The Steam API key scam has a name problem. Valve documents it as trade redirection, and says the API key is optional to the attack rather than central to it. Revoking a key is still worth doing. It just won’t fix an account someone else already controls.
What a Trade Redirection Attack Does
Valve’s own description is precise. A scammer “will coerce you to trade your items to what you believe is a trusted account”. They have already compromised your account security. The trade is then cancelled and redirected to an impersonation account they control, and they hope you confirm it on your phone without reading it. The item you send never reaches the person you meant to send it to.
Where the Steam API Key Scam Name Came From
An API key lets software act on an account automatically. Valve describes it as a tool that can “execute changes to the account hosting a specific API key,” and notes that automating Steam functionality is otherwise prohibited. A hijacker with access to your account can register one silently. From then on, the cancel-and-redirect step runs without a human watching it, which is why the scam got the name it has.
Valve Says the Key Isn’t the Root Cause
This is the part most guides get wrong, and Valve states it outright. The redirection “may be executed with an API key,” but “it’s not a necessary component of the scam”. Their reasoning: automating actions on your behalf is trivial once someone has access to your computer or account, with or without a key. Treat a rogue API key as evidence of a breach, never as the breach itself.
How the Access Happens First
Every version of this attack needs account access before any redirection is possible. The common routes are narrow:
- A fake Steam login page that captures your username, password and Steam Guard code in real time.
- Malware installed as a voice app, anti-cheat tool or tournament client.
- A forwarded confirmation email or shared SMS recovery code.
- A compromised email account, which is how many Steam accounts fall second.
Valve notes that modern malware can wait for “an account having funds available in its Steam Wallet” before triggering, then remove itself afterwards. Nothing looks wrong until items move.
Recognising It Before You Confirm
The confirmation screen on your phone is the last checkpoint, and it carries everything you need. Valve’s instruction is to “use all the information in the confirmation window” to check the trade is the one you intended. Look at the receiving account name, not the avatar. Impersonation accounts copy display names and profile pictures exactly, then differ on the account itself.
What the Key Does and Doesn’t Explain
Separating the two halves of the attack makes the fix obvious:
| Element | Role in the attack | What removing it achieves |
|---|---|---|
| Stolen credentials | The actual breach | Ends the attacker’s access |
| Malware on your PC | How credentials keep leaking | Stops the next compromise |
| Rogue API key | Optional automation layer | Blocks automated redirection only |
| Your confirmation tap | The step that completes it | Nothing moves without it |
Read that bottom row twice. A Steam API key scam still needs you to approve the trade on your phone, which is why the confirmation screen matters more than the key does.
Pressure Tactics That Come With It
Redirection usually arrives wrapped in urgency. Valve names one tell outright: a scammer with access may edit your Steam profile to make it look like your account is about to be banned. Their guidance is unambiguous. Steam Support “will never change your profile content to threaten or execute a ban”. Any unexpected change to your own profile means your security is already gone.
Checking and Revoking a Key
Valve publishes the exact location: keys can be revoked at steamcommunity.com/dev/apikey. If a key sits there that you didn’t create, someone else registered it using your account. Revoking it closes that automation path. It does nothing about the stolen password, the malware, or the email account that let them in. Revoking belongs in the middle of a recovery sequence, not at the end of one.
Recovery, in the Order That Works
- Scan the computer for malware before changing anything, or you’ll hand over the new password too.
- Secure the email account tied to Steam, including its own two-factor.
- Change the Steam password.
- Use Sign out everywhere from Authorized Devices, which Valve recommends when anything looks odd.
- Revoke any API key you don’t recognise.
- Cancel pending trades and, for CS2 items, reverse protected trades from the last seven days.
The Seven-Day Window That Can Save Items
Counter-Strike 2 items are Trade Protected for seven days after arriving in a trade, and trades inside that window can be reversed. That is the only genuine recovery route. Outside it, Valve’s Item Restoration Policy applies: Steam Support “does not restore items that have left accounts for any reason”. Reversing also costs a 30-day trading and Market restriction, which Steam Support cannot lift.
Reducing the Exposure in the First Place
Prevention here is mostly about where you sign in. Valve’s own line is that anyone contacting you about your items through Discord or Steam Chat “does not represent Steam and should be blocked”. Sticking to platforms with published terms and real support helps too. That is why the top CS2 gambling sites list weighs transparency alongside game selection, with CSGORoll leading it on published rules.
Where Account Security Meets Site Choice
A hijacked Steam account and a badly run trading site fail in similar ways: items leave and nobody answers. The safe CS2 gambling sites ranking covers what to check on the platform side, from published payout rules to how withdrawals are actually processed.
Frequently Asked Questions
What can someone do with my Steam API key?
Automate actions on your account, including cancelling an outgoing trade and reissuing it to a different recipient. It only works if they already have access, since registering a key requires being signed in.
Is it safe to create a Steam API key?
Creating one yourself is fine. Sharing it is not. Valve states an account’s API key “should never be shared,” because it identifies your account inside the automation system.
How do I know if someone made a key on my account?
Open steamcommunity.com/dev/apikey while signed in. If a key is listed that you never registered, someone else created it using your account, and you should revoke it and secure the account.
Will revoking the key get my skins back?
No. Revoking stops future automation only. For CS2 items lost in the last seven days, reversing the protected trade is the recovery route, and it carries a 30-day trading restriction.
Does Steam ban accounts used in this scam?
Yes, where evidence exists. Valve bans scamming accounts from the Community, trading and the Market, with permanent bans in serious cases, and may ban every account a scammer holds.

