My steam and discord got hacked
I saw today that i had bought dota 2 items at the middle of the night, this wasn't me obviously as i don't have dota and i've never played it.

I did all the things you should do when something like this happens, i checked my pc for malware, reset my password, deleted my API key and all that.

Later that day when i was playing with my friends, one of them asked me "Bro, why did you just send me a steam giftcard scam link". I checked and saw that my account was being used like a fleshlight to send "____@ Steam gift 50$" scam links to all my discord friends.

I reset my password, took my pc offline, reset my emails' password (which i was using for both steam and discord). I've ran multiple scans of my system with none of them finding anything. I'm going to backup some stuff like images and videos on a usb stick, but after that i'm clearing my whole ssd just in case.

I didn't see anyone online who had both their steam and discord be the target of something like this, especially only hours a part so i wanted to post this incase anyone else has had a similar attack happen to them.
< >
36개 댓글 중 1-15개 표시
Mojitsu 2024년 9월 19일 오후 2시 11분 
Hey I just had the same thing happen to me, no fkin clue how they got me. Sent you a friend req maybe we can find out together
Carlos100 2024년 9월 19일 오후 2시 16분 
Your account is compromised

Do all this in the order its written to make sure your account is secure

1. Scan for malware. https://www.malwarebytes.com/
2. Check that the email and phone number on the Steam account are still yours.
3. Deauthorize all other devices. https://store.steampowered.com/twofactor/manage
4. Change passwords from a clean computer.
5. Generate new backup codes for your Mobile App. https://store.steampowered.com/twofactor/manage
6. Revoke the API key (there should be no key). https://steamcommunity.com/dev/apikey
Prowler™ 2024년 9월 20일 오전 2시 41분 
Yes you have been session hijacked. Its a browser based bot attack against steam and discord. Its been around for a few weeks now.

You have to DE AUTHORIZE all devices to kick it out of your account. Then update your security settings and scan for malware. If its on your PC malwarebytes will find it. Also Clear ALL browser data as the bot copies ALL of it.

Be aware the bot will steal all your steam inventory and wallet via sub $1 trades if you do not de authorize all devices. Because it acts under $1 steam security will not alert you. You won't get any warning. It cannot steal your passwords as that would trigger a security check. It simply copy/pastes your current session login ID and empties your wallet without alerting you.

Contract steam support and ask them to investigate any suspicious market activity on your account. They are able to see if the bot attacked you and will give you some copy/paste security advice.

They will NOT refund you any lost items or wallet funds. Even if they can see the bot stealing them. You CANNOT add verification for sub $1 trades. This is Valves policy. This bot exploits that vulnerability. There is nothing in place to stop it so im sure it will keep attacking steam and discord accounts.
Alfa zenius 😎 2024년 9월 20일 오전 10시 48분 
I just got this as well. Exactly as mentioned all items are sold for under 1 dollar. As well my discord got hacked and sent out 50 usd free gift card scam links to everyone off my friends. Now what really shocked me - i have a second account that i havent logged in to for over a month, and 10 minutes after i realized i was hacked and was doing everything mentioned above - i saw that my second account has launched PUBG, qued for 1 game and left and then i deauthorized my second account from everywhere as well. Now what shocks me is HOW THE ♥♥♥♥ DID THEY DO IT. Nobody has my account logins, both of the acounts are prtotected by steam guard (how did they even manage to bypass steam guard to login to my second account). Windows defender saw nothing, malware bytes quick scan saw 2 files and none of them were related in any way. I checked my chrome and other software activity/history/login locations and found no other software that was afected so far. Runing a custom full premium scan on malwarebytes now, 1 hour in, 651k files scaned, 78 malicious files found. First time i ever get hit by a virus because im not a stupid persson in topics like these but yesterday i was stupid, after smoking a joint i decided to download a few torrents and im certain this was the cause. altho still a mistery about how they logged to my second acount. Could they replicate my ip to logg in from another device without authorisation? What makes it even more crazy is that my api wasnt changed at all.
Yujah 2024년 9월 20일 오전 11시 21분 
What Prowler just above you said is that local malware (browser based, it seems they say, but possibly "normal") on your system stole from you a complete local browser and/or Steam client state in which you were apparently logged in on both accounts. After replicating said state into the attacker's own browser/client it to Steam appeared to be that already logged in browser/client.

