STEAMX / Rails Network / $STEAMX
Comprehensive OSINT investigation revealing misleading explorer data, 81% wash trading, critical security vulnerabilities, fake followers, 2.5 years of expired regulatory compliance, a bridge kept intentionally offline to trap user funds, and a team where the CEO left, the marketing head abandoned ship, and only one person remains running the operation. Telegram analyzed: chain halted and transactions reversed with "#CheckMate #TooSoonJr." ENS wallets traced. All channels dead since Oct 2024. Every finding live-verified with blockchain proof.
Steam Exchange Inc. (Ontario corp #002846823, Vaughan, ON) operates a crypto project claiming to build a hybrid exchange on their custom "Rails Network" blockchain (Chain ID 6278). Our investigation reveals a project built on misleading explorer data, automated wash trading, investor fees sent to a gambling casino, and a geth fork marketed as a "revolutionary" custom blockchain.
| Platform | Actual | Expected (if real) | Gap |
|---|---|---|---|
| Telegram members | 1,726 | ~5,000+ | -65% |
| Telegram (historical peak) | was ~9,000 -> now 1,726 | -- | -81% loss |
| Reddit subscribers | 1,837 | ~2,500+ | -27% |
| Discord members | 1,614 | ~3,000+ | -46% |
| Website monthly visitors | 0 | ~1,000+ | -100% |
| 24h trading volume | $766 | ~$50,000+ | -98.5% |
| GitHub stars | 1 | ~50+ | -98% |
| CMC watchlist adds | 33,887 | -- | Inflated? |
| Trustpilot reviews | 9 | ~50-100+ | -90% (7 coordinated) |
| Exchange listings | 0 CEX | 1-3+ | None |
| Date | Post | Likes | Reposts | Replies | Views | Eng% |
|---|---|---|---|---|---|---|
| 2025-08-27 | P2P Market launch (best post) | 99 | 49 | 20 | 4,194 | 1.00% |
| 2026-01-20 | Scam warning (fake airdrop) | 47 | 30 | 17 | 2,216 | 0.56% |
| 2025-08-13 | Support reply (migration) | 0 | 0 | 0 | 222 | 0.00% |
| 2025-08-06 | Migration thread replies | 1 | 0 | 0 | 119 | 0.01% |
| Metric | Explorer Frontend | Explorer API (Real) | Discrepancy |
|---|---|---|---|
| Total Transactions | 193,823,272 | 303,418 | 638x |
| Wallet Addresses | 28,634,064 | 4,718 | 6,069x |
| Token Price | $1,807.68 | $0.061 | 29,558x |
| Channel / Project | Members | Status |
|---|---|---|
| Announcements Channel | Unknown | Silent since Oct 2024 |
| Official Chat (@SteamExchangeToken) | 228 | Private, private/inaccessible |
| Rails Network TG | 5 | Dead |
| Fantasy Friends / Portfolio Wars | 100 | Rebranded, effectively dead |
| Discord Server | 1,614 | No public content found |
| Forum (forum.steamexchange.io) | -- | Last post Nov 2025 |
| Website Monthly Visitors | 0 | BitDegree: "untracked" due to inactivity |
| Bot Address | Transactions | % of Chain | Pattern |
|---|---|---|---|
| 0x3ea13064...d4c4 | 86,835 | 28.7% | WSTEAMX/USDC swaps q30-60s |
| 0xe8e68C5B...45FB | 85,274 | 28.2% | WSTEAMX/USDC swaps q30-60s |
| 0xA1b48375...b45D | 73,239 | 24.2% | WSTEAMX/USDC + deployed contracts |
| TOTAL BOTS | 245,348 | 81.1% | All send fees to 0x0Fe858A6... |
| Real organic activity | ~57,108 | 18.9% | Over 22 months of operation |
| Date | BNB | ~USD |
|---|---|---|
| 2024-01-24 | 100.353 | ~$59,600 |
| 2024-01-16 | 88.613 | ~$52,700 |
| 2024-01-04 | 87.623 | ~$52,100 |
| 2023-08-31 | 96.726 | ~$41,000 |
| VERIFIED TOTAL (all 38 pages summed) | ~2,694 BNB | ~$700K-$800K |
| Date | BNB | Tx Hash (click to verify) |
|---|---|---|
| 2024-01-24 | 100.35 | 0x333f14c7... |
| 2024-01-16 | 88.61 | 0x5f1c6a45... |
| 2024-01-04 | 87.62 | 0xe78bf6f5... |
| 2024-01-02 | 101.77 | 0x13d14e82... |
| 2023-12-25 | 92.82 | 0xeaf932a8... |
| 2023-12-16 | 76.93 | 0xdefa624d... |
| 2023-08-31 | 96.73 | 0x34fb5477... |
