The strangest part of losing skins to an API scam is that nothing looks broken. You are not locked out. No password reset email arrives. You opened the trade yourself, checked the mobile authenticator, tapped confirm, and the items still went to a stranger. Somewhere between those two taps, a program you never installed rewrote the deal. The tool it used was a Steam Web API key sitting quietly on your account.

What a Steam API key actually is

An API key is a credential that lets an outside program act on your account. Valve built the system for developers and for trading platforms that need to read inventories and process offers automatically. Nothing about it is sinister. Most Steam users have never generated one and have no reason to.

The important detail is what a key does when it ends up in the wrong hands. By itself it is not a password. Combined with a stolen login session, it lets someone watch your trade offers and swap them out mid-exchange. That is why the account keeps working normally while the inventory drains. The attacker does not want your account. They want a few seconds of control over your next trade.

How the theft actually happens

It starts with a login on a site that is not Steam. The bait varies: a free item waiting to be claimed, a request to vote for someone's artwork in a contest, a small tournament signup, or a lookalike steamcommunity address with one character changed. Malicious browser extensions can do the same job without any login page at all, activating a key on the account while you go about your day.

Once the key exists, the waiting begins. When you finally send a real trade offer, the offer is cancelled automatically. A near-identical one appears from a profile built to mirror the person you were trading with: same avatar, same display name, close enough at a glance. Steps two and three happen inside a few seconds, so the replacement lands while you still have the authenticator open. You confirm out of habit and the items are gone.

Check your account right now

Open steamcommunity.com/dev/apikey while logged in. The page shows either nothing or an active key.

The rule is simple. If a key is listed and you did not create it, your account was compromised at some point, no matter how normal everything else looks. This check takes about ten seconds and it is worth repeating any time you have logged into a third-party skin site, a stats tracker, or anything that asked for Steam credentials.

What to do if you find one

Work through these in order, from a device you trust:

  1. Scan for malware first. A new password typed on an infected machine buys you nothing.
  2. Revoke the key manually. Do not assume that changing your password removes it. Use the revoke button on the API key page and confirm the page reads empty afterward.
  3. Change your password, ideally from a different device than the one you normally trade on.
  4. Deauthorize all devices at store.steampowered.com/twofactor/manage.
  5. Generate fresh authenticator backup codes from the same page.
  6. Create a new trade URL so any saved link the attacker holds stops working.

One warning sign deserves its own line. If the key reappears within minutes of being revoked, someone still has live access to your account. Stop trading entirely and work through the list again from a clean machine.

Habits that keep a key off your account

Use the mobile authenticator rather than email codes. Email-based Steam Guard is better than nothing, but it fails the moment your inbox does. Authenticator codes live only on your phone.

Never log in through a window that another website opens for you. Go to Steam directly, type the address yourself, and look at the address bar before typing anything.

Then slow down at the confirmation screen, because that is the only moment the scam can be caught. Compare the recipient's name, profile level, avatar, and account creation date against the person you meant to trade with. If your trade history shows two nearly identical offers at the top and one of them is cancelled, the trade was hijacked. Set your inventory to private as well. Small inventories still attract attempts.

If the items are already gone

Eligible CS2 items stay Trade Protected for seven days, which allows a redirected trade to be reversed. Treat this as a genuine last resort. A reversal affects every eligible protected trade in that window and comes with a 30-day block on trading and the Community Market.

Secure the account before you do anything else. Recovering items while the key is still active only teaches you the lesson twice.

Check the API key page, revoke anything you did not put there, and read the confirmation screen before you tap it. That is most of the defense.