Be sure to do all that Carlos100 in #2 said.
Yujah 님이 마지막으로 수정; 2024년 9월 20일 오전 11시 55분
Carlos100 2024년 9월 20일 오전 11시 53분 
Alfa zenius 😎님이 먼저 게시:
I just got this as well. Exactly as mentioned all items are sold for under 1 dollar. As well my discord got hacked and sent out 50 usd free gift card scam links to everyone off my friends. Now what really shocked me - i have a second account that i havent logged in to for over a month, and 10 minutes after i realized i was hacked and was doing everything mentioned above - i saw that my second account has launched PUBG, qued for 1 game and left and then i deauthorized my second account from everywhere as well. Now what shocks me is HOW THE ♥♥♥♥ DID THEY DO IT. Nobody has my account logins, both of the acounts are prtotected by steam guard (how did they even manage to bypass steam guard to login to my second account). Windows defender saw nothing, malware bytes quick scan saw 2 files and none of them were related in any way. I checked my chrome and other software activity/history/login locations and found no other software that was afected so far. Runing a custom full premium scan on malwarebytes now, 1 hour in, 651k files scaned, 78 malicious files found. First time i ever get hit by a virus because im not a stupid persson in topics like these but yesterday i was stupid, after smoking a joint i decided to download a few torrents and im certain this was the cause. altho still a mistery about how they logged to my second acount. Could they replicate my ip to logg in from another device without authorisation? What makes it even more crazy is that my api wasnt changed at all.
You have been compromised for a long while and they wait it out then 1 day it all goes down.
You must learn how to not click random links and go to bad sites ............without knowing how to keep yourself safe on them sites
coldzebra 2024년 10월 22일 오후 9시 39분 
Same thing actually just happened to me. I woke up to over 400 “You’ve just given a community award to a screenshot” emails this morning after having my discord hacked this weekend with the “steam giftcard messages sent to friend DMs” hack
Maria 2024년 10월 22일 오후 9시 44분 
coldzebra님이 먼저 게시:
Same thing actually just happened to me. I woke up to over 400 “You’ve just given a community award to a screenshot” emails this morning after having my discord hacked this weekend with the “steam giftcard messages sent to friend DMs” hack
Change your steam's account password, you will get your points back.

Yea, discord scam is really nasty, they get to all ur accounts kek.
Yujah 2024년 10월 22일 오후 10시 52분 
Maria님이 먼저 게시:
Change your steam's account password, you will get your points back.
Note, not if you "change" but only if you "reset" it. Difference as per e.g. https://www.howtogeek.com/869288/how-to-reset-or-change-your-steam-password/
jahfield 2024년 10월 23일 오후 6시 21분 
Just happened to me, must've been something on the PC. My discord and steam both got hacked at the same time. Even with 2FA. Resetting my PC and changing passwords on everything. Similarly I didnt get any malware coming up on scan. They also got me a game ban on rust, which I'll have to appeal. Luckily not a VAC
Onyeka Okongwu 2024년 10월 29일 오전 9시 03분 
Same thing happened to me, can they access to our email?
alphara 2024년 11월 13일 오후 2시 40분 
my discord and steam got hacked, all items were sold and around 40 EUR of steam credit is gone. All the money was used to buy 3 cent dota2 items for 2-15 EUR each from 2 users.

1. Why didnt I get any emails about market activity? I always get an email even when I have bought/sold a 3 cent item. This time there was nothing.
2. How did they access my discord and steam account when I havent logged in anywhere with these 2 accounts nor have I clicked any suspicious links?
RPG Gamer Man 2024년 11월 13일 오후 2시 44분 
Maria님이 먼저 게시:
coldzebra님이 먼저 게시:
Same thing actually just happened to me. I woke up to over 400 “You’ve just given a community award to a screenshot” emails this morning after having my discord hacked this weekend with the “steam giftcard messages sent to friend DMs” hack
Change your steam's account password, you will get your points back.

Yea, discord scam is really nasty, they get to all ur accounts kek.

This is why i do not use discord.
RPG Gamer Man 2024년 11월 13일 오후 2시 45분 
Onyeka Okongwu님이 먼저 게시:
Same thing happened to me, can they access to our email?

Yes they can. That is why you change your password on your email and other things. That is why you do this:

1. Scan for malware. https://www.malwarebytes.com/
2. Check that the email and phone number on the Steam account are still yours.
3. Deauthorize all other devices. https://store.steampowered.com/twofactor/manage
4. Change passwords from a clean computer.
5. Generate new backup codes for your Mobile App. https://store.steampowered.com/twofactor/manage
6. Revoke the API key (there should be no key). https://steamcommunity.com/dev/apikey
RPG Gamer Man 2024년 11월 13일 오후 2시 50분 
Prowler™님이 먼저 게시:
Yes you have been session hijacked. Its a browser based bot attack against steam and discord. Its been around for a few weeks now.

You have to DE AUTHORIZE all devices to kick it out of your account. Then update your security settings and scan for malware. If its on your PC malwarebytes will find it. Also Clear ALL browser data as the bot copies ALL of it.

Be aware the bot will steal all your steam inventory and wallet via sub $1 trades if you do not de authorize all devices. Because it acts under $1 steam security will not alert you. You won't get any warning. It cannot steal your passwords as that would trigger a security check. It simply copy/pastes your current session login ID and empties your wallet without alerting you.

Contract steam support and ask them to investigate any suspicious market activity on your account. They are able to see if the bot attacked you and will give you some copy/paste security advice.

They will NOT refund you any lost items or wallet funds. Even if they can see the bot stealing them. You CANNOT add verification for sub $1 trades. This is Valves policy. This bot exploits that vulnerability. There is nothing in place to stop it so im sure it will keep attacking steam and discord accounts.

Can you explain exactly what happens in a session hijack? I would like to know more information about this.
< >
36개 댓글 중 1-15개 표시
페이지당 표시 개수: 1530 50

게시된 날짜: 2024년 9월 14일 오후 1시 46분
게시글: 36