According to Gabe Follower, the Valve dataminer who went through the files, everything in the dump was obtained via a publicly accessible endpoint with no hacking involved, and he said the fault is Valve's [2].
Twelve terabytes covering 2003 to 2013 averages roughly 1.2TB for every year in the range [13]. That is a decade of packaging output rather than one product's leftovers, spanning playable Portal 2 builds dated July 2009 [5] and a CS:GO that was still a heavily modified Counter-Strike: Source [6]. An archive that size accrues across staff generations, which is exactly the condition under which a host quietly loses its owner.
A decommissioned service that takes no writes is often assumed to be out of scope for a security review; this one kept answering reads, and everything on it was historical anyway. Old builds persist rather than decay. The F-Stop assets from a scrapped Portal prequel [7] and the Weaponizer models tied to the canceled Episode 3 [8] matter more to researchers now than when they were current work, which is why the dump set off a wave of community archaeology [12].
The detail that moves this out of gaming trivia is the third-party content: early builds and beta material for Sonic 4 Episode II and Fallout: New Vegas were identified inside [9]. Those publishers did not run the endpoint and did not pick its retirement date. If other companies ship through your pipeline, their unreleased work is sitting in your retired systems, and their loss will never appear on your incident log.
Two things remain unresolved. Valve has not issued a public statement about the exposure [10], and dataminers are still separating genuine finds from duplicated code and placeholder assets [11], so the inventory of what escaped is not settled. The account of how it escaped rests on Follower's word as reported by Dexerto [2].
One simple test separates the systems that need attention from those that do not. First axis: does the system still accept writes? Second axis: does it still answer reads from the public internet? Write/read is watched, because it is the product. Neither is genuinely dead weight, and can be treated as such. No-write/read is where a decade of intellectual property sits with no owner and no alerting. For each system your team has in that cell, name the person who would notice a request against it tomorrow. When the honest answer is a dataminer, the endpoint already has a value to someone outside the company.
Ranked by verification strength, evidence, and original report placement.
A 12-terabyte archive of internal Valve game builds, source code and early assets spanning 2003 to 2013 has leaked online, dubbed the "Steam2 Teraleak".
Valve dataminer Gabe Follower wrote: "No hacking involved, just verified that everything in Steam2 Teraleak was obtained via a publicly accessible endpoint. It's Valve's fault."
The files come from Steam2, Valve's legacy content delivery system, which packaged game content into older formats.
Valve migrated to its modern SteamPipe infrastructure in 2013, and Follower said that transition is why the leaked material only covers the period before 2013.
The archive includes early development versions of Portal 2, Left 4 Dead and Counter-Strike: Global Offensive alongside long-canceled projects, with playable Portal 2 builds surfacing from as early as July 2009.
Follower said one of the earliest CS:GO builds was discovered in the archive, from when the game was essentially a heavily modified version of Counter-Strike: Source.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 30, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
Valve's leaked setup videos settle the Steam Frame's hardware. Price is the last blank2 distinct publishers
build
Epic confirms a native Linux launcher, but the anti-cheat job posting is the real tell1 distinct publisher
product
RingCentral lost 1.6 million records to a phone call, not a missing patch1 distinct publisher
security
Eight warehouses down, six brands notifying: the Ceva outage nobody's plan modelled2 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single outlet relaying a single dataminer
Every load in this story is carried by one chain: Gabe Follower's posts, quoted by Dexerto. The 12TB figure, the 2003-2013 span, the public-endpoint mechanism, the contents list — none of it has a second witness, a published file manifest, or a word from Valve. Dexerto does flag what is unverified, notably the absence of any confirmed Episode 3 build, which is honest reporting and also a map of how much is still assertion.
Visible community activity, unmeasured spread
What is observable is people digging: builds being opened, models identified, duplicates filtered. What is not observable is scale — no mirror count, no download figure, nothing on how widely the 12TB is held. And the response side is empty: Valve has not spoken, and nothing here says the endpoint that reportedly served the files has been shut.
Reveal framing, inventory substance
"Reveals" is doing more work than the findings support: much of what is described is early builds and asset folders whose novelty the dataminers themselves have not finished establishing. Dexerto earns credit for refusing the easy Episode 3 headline and naming the duplicate-and-placeholder problem. The overstatement sits less in the language than in the proportions — the durable finding, that a system retired in 2013 was apparently still handing out reads, gets a paragraph, while F-Stop gets the enthusiasm.
Everyone speaking benefits from this version
Follower's standing as a Valve dataminer rises with the size of the find, and he assigns fault in five words. A gaming outlet gets Portal and Episode 3 into a headline. Valve, the only party who could confirm how the files got out, benefits from saying nothing at all. None of that makes the account false; it does mean no voice in it is positioned to challenge it.
Plausible mechanism, thin corroboration
The core narrative hangs together — a legacy delivery system left reachable after a 2013 migration is a familiar and entirely credible failure — and Dexerto reports it with visible caution. But credibility is not confirmation. One publisher, one source, no company response and an unfinished audit of the contents put a firm ceiling on how much of this should be treated as settled today.