Guides
Safe Trading: How to Avoid the Most Common CS2 Scams
Valve does not restore traded items. Not for scams, not for compromised accounts, not for “I confirmed the wrong offer”. That single fact is why skin trading attracts the volume of fraud it does, and why every protection you get has to be one you applied yourself before the trade happened. Here is what the real attacks look like and what defeats each one.
Lock the account down before you trade anything
Almost every large inventory loss starts with account access, not with a bad trade. Get this layer right and most of the rest becomes impossible.
Run the Steam Guard Mobile Authenticator, and treat its recovery code as the single most sensitive string associated with your account. Never share a Steam Guard code with anyone for any reason — no support process, no verification step and no trade requires you to read a code to another person. Anyone asking for one is trying to log into your account while you read it out.
Be equally hostile to QR codes. Steam supports signing in by scanning a login QR code with the mobile app, which means a QR code someone sends you or displays on a page can be a login request for their session on your account. Scan login QR codes only when you generated them yourself, on a device in front of you.
Finally, be selective about browser extensions. An extension with permission to read and modify pages can rewrite what you see on a trade page — including the items listed in an offer. Install extensions you can justify, from sources you can verify, and remove the rest.
API key theft
This is the most damaging attack in skin trading and the one most traders do not understand.
Your Steam account can have a web API key attached to it. That key allows automated interaction with trade offers. If an attacker obtains it — typically after you have logged into a phishing page, or through malware — they gain the ability to watch your trade activity and act on it in real time without ever touching your password again.
What it looks like from the victim’s side is deeply convincing. You negotiate a legitimate trade. You send or receive an offer. You open the mobile app to confirm. Everything appears normal, and afterwards the items are gone to an account you never dealt with. The offer you thought you were confirming was not the offer that executed.
The critical detail: changing your password does not remove an API key. Recovery guides that stop at “change your password” leave the attacker in place. If you have any reason to suspect exposure, do all of the following, not just one:
Go to Steam’s developer API key page directly, by typing the address yourself, and revoke any key listed there — including one you think you created. Change your password. Deauthorize all other devices from your account settings so existing sessions are killed. Then run a proper malware scan, because a key that reappears was taken by something still running on your machine.
Do this periodically as maintenance, not only after a scare. Checking that page takes fifteen seconds and it is the only way to see whether a key exists at all.
Phishing pages and fake login windows
The classic version is a page that renders a fake browser window inside itself — a convincing Steam login box, complete with an image of an address bar showing the correct domain. It is a picture, not a browser.
Two tests defeat it every time. Try to drag the login window outside the boundary of the real browser; a genuine popup can leave the parent window, a fake one cannot. And look at the actual address bar at the top of your real browser, not the one drawn inside the page.
The other version is a straightforward lookalike domain. These rely on you skimming: swapped or doubled characters, an extra word, an unusual top-level domain, or a subdomain arrangement where the real domain is at the end rather than where you expect it. Reading a URL properly means reading it right to left, finding the actual registered domain, and ignoring everything before it.
The habit that makes all of this moot: never log into Steam from a link. Reach Steam through a bookmark you made yourself, or by typing the address. If a site needs you to sign in, open Steam separately first and see whether you are already authenticated.
Impersonation
Display names and avatars are free to copy. A cloned profile can match a trusted trader exactly and still be an entirely different account.
Verify identity by the profile URL or Steam ID, never by the displayed name. Look at the account’s creation date, its level, how many friends you have in common, and whether the profile carries any trade or community ban notice. A brand-new account wearing a familiar name is the whole scam.
Two specific pretexts deserve naming. First, nobody from Valve will contact you about a trade — there is no Steam support representative who messages you, and any account claiming to be one is lying. Second, a message from an account on your friends list is not proof the message is from your friend; compromised accounts are used to message their own friend lists precisely because the trust is already there. If a friend suddenly asks for a favour involving your items, verify through a channel outside Steam.
Fake middlemen
The pitch is that a trusted third party will hold the items or the payment while both sides deliver. In a two-party Steam trade there is no such role. The “middleman” is simply a third person you are handing your inventory to, and once it is theirs, it is theirs.
The setup usually comes with social proof: a second account vouching, screenshots of past trades, a reputation thread, sometimes a fabricated page on a lookalike domain designed to resemble a community reputation database. All of it is cheap to produce.
If a trade genuinely needs a neutral party, that party should be a platform that holds both sides of the transaction as part of its own system, not a person. If someone offers to be the middleman, the answer is no — regardless of who vouches for them.
Trade offer attacks
| Pattern | What you see | The check that stops it |
|---|---|---|
| Wrong-account offer | An offer arrives that matches what you negotiated | Confirm the offer originates from the exact profile you negotiated with, and read Steam’s warnings about unfamiliar or new accounts |
| Item swap | Contents changed at the last moment | Re-read every item on the confirmation screen, after any change to the offer |
| Lookalike items | Right name, wrong item | Check souvenir vs StatTrak vs plain, the exact wear, and the rarity colour |
| Name-tag disguise | An item displaying a valuable skin’s name | Read the item’s real type in the description, not the custom name |
| Empty-side offer | An offer that gives you nothing | Confirm both sides of the trade on the mobile screen before approving |
The mobile confirmation screen is your last honest checkpoint. It shows what is actually leaving your account, generated by Steam rather than by the page you are looking at. Read it every time, slowly, even when you are certain. Especially when you are certain.
Cash trades and payment fraud
Trades involving real money add reversibility to the problem. Payment methods that allow chargebacks let a buyer receive items and then reclaim the funds weeks later. Screenshots of payment confirmations are trivially faked. “You go first, I have a good reputation” is not a security model.
If you are selling for money rather than items, use a platform that handles both sides of the transaction and holds the item until payment settles. If you are dealing directly with an individual, understand that you are extending unsecured credit to a stranger with no recourse.
The universal tell
Every one of these attacks depends on you moving faster than you think. Time pressure, a deal expiring, a queue of other buyers, a friend who needs it right now, a limited window. Urgency is not a feature of legitimate trades — an item that is genuinely worth what it is worth will still be worth that in ten minutes.
When something feels rushed, stop. Close the window. Verify the profile, the domain and the offer contents from scratch. No genuine counterparty will object to a two-minute pause, and every scammer will.
Practical takeaway
Protect the account first: mobile authenticator on, recovery code and Steam Guard codes never shared, login QR codes never scanned unless you generated them, browser extensions kept minimal.
Check your Steam API key page as routine maintenance, and remember that a password change alone does not revoke a key — revoke it explicitly, deauthorize other devices, and scan for malware if you suspect exposure.
Never log into Steam from a link. Verify counterparties by profile URL rather than display name. Refuse middlemen on principle. Read the mobile confirmation screen in full, every single time, because it is the only display in the chain that Steam controls.
And accept the underlying reality that makes all of this necessary: once items leave your inventory, they are gone. Prevention is the entire remedy.