How Steam trading accounts actually get emptied

Almost nobody loses a CS2 inventory to a guessed password. The accounts that get cleaned out belong to people who had a strong password, had Steam Guard on, and still watched their items leave. The attacks that work go around authentication rather than through it.

There are four that matter. None of them are exotic.

1. Web API key theft, the quiet one

Steam lets an account register a Web API key. Anything holding that key can read your inventory and, critically, see and act on trade offers programmatically. A hijacker who gets into your account for sixty seconds does not need to steal anything in that minute. They register an API key, log out, and wait.

From then on, every trade you send can be cancelled and replaced with an identical looking offer to a different account. You confirm it in your authenticator, because it looks exactly like the trade you just created. The items go to them.

This is why an account can appear healthy for weeks and then empty in a single trade. Check whether a key is registered on your account, and revoke it if you did not deliberately create one for a tool you still use.

2. Fake sign-in pages

"Sign in through Steam" is a real, legitimate flow, which is exactly what makes the fake version effective. The counterfeit is often a fake browser window drawn inside the page — it has a fake address bar, a fake padlock, and it looks correct because it was built to.

The reliable test: try to drag the window outside the browser. A real popup moves beyond the edge of the page. A drawn one cannot. Failing that, never sign in from a link someone sent you. Open Steam yourself in a new tab.

3. Stolen session cookies

A logged-in session is a cookie. Malware that reads that cookie does not need your password or your Guard code, because the session is already authenticated. This is what most "free skins" downloads, cracked cheat loaders and random Discord executables are actually for.

If you suspect anything ran on your machine, changing your password is the important step: it invalidates existing sessions everywhere. Deauthorising other devices in Steam does the same for the ones you do not recognise.

4. The confirmation you did not read

Trade confirmations in the mobile authenticator show what is leaving and what is arriving. Under time pressure — a trade "expiring", a middleman "waiting" — people approve on muscle memory. Read the item names on the confirmation screen, not on the page that asked you to open it.

If it has already happened

In this order, because the order matters:

  • Change your Steam password. This kills every active session.
  • Revoke the Web API key, or the attacker keeps their access through it.
  • Deauthorise all other devices.
  • Run a malware scan before logging back in, or you will simply hand over the new session too.
  • Then contact Steam Support. Items already traded away are rarely recoverable, which is why the first four steps come first.

Two settings worth checking right now

Have the mobile authenticator, not email Guard. Email Guard satisfies Steam's 15-day requirement but leaves trades subject to holds, and an email inbox is a softer target than a phone app.

And keep your revocation code somewhere you can actually find it. It is the only thing that lets you detach an authenticator you no longer control. People discover they have lost it at precisely the moment they need it.

Every account we sell arrives with its own email inbox, its own password and the full Steam Guard set including that revocation code, so the security above is yours to manage from day one rather than shared with anybody. See the current tiers.