Counter-Strike 2

Counter-Strike 2

368 ratings
API Scam Prevention Guide
By Guardy
An in-depth guide into the API scam and ways to prevent it from happening to you.
8
13
3
3
2
   
Award
Favorite
Favorited
Unfavorite
Steam's API Key
This guide breaks down the process of one of Steam's most infamous scam methods and how best to prevent it happening - the API scam.


Steam's API key gives access for services to freely create and decline trade offers.

The only circumstances you would ever require using an API key is when using legitimate p2p (peer to peer) sites. Most users will not need to use an API key, hence it is one of the most dangerous ways to get scammed.

You MUST NEVER hand out your API key to other users in any situation or services you do not trust. There is also no real reason you would need an API key.


How Do I Access My API Key?
Your API key can be found here: https://steamcommunity.com/dev/apikey

You can only have 1 active API key at a time.

When creating an API key, you are now required to confirm through your mobile authenticator within a short amount of time. If you see a notification on your authenticator asking to create a developer API key without your knowledge, deny the request and follow the steps to securing your account immediately.




Overview Of The API Scam
How it works:

Step 1: The scammer will send you a phishing link - a link which steals your login details or personal information, giving the scammer access to your account.

Step 2: The scammer creates an API key.

Step 3: Any trade offers you make will be cancelled and redirected to an impersonators account which is 'face identical' to the real user you are trading with.


Some very common methods of phishing links are:
  1. You win a free item and must claim it by logging into a dodgy website.

  2. You are asked to send full details/price evaluation and must login to dodgy website.

  3. You are asked to compete in a small tournament hosted by a dodgy website and must login.

  4. You are asked to help someone by voting for their submission (such as artwork), in some sort of competition and must login to vote.

  5. You are given are given an in incorrect 'steamcommunity' link which you are required to login to. Note that the ' https://steamcommunity.com ' domain is protected, however scammers may use steamcommunility etc.


In-Depth Breakdown (Step 1)
When logging into any website which requires Steam, you will be presented with 1 of 2 login methods. Before logging into any sites, ensure you sign directly into Steam beforehand - once you are logged in, you will not be required to enter your login credentials again unless you are signed out of Steam browser. This initial step gives a good (but not foolproof) way of filtering out some scam sites at a very early stage. This is the initial stages of the API scam, and it is very difficult to know if your account has been compromised until it is too late.

How it works:

Step 1: The scammer will send you a phishing link - a link which steals your login details or personal information, giving the scammer access to your account.


✔️ How to stay safe:
  • Ensure you are logged in directly to Steam before signing into any sites.

  • Do not click on any links or login to any sites sent by anyone (even friends) that you do not trust or are not familiar with.

  • If presented with the 'FAKE LOGIN' interface, ensure you DO NOT enter your login credentials. You should not be required to re-enter your login if you have already signed into Steam beforehand.






In-Depth Breakdown (Step 2)
Your API key can be found here: https://steamcommunity.com/dev/apikey

Most users will never require an API key. If you did not assign an API key, and you find one assigned, then your account has been compromised. You should follow the steps in 'Secure your account' section of this steam guide. The step of assigning an API key is the backbone of the API scam. The API key can also be assigned at any stage as long as the used credentials have not been logged out.

How it works:

Step 2: The scammer creates an API key.


✔️ How to stay safe:
  • Verify there is no API key assigned.

  • In the event that there is an API key that you did not assign, change your password immediately, deauthorise all devices (shown below) and revoke the API key.


In-Depth Breakdown (Step 3)
The scammer has now assigned an API key, giving them the ability to create and decline trade offers.

When doing a trade with your intended trader, before confirming via the mobile authenticator, the API can redirect the trade to a scammers account which copies the name and profile picture of your intented trader. It is very easy to overlook this especially with the most recent steam mobile app not displaying the users registration date. There are multiple ways you can ensure you are confirming a trade with your intended trader and not a scammer.

How it works:

Step 3: Any trade offers you make will be cancelled and redirected to an impersonators account which is 'face identical' to the real user you are trading with.


✔️ How to stay safe:
  • Add the user on Steam prior to sending any trades. The trade confirmation will display a 'friend' icon which can act as an extra layer of security.

  • Ensure the Steam level in the trade confirmation matches with the intended traders steam level, as well as their displayed badge.

  • Do not send an empty trade offer, it is always handy to add a 3 cent sticker on the intended traders side as most API bots will not have an item. This also then ensures that when confirming the trade, and the 'intended traders' items you are receiving are empty, then it means your account has been compromised. The image below is an example showing the 3 different verification ways.




  • When using third-party sites, open the trade within the site and not navigating to your Steam trade offers.

  • When confirming via the mobile app, open up the confirmation then proceed to check your trade offers here: https://steamcommunity.com/id/me/tradeoffers/sent/ and verify there is no cancelled trade offer. If you see an image similar to the one shown below - where there is an active and cancelled trade offer which are both identical, your account has been compromised.

  • Click on the users icon in the trade to go to their profile, an ensure it is the same user. You can also verify the account creation date by posting their Steam URL into https://steamid.uk/ . Another good indication is most API scam bots will have a steam URL with '/profiles/XXX' (where X is a long number) opposed to a /id/...'.