_platformFee = 4, _marketingFee = 3 (7% combined, sent as BNB). Owner can change wallet addresses via setPlatformAddress() and setMarketingAddress().swapAndLiquify which converts STEAMX to BNB and sends ~0.041 BNB to platform wallet, ~0.055 BNB to marketing wallet.0x516bb07d.... Zero BNB retained in either wallet.On-chain transaction analysis proves the wash trading is an inside operation:
Additionally:
Both mainnet and testnet expose admin, debug, personal, and txpool modules. This enables:
personal_listWallets exposes keystore file paths, account addresses, and creation timestamps to anyone:--allow-insecure-unlock not set), so transactions can't be signed remotely without the password. But the exposure leaks the server directory structure (/rails/data/keystore/), confirms active account management (2 accounts created days ago), and combined with the exposed admin/debug modules creates a dangerous attack surface if passwords are ever compromised. Testnet exposes 4 accounts. All hold zero balance.The V2 BSC contract (0xc0924e...) contains an unlock() function that allows the previous owner to reclaim ownership after a timelock expires, even after "renouncing." The SourceHat audit only covered V1 - this backdoor was NEVER AUDITED. Ownership is NOT renounced on either V1 or V2.
The SourceHat audit (July 4, 2021) explicitly documented that the V1 contract's "5% liquidity fee" does NOT add liquidity to the LP:
Investors were told 5% of every trade went to "liquidity." It went to a team wallet as BNB. The V2 contract made this explicit with 4% Platform Wallet + 3% Marketing Wallet (7% to team as BNB), plus owner-callable setter functions to change all wallet addresses and fee percentages at any time: setPlatformFeePercent(), setMarketingFeePercent(), setPlatformAddress(), setMarketingAddress()
A technical breakdown of what was built, what it cost, and how long it takes -- vs what they claim
| Component | What They Call It | What It Actually Is | Setup Time | Cost |
|---|---|---|---|---|
| Blockchain | "Rails Network" with "innovative PoWbA consensus" | go-ethereum (geth) fork renamed "Grails". Changed chain ID to 6278, genesis nonce to 0x6278006278006278. PoW config with 2 hardcoded miners. Zero original consensus code. | 1-3 days | $0 (MIT license) |
| Explorer | "Rails Network Explorer" | Blockscout fork. Running in DEVELOPMENT mode. Shows stock placeholder data (193M tx, $1,807 price) instead of real API data (~303K tx, $0.061) due to React Query hydration bug they never fixed. | 4-8 hours | $0 (open source) |
| DEX | "Steam Exchange DEX" | Uniswap V2 fork (UniswapV2Router02 + Factory). Neville's GitHub literally contains a fork of the Uniswap interface. | 2-4 hours | $0 (GPL license) |
| Subgraph | "Rails Subgraph" | The Graph Protocol fork. Neville's GitHub contains a fork of graph-node and graph-tooling. | 2-4 hours | $0 (open source) |
| Documentation | "Technical Docs" | Docusaurus (Facebook open-source docs framework) hosted free on Netlify. | 1-2 hours | $0 (free tier) |
| Infrastructure | "Enterprise-grade" ($27K/month claimed) | 6 Hetzner Cloud VPS servers (5.78.x.x / 5.161.x.x range). nginx 1.18.0 (2020). Let's Encrypt SSL. Cloudflare free tier for CDN. Static sites on Netlify free tier. | 2-4 hours | ~$60-120/mo |
| Token (BSC) | "STEAMX Ecosystem Token" | Standard BEP-20 reflection token (SafeMoon-style). 13% tax: 4% platform, 3% marketing, 4% LP, 2% reflection. Common template. | 1-2 hours | ~$5 deploy gas |
| Wash Trading Bots | "Active ecosystem" / "trading volume" | 3 bot wallets running automated WSTEAMX/USDC swaps every 30-60s. Simple ethers.js script. Produces 81.1% of all chain transactions. | 2-4 hours | ~$0 (gas on own chain) |
| TOTAL ESTIMATED BUILD | 2-4 weeks | ~$60-120/mo | ||
A forensic analysis of every public GitHub repo associated with Steam Exchange.
