Loading...

13TB Steam Leak Exposes Beta Builds Spanning Valve’s First Decade

Key takeaways

  • A 13-terabyte archive of Steam data from 2003-2013 leaked online via a publicly accessible endpoint, containing beta builds of Portal 2, Left 4 Dead 2, and hundreds of other games.
  • Elan Ruskin, the former Valve developer who led Portal and Left 4 Dead, stated that all valuable ideas made it into the final releases and discarded content wasn't worth preserving.
  • The leak's 10-year span coincides with Steam's 2003 launch and SteamOS's 2013 release, suggesting Valve's storage system transition may explain why no data past 2013 was included.
  • Community researchers are cataloging the archive on GitHub while exercising caution about speculative claims, particularly regarding unconfirmed Half-Life 2: Episode Three materials.

Roughly 13 terabytes of Steam depot data spanning 2003 to 2013 surfaced online within a 24-hour window at the end of August 2026, distributed through torrent files and quickly drawing intense scrutiny from gaming communities. The leak—referred to as Steam2 by researchers—contains beta builds, development assets, and internal iterations of thousands of games, including Portal 2, Left 4 Dead 2, Dragon Age: Origins, Batman: Arkham Asylum, Counter-Strike: Global Offensive, F-Stop, and what may be early builds of Half-Life 2: Episode Three.

The leak’s authenticity has been confirmed by multiple sources within the industry, though the identity of the person or group responsible remains unconfirmed. Security researcher Gabe Follower initially publicized the breach, reporting that the data was accessed through a publicly accessible endpoint on Steam’s infrastructure—essentially a URL that should have required authorization but apparently did not.

The Scale of the Breach

A Decade of Development Data

The 13-terabyte figure deserves particular consideration when placed against the gaming landscape of the 2003-to-2013 period. Video game file sizes in that era operated under vastly different constraints compared to modern standards; a decade later, single-player campaigns routinely exceed the totality of some 2010-era releases. The sheer amount of data—despite predating contemporary bloat—underscores the breadth of Valve’s development infrastructure during that decade.

Timing and Storage Systems

The leak’s 10-year window aligns curiously with two major Valve milestones: Steam’s original launch on September 12, 2003, and the December 2013 release of SteamOS 1.0. According to Gabe Follower’s analysis, Valve transitioned to a new storage system in 2013, potentially explaining why the leaked depot data terminates at that point rather than continuing into the present day.

Historical Development Era

Early 2000s Valve development spanned some of the studio’s most significant output, including the Half-Life and Portal franchises, the Left 4 Dead series, and the original development phase of titles that would define PC gaming for years. Accessing builds from that era provides a rare window into how these foundational games evolved from concept through release.

What’s Inside the Archive

Portal and Half-Life Iterations

The beta builds contained within the leak span multiple flagship Valve properties. Portal 2 appears in multiple developmental iterations, offering potential insight into how puzzle design, physics mechanics, and narrative structure shifted over the game’s production cycle leading to its April 2011 release. Left 4 Dead 2, released in November 2009, has similarly appeared in pre-release form.

The most speculative discovery involves potential builds of Half-Life 2: Episode Three, the long-mythologized sequel to 2006’s Episode Two that Valve never officially released. Unconfirmed claims about EP3 materials circulating within gaming communities warrant skepticism, given decades of false Half-Life 3 rumors.

Third-Party Titles and Experiments

Beyond Valve’s own releases, the depot data includes builds of third-party titles that used Valve’s Source engine or distributed through early Steam infrastructure. Dragon Age: Origins and Batman: Arkham Asylum represent the variety of non-Valve IP present in the archive. Counter-Strike: Global Offensive appears alongside technical experiments like F-Stop, a Valve prototype that never received an official release.

Developer Commentary on Leaks

Elan Ruskin, a former Valve developer who served as lead on Portal, Portal 2, and the Left 4 Dead series, issued a comment on X regarding the leaked prerelease builds. His statement addressed the Portal 2 and Left 4 Dead 2 iterations specifically: “Listen, every good idea we had went into the final thing we shipped, and anything not in the final version was not a good idea.”