Resecure Your Account
You have found that your account has been compromised by a phishing link. How do you go about resecuring it?

Step 1: Change your password.

Step 2: Deauthorise all devices.

Step 3: Remove API key.


Step 1 - How to change your password:

Access 'Change your password' here: https://store.steampowered.com/account/

Scroll down to the 'ACCOUNT SECURITY' section and select 'Change my password'.




Step 2 - How deauthorise all devices:

Access 'Deauthorise all devices' here: https://store.steampowered.com/twofactor/manage

Select 'Deauthorise all devices'. You will be required to login to every site and mobile again. Ensure you login to https://steamcommunity.com first. Also note that deauthorising your devices will log you out of the steam mobile authenticator, meaning you cannot access any of the features including confirmations. You will need to remove the authenticator via the link above and redownload the steam app, resulting in a 15 day tradehold once the authenticator is re-enabled.




Step 3 - How to remove API key:

Access your steam API key here: https://steamcommunity.com/dev/apikey

Select 'Revoke My Steam Web API Key' and select 'OK'.




Two-Factor Auth. and Family View
Steam's Two-Factor Authentication should be the absolute minimum level of security of all users. An outline of what it does and how it can help you are displayed below. In addition, Steam's Family View is a very useful feature which requires a pin to access specific sections of your steam account.

An important note is you should never share your email and phone number, as these can be used to recover your account, as well as hijack.


✔️ Steam Two-Factor Authentication - https://store.steampowered.com/twofactor/manage :
  • Should be the bare minimum level of security for all users.

  • Enabled in the steam mobile app, which allows you to confirm trades instantly, and removes the 7 day/15 day tradehold when sending items (after having it enabled for 7 days).

  • This also allows you to verify steam level, displayed badge and friend status easily, prior to confirming any trade.


✔️ Steam Family View - https://store.steampowered.com/parental/set :
  • An additional security method which requires a pin to access specific parts of your steam account (which you choose - for example; specific games, 'Steam store', 'Community-generated content', 'Friends, chat and groups' and 'My online profile, screenshots and achievements').

  • Enabled via the steam browser. The options you select are what you can access without entering the pin. It is a good idea to only tick 'Friends, chat and groups' for the Online content & features section.

  • Note that the 'Community-generated content' includes modifying the API key and the steam market access. You also cannot send trade offers via the use of an API key if the ''My online profile, screenshots and achievements' option is not ticked.

  • Whenever you relog into steam or relaunch steam app, you will need to re-enter the pin to access the family view locked content.




You have been API scammed. What do you do?
If you have unfortunately found this guide after being API scammed, there will be nothing you can do to recover your items. Steam support will never contact you or offer to recover your lost items.

The next steps you should take is by reporting the steam profile of the scammer to steam support, and hope the user gets banned before the item tradehold ends. This will not return your item back, but it will prevent them from selling for real cash or scamming other individuals. Make you are familiar with the contents of this guide to prevent this from happening in the future, and ensure you complete the "Resecure your account" steps.

You should also spread the awareness on twitter, providing the users steam64ID permalink which can be found posting their steam here: https://steamid.io/ , and some detailed evidence. It would also be good to contact a few known members in the community who spread awareness on scammers such as myself, @RadiantCS_, @ExerpasCS and @ZeusperCS.




Thanks For Reading
If you found this guide useful, an upvote will be highly appreciated. Additionally, you can favourite the guide, and showcase it on your steam profile as your 'Favourite Guide'.

Sharing this guide, as well as the 'Scam Prevention Guide' - which provides many other common techniques of scamming will be highly appreciated, and will hopefully help reduce the number of scams in the future.

https://steamcommunity.com/sharedfiles/filedetails/?id=2569847731

64 Comments
𝕿.𝕿..MR.FRANKLIN Jan 30 @ 2:30am 
I just got scammed for 3000$ inventory and i dont know of to get it back
bymare.ツ Jan 28 @ 1:04pm 
Happend to me 3 years ago, my Old 400 Euro Inventory would now be worth about 1200 Euros. Atleast that Scum is Trade Banned
Niblets911 Jan 15 @ 1:38pm 
so if i clicked the link but didn't sign in im good? Also i don't really have any cool or good items soooo is there anything else they can do other than stealing my cs2 skins
Can someone help me get my skin back? I have all the proof of the scam and the profile name.:steamsad:
donkCASE.GIFT Dec 28, 2024 @ 3:22am 
-100 nice guys can i get back my skins ?
Kutam Dec 16, 2024 @ 12:36pm 
- 300 gbp today, absolutely gutted:steamsad:
gamblemaNN Dec 15, 2024 @ 6:04am 
Hello guys this happened to me today, of my 2000$ butterfly what can I do to get it back?
🍭☠🍭 Dec 4, 2024 @ 12:04pm 
Just checking comments. Feels bad to see that much losses but guys... u dont know how to keep your "money" safe.
stephen Dec 1, 2024 @ 2:23pm 
How do we do we know it's not just steam employees running the scams. Conveniently make it so they can steal items back. "They did a trade without checking their api key status first so they deserve to lose their items". Clearly.
Who? Nov 17, 2024 @ 3:55am 
-75$
Old steam was way better when you could contact steam to talk about the trade scam. They would give back your items and ban the scammer. Today, you can't do anything.