PRACTICAL GUIDES
Steam phishing and API keys: protect your CS2 skin account
Verify the domain, sign-in, trade offer and API key before approving a skin transfer.
1. Distinguish Steam OpenID from a fake window
A genuine sign-in redirects to a secure steamcommunity.com page with the exact address visible in the browser. An overlay can imitate browser chrome. A manager, bot or support agent never needs your password, QR approval, Steam Guard code or session file in chat.
- The address is entered or inspected manually
- The form is hosted on steamcommunity.com
- No secret is sent to a person or bot
2. Recheck every trade offer
Before mobile confirmation, compare the recipient’s name, level, registration details and items with the transaction. A cancelled offer followed by a similar bot is a common substitution pattern. Never rely only on an avatar, saved name or message on a third-party site.
- Recipient data matches the transaction
- Items are checked inside Steam
- An unexpected replacement is not confirmed
3. Control API keys and active sessions
An unknown Steam Web API key can help an attacker monitor and replace trades. Inspect the API-key page, authorised devices and login history, then revoke anything you did not create. After a password change, close other sessions and rotate the trade URL.
- No unknown Steam API key remains
- Unneeded sessions are closed
- The trade URL is rotated after an incident
4. Respond in the right order
If compromise is suspected, stop trades, change the password from a clean device, close sessions, revoke API keys and secure email. Preserve URLs, timestamps, messages and trade IDs, then contact Steam Support. Do not pay recovery scammers who promise to return items for a fee.
- Trades stop until the account is clean
- Access is recovered from a trusted device
- Evidence goes to official support
FAQ
Does a skin site need my Steam API key?+
A normal user should not create a key because a site, bot or stranger requests one.
Does a bot avatar prove identity?+
No. Names and images are copied; verify the recipient and offer itself.
What if I already entered details on a phishing page?+
Change the password, close sessions, revoke unknown API keys and contact Steam Support immediately.
