Almost nobody loses a backpack to a scam that looks like a scam. They lose it to a trade that looked completely normal right up until the confirmation screen, which they did not read because they had read forty of them that week.
Every attack below is still working today. Every one of them is defeated by a habit that takes seconds.
1. The API-key hijack
This is the one that empties backpacks, and it is far more sophisticated than most people realise. It does not need your password.
- You log in somewhere you should not have — a fake trading site, a fake giveaway, a fake vote-for-my-team page.
- The attacker captures your session and quietly registers a Steam Web API key on your account.
- You go about your day. Days or weeks later you set up a legitimate trade with a legitimate trader.
- Their bot, watching through that API key, cancels your real trade the instant you send it and immediately fires an identical-looking offer from a cloned profile with the same avatar and name.
- You confirm on your phone without re-reading, because you were expecting a confirmation. Items gone.
2. The login window that is not a window
A “Sign in through Steam” popup appears. It has a title bar, a padlock, a URL showing steamcommunity.com, the works. It is a `div`. The whole thing is drawn inside the page you are already on, and everything you type into it goes straight to the attacker.
The test takes one second: try to drag the popup outside the browser window. A real browser window can leave. A fake one is trapped inside the page, because it is part of the page. Nothing else about it will give it away — the URL bar is a picture.
3. QR-code login phishing
A newer one, and it catches careful people. Someone sends you a Steam QR code to “verify” something, or a site shows you one to log in. You scan it with the Steam mobile app and approve.
What you have actually done is log them into your account. The QR flow is designed to let you sign yourself in on another device; it does not care whose device it is. Never scan a Steam QR code that arrived from another person, for any stated reason.
4. The quickswitch
The oldest trick and still effective, because it exploits attention rather than technology. You agree on a Professional Killstreak Australium. Somewhere between the trade window and the confirmation, it becomes a plain Australium — or the unusual becomes the same hat with a cheaper effect, or the Factory New becomes a Battle Scarred.
The variants are endless because TF2 is full of items that differ by one word. Burning Flames and Scorching Flames. Specialized and Professional. Genuine and Unique. The defence is the same as for the API-key attack: read the confirmation screen, by item, every time.
5. The fake middleman and the fake admin
A third party appears to “hold” the items and make the trade safe. Sometimes they arrive with a SteamRep admin badge on their profile, a convincing rep thread and a friend who vouches for them. All of it is free to fabricate.
- Nobody legitimate needs to hold your items to make a trade work.
- Real SteamRep admins do not message you first, and do not intervene in trades.
- A “vouch” from an account you also just met is not a vouch.
- Profile comments, group memberships, badges and rep threads are all trivially faked or bought.
6. The duped item sold at clean price
Not a scam in the technical sense — the item is real and the trade completes — but you have paid a clean price for something the market discounts. Duplicated unusuals from the 2019 item-server exploit still circulate and still trade below their clean counterparts.
A dupe check on backpack.tf takes fifteen seconds and is covered in more depth in how to buy TF2 items without getting burned. Do it on anything worth more than a few keys.
If it has already happened
Speed matters enormously, and the order matters more than people expect. Secure the email first — if the attacker controls that, everything else you do can be undone.
- Change your email password and check its forwarding rules and recovery addresses.
- Change your Steam password.
- Deauthorise all devices from Steam Guard, which invalidates every active session.
- Revoke your Steam Web API key at steamcommunity.com/dev/apikey.
- Run a malware scan — session theft sometimes comes from a local infostealer rather than a phishing page.
- Open a Steam Support ticket with the trade IDs. Recovery is not guaranteed, but it is impossible without a ticket.
The habits, condensed
- Read the other side’s items on the mobile confirmation screen, every trade, without exception.
- Never log into Steam anywhere except a window you opened yourself, and drag-test any popup.
- Never scan a Steam QR someone sent you.
- Check your API key page monthly.
- Slow down when someone is rushing you. Urgency is the tool, not the emergency.
None of this is paranoia and none of it costs you anything. It is five habits that, once they are automatic, remove nearly the entire surface area these attacks depend on.
Common questions
- What is the Steam API key scam?
- An attacker who has captured your session registers a Steam Web API key on your account. Their bot then cancels your outgoing trades and replaces them with identical-looking offers from a cloned profile, hoping you confirm without reading. Check steamcommunity.com/dev/apikey and revoke anything you did not create.
- How do I spot a fake Steam login page?
- Try to drag the popup outside your browser window. A genuine browser window can be moved off the page; a fake one is drawn inside the page and cannot leave. The URL bar and padlock inside a fake popup are just images.
- Is it safe to scan a Steam QR code someone sends me?
- No. Scanning and approving a Steam QR code signs that code’s owner into your account. The feature exists so you can log yourself in on your own second device. Never scan one that came from another person.
- What should I do first if my Steam account is compromised?
- Secure your email password first, then change your Steam password, deauthorise all devices, revoke your Steam Web API key, scan for malware, and open a Steam Support ticket with the trade IDs.