| Metric | Ethereum | Solana | Steam Exchange (ALL combined) |
|---|---|---|---|
| Public repos | 308 | 116 | 6 |
| Main repo stars | 50,966 | 14,852 | 1 |
| Main repo forks | 21,878 | 5,603 | 0 |
| Contributors | 1,226 | Hundreds | 1 (contractor) |
| Custom consensus code | Millions of lines | Millions of lines | Zero lines |
| Tests | Extensive | Extensive | Zero |
| CI/CD | Multiple pipelines | Multiple | None |
| Code reviews | Mandatory | Mandatory | None (self-merged) |
| Original commits | Hundreds of thousands | Hundreds of thousands | ~40-50 total |
| Service | Estimated Monthly Cost |
|---|---|
| Hetzner CX31 VPS x2 (mainnet RPC + depot) | ~$22 |
| Hetzner CX21 VPS x4 (testnet nodes) | ~$24 |
| Domain registration (steamexchange.io + .ca) | ~$3 |
| Cloudflare (free tier) | $0 |
| Netlify (free tier for static sites) | $0 |
| Let's Encrypt SSL (free) | $0 |
| Discourse forum (self-hosted) | ~$0 (on existing VPS) |
| TOTAL | ~$49-80/month |
What they told investors vs what we proved. Every quote is from official press releases, interviews, and their own website.
What they promised vs what was delivered after 5+ years of development.
Real investors documenting fraud allegations on CoinMarketCap. These posts confirm multiple findings from our investigation.
"watch this shit dump and this team of frauds get away with the stuck funds. Waiting for the bootlickers tom, papa rne, and other cocksuckers to come say i'm a fudder without ever giving out arguments because they have none. When you are too busy blowing neville and his brother, you have no time to do your research"
"how do we sue the team man? They are not getting away like this. We need our USDC out."
"How much proof do you want after 6 years? nothing accomplished for this assumed binance killer. And stealing funds is a fact, they had thousands BNB; where did it go? Alledgedly scammed (by Neville himself probably) and you morons believe everything he says."
| Giveaway | Prize Pool | Winners Announced? | Paid? |
|---|---|---|---|
| Holiday 2022 | 17 prizes + $500 SickKids | 17 names listed | Unverifiable |
CrossRails June 2024![]() | $3,500+ (extended +50%) | No evidence | No evidence |
| Launchpad Sept 2024 | $10,250+ | No evidence | No evidence |
| $5 Bridge Bonus | $5 per qualifying wallet | No evidence | No evidence |
Official Steam Exchange tweet: "Recently, we encountered a security incident at SteamX involving unauthorized sell transactions triggering alerts in our monitoring systems. We immediately took action, temporarily halting some tools."
Source: x.com/Steam_Exchange/status/1771653054128910633
An unauthorized transaction caused a 110% price pump. The team's response -- in their own words from Telegram:
User andrew_parker: "After Migration, I lost 3.6 million SteamX coin" -- balance dropped from ~$400 to less than $1. Team explained a "550:1 split" was applied. User boggs: "544,000 SteamX all gone." User Kim_Arjero_Carino: "from 655,000 to 1.191... OMG."
Source: forum.steamexchange.ioAll 9 reviews posted in a 5-day window: August 5-8, 2025 — approximately 3 months after the CryptoFlan article. All 4-5 stars. Same language patterns: "transparent," "trustworthy," "devs doxxed." Zero negative reviews despite documented user complaints on the forum and BSC token showing ZERO daily transfers. Textbook coordinated review stuffing.
Source: TrustpilotUsers attempting to move old tokens from Trust Wallet to MetaMask were limited to one token at a time with 15% lost on each transfer due to built-in tax. With 550 tokens to migrate, cumulative losses were enormous.
Source: forum.steamexchange.ioContract enforces: holders with 0.5%+ of supply can only sell 20% of their balance at a time, then must wait 24 hours. Transactions exceeding 0.1% of total supply are blocked entirely. Combined with 13% sell tax, exiting a position is extremely punitive.
Source: SourceHat Audit"Steam tokens disappearing from Trustwallet. I looked at Bscan and it is showing up in another wallet"
"Anybody know why the twitter is botted?"
"I have $50k of steamx in my coinstat app.. I can't find the coin in my trustwallet"
"I've been trying to sell my STEAMX tokens for weeks, but every time I try, the transaction fails"
"I can see STEAMX token in my account but I do not see any value of this token.. Value shows Zero."
V1 (0xf6d4...): 2,061 holders with worthless tokens. V1 LP was drained by the deployer (confirmed Remove Liquidity transactions Oct-Dec 2023). V1 holders were NOT automatically migrated -- left behind.
