December 19, 2016
Czech Republic 
 This topic has been pinned, so it's probably important
What you should know about "Steam web API" scam. How not to lose your skins!
Mostly used scam method today is the so-called "Steam web API key" scam. Unfortunately, we get several requests daily from our users who lost skins due to this.

In this post, you will learn how this method works and how to protect your skins.

The method is based on the use of phishing websites with a fake "Login with Steam" button.
Usually, those websites are advertised in the search engine and copy the style of popular services.
When you push this button you get a fake "Steam login" form which asks for your login, password and 2FA code later.
Hacker's script uses this data to log in to your Steam account and set Steam web API key on this page: Using this API, the script can monitor all your trade offers and if there is an offer with valued skins - this trade offer will be cancelled and you will get an absolutely similar-looking offer but from the hacker's account.

To protect your skins, always follow the next rules:

1. Try not to use a search engine to find a service you already know. Do not use results from the “advertising” section. Use direct addresses. For example https://loot .farm

2. NEVER enter your Steam login data while "Login with Steam" process. You should have an active session in Steam and just push "Login" button on the Steam website. If you asked for login data - load website and log in here.

3. When you request a trade offer on LOOT Farm you get a direct link to the trade offer created. Always use this link to accept a trade offer. Don't search for a trade offer in Steam or Steam application.

4. Additionally, make simple checks. In every trade offer, we show bot's registration data. Check this data of your counterpart in trade offer. Also, all our bots have level 10 in Steam.

5. We have created a simple Google Chrome extension. This extension will check your trade offers and will notify you if you open a fake trade offer from our service.
Install our extension here:

Using these five rules you will never be scammed using Steam web API scam.

What should you do if you already was scammed?

Unfortunately, you can not return your skins. You should write a report to the hacker's Steam account. Most likely this account will be banned, but trades will not be reversed.
To make your account secure you should:

1. Change your Steam password.
2. Go to this page: and "Revoke" Steam web API key. (Create a new one if you need this key).
3. Change your TradeURL.
4. Update your new TradeURL on the LOOT Farm and other services.
Last edited by LOOT Farm *****; Aug 18, 2021 @ 6:54am
< >
Showing 1-8 of 8 comments
Sandokan Apr 22, 2020 @ 6:10am 
Hello, yesterday one of your "reliable" trade bots scammed my inventory and i lost all of my skins. I got the screenshots (it was a trade wich i never saw and never accepted on steamguard or anything.) at the time of the "trade" i wasnt online. So it could not be a real trade. The "scambot" is a member of your group and the loot farm bots group.
LOOT Farm ***** Apr 30, 2020 @ 6:22am 
Unfortunately, this is another scam method. Your phone account ( or AppleID) or your phone with Steam mobile authenticator was hacked and all your skins were stolen. We can not help in this situation because all trades in Steam are final. You should pay attention to your phone security.
😶😶 Mar 7, 2021 @ 7:15am 
I also get scam with the same thing by bot
😶😶 Mar 7, 2021 @ 7:16am 
almost $400 spend in trade butterfly knife and AWP and in the end, get scam by this evening
LOOT Farm ***** Mar 8, 2021 @ 6:10am 
I'm sorry if your Steam account was hacked. But it is your responsibility to protect your account. From our side, we make all possible to protect you including Chrome browser extension.
😶😶 Mar 8, 2021 @ 7:08am 
but the thing is I extent the chrome browser from and still have the problem like this
nuoyan2317 Apr 9, 2021 @ 9:32am 
My profile link
Here are some skins tradable today. It says cancelled but I don't do it. Also the tradable skins didn't show in the system. And They are still in your robots. Here are 5 skins should be mine but still in your robot.
★ Butterfly Knife | Night (float 0.2069) in Robot 42
M4A4 | Bullet Rain(float 0.09765) in robot 48
P250 | Asiimov(float 0.20754) in robot 9
★ StatTrak™ Gut Knife | Doppler(float 0.001255) in robot 9
StatTrak™ Desert Eagle | Mecha Industries(float 0.1868) in robot 8
There are 3 skins are untradable that I cann't understand. Help me check pls.
LOOT Farm ***** Apr 15, 2021 @ 7:16am 
Steam has some serious issues with a trading system last few days. This is a reason why skins dissapers. It returning to the account several hours later but this a new ID so it treated as new skins.
< >
Showing 1-8 of 8 comments
Per page: 1530 50