The comment reflects a common reality in game development—that release versions represent the culmination of iterative refinement, with cut content typically removed for technical, design, or practical reasons rather than being abandoned prematurely. Ruskin’s framing suggests the community would find little of value in examining unreleased iterations over the officially shipped products.

Videos demonstrating gameplay from beta builds have emerged online, suggesting some individuals have successfully extracted and executed the leaked files. Whether those functional builds run on modern systems or require period-appropriate hardware or emulation remains unclear from available reports.

The Security Breach

Endpoint Vulnerability

The breach’s mechanics center on what security researchers call an “endpoint”—in this context, a URL within Steam’s backend infrastructure designed to serve data to authorized requesters. While endpoints are typically publicly discoverable by design, they should remain inaccessible without proper authentication tokens or credentials.

According to Gabe Follower’s reporting, the compromised endpoint lacked adequate authorization controls, allowing unrestricted access to the Steam2 depot data. The precise cause—whether human error in configuration, an overlooked legacy system, or deliberate exposure—has not been established.

Valve’s Silence

Valve has not issued an official public statement regarding the breach as of reporting. The company’s typical approach to security incidents involves internal investigation and remediation before public disclosure, if at all. The lack of immediate response is consistent with past Valve security events.

Community Documentation Efforts

Given the sheer volume of material and the breadth of titles involved, efforts to catalog and understand the contents have moved at a deliberate pace. A GitHub repository has emerged as a central hub for community documentation, with researchers continuing to identify specific titles and versions within the archive.

The community faces significant challenges in verifying which materials are complete, which are fragmentary, and whether executable builds can be reconstructed from the depot data. Many files within game depots consist of resource archives, intermediate compilation states, and dependencies that require specific reconstruction tools to become usable.

Researchers are also exercising caution regarding speculative claims about Half-Life properties, given the community’s history of misidentifying ambiguous file names or placeholder assets as evidence of cancelled sequels. The established practice of marking uncertain discoveries with explicit disclaimers reflects this wariness.

Historical Implications

If verification efforts confirm the breadth and completeness reported by initial sources, the Steam2 leak could rank among the largest authenticated breaches of proprietary game development materials. Earlier notable incidents include the 2020 Capcom ransomware attack and the 2011 Insomniac Games leak, though those involved more recent development data and smaller overall file quantities.

The historical value of decade-old development materials lies primarily in understanding production methodologies, discarded mechanics, and how design philosophy evolved across specific titles. For researchers studying game development practices, AI training datasets, or preservation efforts, the leak presents both opportunities and legal complications.

The 2003-to-2013 window encompasses a transformative period for PC gaming, 3D graphics evolution, and online multiplayer design. Studying how Valve’s internal teams approached these shifts provides context for understanding the commercial and critical success of the eventual releases.

The leak’s implications extend beyond mere curiosity—they underscore ongoing challenges in managing legacy digital infrastructure and the potential consequences when older systems fall out of active maintenance or oversight. Valve’s potential infrastructure consolidation in 2013 may have inadvertently left older storage systems with insufficient access controls.

Frequently Asked Questions

What was leaked and how large was it?

Thirteen terabytes of Steam depot data from 2003-2013 containing beta builds of Portal 2, Left 4 Dead 2, Dragon Age: Origins, Batman: Arkham Asylum, Counter-Strike: Global Offensive, and hundreds of other games, distributed via torrent.

How did the leak happen?

According to security researcher Gabe Follower, the data was accessed through a publicly accessible endpoint on Steam's servers that lacked adequate authorization controls, though Valve has not confirmed the exact cause.

Did Valve respond to the leak?

Valve has not issued an official statement as of reporting. However, Elan Ruskin, a former Valve developer on Portal and Left 4 Dead, commented that all good ideas from development made it into the final releases and prerelease versions would not be worth studying.

Written by
Sam Nakamura

Sam Nakamura covers gaming culture, esports, and the indie scene. With a background in competitive gaming and a deep love for JRPGs and retro consoles, Sam brings a player-first perspective to every story. If it involves a great narrative or a tournament worth watching, Sam has already written about it.