V2 (0xc092...): 19,228 holders at $0.0003. LP drained to $8.31 -- only 1 LP token holder remains (the deployer). Zero 24h transfers. Migration tool reported broken by multiple users. Listed on ZERO centralized exchanges.
Team tokens: 24.91% (24.91B tokens) on 6-month Unicrypt vest ending ~Jan 2022. After unlock, deployer executed hundreds of small PancakeSwap swaps (0.03-0.08 BNB each) -- a systematic drip-sell strategy. Ownership never renounced despite audit recommendation.
All findings from publicly-served HTML that any browser receives when visiting these sites.
| Subdomain | Server | Framework | Version | Last Updated | Issues |
|---|---|---|---|---|---|
| steamexchange.io | Cloudflare | Bootstrap 5 + vanilla JS | Font Awesome 6.0.0-beta3 | Jan 2025 (15mo old) | og:image = "UPDATE ME" |
| depot.steamexchange.io | nginx/1.18.0 (exposed) | React (CRA) | Unknown | May 2024 (2yr old!) | Zero security headers. No CDN. |
| swap.steamexchange.io | Cloudflare+Netlify | Next.js + Tailwind | Unknown | Unknown | HSTS present |
| docs.steamexchange.io | Cloudflare+Netlify | Docusaurus v2.0.0-beta.17 | 4-year-old BETA | Unknown | Beta from 2022, current is v3.x |
| forum.steamexchange.io | nginx (hidden ver) | Discourse 3.2.0.beta4-dev | Dev build + git commit exposed | Unknown | Exact commit hash public: 2477bcc... |
| explore.steamexchange.io | nginx/1.18.0 (exposed) | Next.js + Blockscout v1.32.0-alpha | Alpha build | Unknown | DEVELOPMENT MODE on prod! |
envs.js file reveals:debug_memStats RPC method returns live server memory data to anyone who asks:0xba01646C... (appears in many pending tx -- likely the DEX router)| Software | Their Version | Current Stable | Age | Risk |
|---|---|---|---|---|
| nginx | 1.18.0 | 1.27.x | 6 years (Apr 2020) | HTTP request smuggling, buffer overflows. Multiple CVEs since 1.18 including CVE-2021-23017 (DNS resolver crash), CVE-2022-41741/41742 (mp4 module memory corruption) |
| Go | 1.20.7 | 1.23.x | ~3 years (Aug 2023) | 50+ security fixes since 1.20.7. Includes HTTP/2 rapid reset DoS (CVE-2023-44487), path traversal, TLS vulnerabilities |
| go-ethereum | Fork from Jun 2024 | v1.14.x (2026) | ~2 years behind | Multiple consensus and p2p security advisories since their fork date. Never patched. |
| Docusaurus | v2.0.0-beta.17 | v3.7.x | 4 years (early 2022) | Running a BETA from 2022. Multiple XSS and dependency vulnerabilities patched in stable releases |
| Discourse | 3.2.0.beta4-dev | 3.4.x stable | Dev build | Running a dev build with git commit hash exposed publicly (2477bcc...) |
| Blockscout | v1.32.0-alpha | v6.x stable | Alpha build | Alpha on production. APP_ENV="development". Sentry DSN + WalletConnect ID exposed. |
"UPDATE ME". After 5 years of development and claimed $27K/month infrastructure costs, they never filled in a basic meta tag. This is the level of attention to detail being applied to a project that holds people's money.| Header | Main Site | Depot | Explorer | Forum |
|---|---|---|---|---|
| HSTS | Missing | Missing | Missing | Yes |
| CSP | Missing | Missing | Missing | Yes |
| X-Frame-Options | Missing | Missing | Yes | Yes |
| X-Content-Type | Missing | Missing | Yes | Yes |
| Referrer-Policy | Missing | Missing | Yes | Yes |
7 of 9 reviews posted on August 5-6, 2025. Nearly identical language praising "transparency." Posted 2.5 months after CryptoFlan's critical Medium article. 5 of 7 reviewers have ONLY 1 review on their entire Trustpilot profile (classic sock puppet indicator). Reviewers span 6+ countries (Argentina, Canada, Spain, Philippines, Indonesia, UK) but all posted the same day. NONE of these names appear on the Steam Exchange community forum -- complete disconnect from actual users.
