12TB Steam Leak Reveals Over a Decade of Lost PC Games

▼ Summary
– A massive data leak dubbed the ‘terarelease’ has surfaced, containing over 12TB of content from Valve’s defunct Steam2 server architecture spanning 2003 to 2013.
– The leaked data includes thousands of depots with public releases as well as previously unseen pre-release, prototype, and playtest versions of various games.
– The leak ends in 2013 because that year marked Valve’s transition from the proprietary Steam2 system to the modern HTTP-based SteamPipe distribution method.
– Analysts Gabe Follower and Scolcer confirmed the data was obtained via publicly accessible API endpoints without passwords, attributing the breach to Valve’s lack of protection.
– This event has revived interest in lost archival content, revealing that materials once thought inaccessible were actually available for download on aging machines.
A massive 12TB data leak has surfaced, exposing over a decade of previously inaccessible PC games from the Steam platform. The archive, dubbed the “terarelease,” contains content spanning from 2003 to 2013, offering an unprecedented look into the history of Valve’s digital distribution network. This collection is circulating via BitTorrent and appears nearly impossible for the company to fully eradicate from the internet.
The dump represents a comprehensive snapshot of Steam’s obsolete Steam2 server architecture. It includes thousands of “depots,” which are essentially containers for game files. These depots hold not only public release builds but also rare pre-release prototypes, playtest versions, and other developmental assets for titles published by Valve and third-party developers. For years, archivists considered many of these early versions lost, as they were no longer available through official channels and existed only on aging local machines.
The Shift to SteamPipe
The leak’s timeline ends abruptly in 2013 because that year marked Valve’s transition from the proprietary Steam2 system to the modern SteamPipe infrastructure. This upgrade replaced custom file distribution formats with standard HTTP file trees. The change eliminated update approval bottlenecks and optimized patch downloads by using file differentials rather than redistributing entire game files. Consequently, the old Steam2 servers were decommissioned, taking their unique data structures with them.
Despite the belief that this content was gone forever, investigators have found that the leaked material was not stolen through a breach of internal security. Instead, it was extracted from endpoints that remained publicly accessible. Gabe Follower, a prominent Valve data miner, stated on social media: “verified that everything in Steam2 Teraleak was obtained via a publicly accessible [API] endpoint. It’s Valve’s fault…”
This assessment was echoed by Scolcer, a Spanish-language Valve analyst and streamer, who noted that the data was exposed due to a lack of access controls. According to Scolcer, the teraleak was “obtained from a site that was 100% accessible to the public. It was there for everyone to download. No passwords. Nothing. Hidden in plain sight, but with no protection whatsoever.” The incident highlights how legacy systems can leave vast amounts of corporate intellectual property vulnerable if proper archival protocols are not maintained during infrastructure migrations.
(Source: Ars Technica)



