Sheogorath Oct 21, 2023 @ 1:37am
How does this scam even work. How did this happen to me.
I received a message through steam, which firstly I understand I shouldn't have listened too, and secondly I know I'm stupid. But they told me to trade my items to a friend right, so I did. I went to my FRIENDS ACCOUNT ON STEAM, AND CONFIRMED IT WAS THE REAL HIM. I sent the trade offer, and somehow a fake version of his account accepted it. How does this work. How is steam so stupid that I can send a trade to my actual real friend and another account can accept that trade???

For reference, I sent the trade to https://steamcommunity.com/profiles/76561199048396830/, I am 100% certain, and the account https://steamcommunity.com/id/gulqmiraharitonov was able to accept that trade. How.
< >
Showing 1-5 of 5 comments
FFL2and3rocks Oct 21, 2023 @ 1:39am 
At some point, you logged into a phishing site, which allowed their bot to sit on your account.
When you made the trade offer with your friend, the bot canceled it and made a similar trade to a different account.
Last edited by FFL2and3rocks; Oct 21, 2023 @ 1:39am
JPMcMillen Oct 21, 2023 @ 1:47am 
Check your trade history. You'll probably see a trade to your friends account that was canceled, and a second trade to the scam account that was created right after it.
Dr.Shadowds 🐉 Oct 21, 2023 @ 1:47am 
How scammers do it.
1. Victim login to scam site, scammer bot gets access to account.

2. Scammer bot injects API key to account.
https://steamcommunity.com/dev/apikey

3. Scammer bot waits for you to issue a trade, and redriect your trade to it alt account.

That how it works.




Also I HIGHLY suggest you to do these 5 steps, don't skip any, don't hold this off, do it right now.
1. Scan for malware https://www.malwarebytes.com/

2. Deauthorize all other devices https://store.steampowered.com/twofactor/manage

3. Change passwords from a clean computer.

4. Generate new backup codes.
https://store.steampowered.com/twofactor/manage

5. Revoke all API keys, there should be none.
https://steamcommunity.com/dev/apikey
Supafly Oct 21, 2023 @ 1:52am 
There is 0 reason to trade stuff to a friend on request. Thats a HUGE RED FLAG that screams SCAMMER. Didn't need to read anymore of what you said

How it happened
Your account has been hijacked, likely cause is you gave a phishing site you login details. That allowed them to access your account. Then when you sent a trade to your friend the hijackers BOT cancelled it. It then modified their account to look like your friends and resent the trade all with a few seconds so you didn't notice a delay. You then ignored the warning about the target NOT being a friend and confirmed the trade.

Scan for Malware/virus https://www.malwarebytes.com/mwb-download/
Deauthorize all devices https://store.steampowered.com/twofactor/manage
Change your Account password on a secure device, mobile phone for example.
Generate new back up codes https://store.steampowered.com/twofactor/manage
Revoke the API key https://steamcommunity.com/dev/apikey

Recover and secure the account with the steps above. Then stop using dodgy sites.

If you insist on using third party sites do it the safe way

1. Open Web browser
2. Login on Steams Official page
3. Visit Third party site
4. Look for and use the one click login button
5. If 4 doesn't work and you're asked for you username, password and Guard code your on a phishing site. LEAVE and DO NOT use again

Can also use sites like scamadviser.com to check how trustworthy a site is before using it. Works for any site not just Steam related. Use it whenever entering login credentials or banking data
Teksura Oct 21, 2023 @ 2:14am 
Scan for malware https://www.malwarebytes.com/
Deauthorize all other devices https://store.steampowered.com/twofactor/manage
Change passwords from a clean computer
Generate new backup codes https://store.steampowered.com/twofactor/manage
Revoke the API key https://steamcommunity.com/dev/apikey
Stop using shady third party trade sites or clicking suspicious links.


Do each of the steps.



What happened is your account became compromised, most likely through a third party site. This well known scam then requires you to authorize the trade giving your items away after you allow them access to your account through either malware, or giving away your details through a phishing fake login page or other trick used by those shady third party sites.

The way it does this is after it gains access to your account, a bot waits until you send out a trade offer, and then using the access you gave to them, their bot cancels the trade, changes a bot account to match the name and profile picture of the person you wanted to trade with, and then sends a trade giving your stuff away for free.

The scam depends on you ignoring all the warnings, such as "this user is not on your friends list", "this user has a similar name to someone on your friends list", their items missing from the offer, the big "you will receive nothing" text, the fact that they have the wrong level, wrong "has been on Steam since" date (usually obviously too recent to make sense), and a few other obvious warnings. It only works if you're not even looking at what you're doing. Sadly, an awful lot of people don't care enough to verify the trade is what they are expecting, so this scam continues to work.

Valve will not return items you gifted away to the scammer as a result of ignoring all the warnings. https://support.steampowered.com/kb_article.php?ref=9958-MJDG-3003
< >
Showing 1-5 of 5 comments
Per page: 1530 50

Date Posted: Oct 21, 2023 @ 1:37am
Posts: 5