Verify: trustpilot.com/review/steamexchange.io/rails/data/keystore/| Chain | Contract | Address |
|---|---|---|
| Ethereum | USDC | 0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48 |
| Ethereum | Bridge | 0x2Add4242B7eb8Aa167ee374f706B8DB28258C708 |
| BSC | STEAMX Token | 0xc0924edefb2c0c303de2d0c21bff07ab763163b5 |
| BSC | Migration | 0xdB6D6C6188AAD23C8443C280BbB53993C4434622 |
| Polygon | USDC | 0x3c499c542cef5e3811e1192ce70d8cc03d5c3359 |
| Polygon | Bridge | 0xbA05AFC65BEF2E2bdfF7E248C7908e4b72e5545C |
| Rails | USDC | 0x0000000000000000000000000000000000627801 |
| Rails | Bridge | 0x0000000000000000000000000000000000627803 |
| Rails | Bridge Bonus | 0x00fDD1afbF69f2dFC8d668B4A4f64d8aE902C8b6 |
Not everyone speaks blockchain. Here's what the key technical terms mean in simple English.
Individuals connected to the Steam Exchange network flagged for further investigation. Claims listed are from community reports and require independent verification.
| Project | Chain | Launch | Team Doxxed? | Status | Delivered? |
|---|---|---|---|---|---|
| B.O.T. NFT | Solana | Jan 2023 | No (zero team on site) | Dead | No — bot never existed |
| Dworfz | Solana | Mar 2023 | No | Dead (0.02 SOL floor) | No — "gamified tools" never built |
| Puffsterz | Solana | May 2023 | Partially (LLC filing) | Dead (0 daily txs) | Smoke shop only. NFT utility = nothing. |
| VibeTribe | Solana | Sept 2023 | No | Near-dead | "Youth apparel" from a vape shop |
| Moowaan | ETH + SOL | Oct 2024 | No | Dead ($1.56/day) | Dev abandoned (CTO) |
| Steam Exchange | BSC → Rails | Jun 2021 | Partially | Zombie (0 daily txs) | ~$700K-$800K → Stake.com |
| Category | Evidence | Weight | Score |
|---|---|---|---|
| Fund Misappropriation | ~2,694 BNB to Stake.com gambling. 100% one-way, zero returns. 500x bet escalation. Loss-chasing. LP drained. Team tokens drip-sold. | 20 | 20/20 |
| Market Manipulation | 81.1% wash trading. 3 team-funded bots. Sole LP provider. Fake volume on private chain. ~$10M-$13.5M trading volume taxed. | 15 | 15/15 |
| Regulatory Violations | MSB expired 2.5+ years (up to $2M fine + 5yr prison). Not registered with OSC. Fabricated "FINTRAC entity framework" language. | 15 | 15/15 |
| Centralized Control | 2-node geth fork. Halted chain, killed RPC, reversed all transactions (admitted on Telegram: "#CheckMate #TooSoonJr"). Chain reset with balance restoration. Fake "USDC" minted by admin. 99.8% of genesis to 1 wallet. | 10 | 10/10 |
| Smart Contract Risk | V2 unlock() backdoor (never audited). Ownership not renounced. 13% tax. Owner can change all wallets. Anti-whale for investors only. | 10 | 9/10 |
| Security Posture | All 8 RPC modules exposed. 6 server IPs leaked. Keystore paths. nginx 6yr. Go 3yr. Dev mode on prod. Zero security headers. | 10 | 9/10 |
| Team Integrity | CEO left. VP left. Marketing left. Sole operator. Brother in pump-and-dumps. Career unverified. Virtual office. Promoters fabricate credentials. | 10 | 8/10 |
| Social Manipulation | 62% fake followers. 0 website visitors. All 9 Trustpilot reviews appeared Aug 2025 (3mo after CryptoFlan article). Paid press only. Sock puppet CMC defenders. BitDegree: "untracked" due to inactivity. | 5 | 4/5 |
Product Delivery![]() | 5 years: CEX just entered "Closed BETA v1.0" (April 2026) after 5 years of promises. DEX has $5K daily volume with 1,886 automated bot txs ($2.76 avg). CrossRails cross-chain swap non-functional. Wallet, RNS, DAMNFT, LandXchange all "Coming Soon." Reddit: 1,837 subscribers, zero searchable posts in 5 years. | 5 | 5/5 |
| TOTAL RISK SCORE | 100 | 91/100 | |
Summary of potential offenses with corresponding evidence, applicable laws, and verification links.
You don't have to take our word for anything. Here's how to check the key claims yourself in under 5 minutes.
mainnet.steamexchange.io:function unlock()