Personal Web API key
steamcommunity.com/dev/apikeyIssued from a user account for permitted API calls. Key creation, visibility, revocation and abuse detection are account-security questions.
meta name="referrer" content="strict-origin-when-cross-origin" />
Skip to Part IITHE STEAM DOSSIER / II
Public automation. Outsourced support. The people left counting the cost.
Follow the infrastructure, the reported losses and the documents behind the claims.
Steam accounts actively on sale on LZT Market
at this very moment
The primary underground clearinghouse for hijacked Steam accounts, lzt.market (Lolzteam / Zelenka), authenticates both buyers and sellers using Valve's official Steam OpenID (openid.realm = https://lzt.market). At any given minute, over half a million stolen and compromised accounts (stealer logs from RedLine/Lumma, phishing captures, credential stuffing) are actively listed for pennies ($0.50–$2.00). Neither lzt.market nor lolz.team is blocked by Valve's Link Filter. This is the industrial reservoir supplying the 63.06% paid bot accounts that Valve bans without assisting the victim.
01 / AN ECOSYSTEM WITH AUTHORS
Named projects. Published capabilities. Trace a tool to its documentation, then inspect the collected developer relationships.
The graph maps published contributor and forker relationships between named projects and GitHub profiles. These are public records — repository forks, contribution lists, profile associations. The question is what the paper trail of published capabilities and developer relationships requires Valve to answer, not what this investigation invented. Source hashes are saved in the map provenance.
02 / DIFFERENT CREDENTIALS. DIFFERENT POWERS.
Playing a game does not require the player to issue a personal Web API key. That is the distinction at the centre of this inquiry.
steamcommunity.com/dev/apikeyIssued from a user account for permitted API calls. Key creation, visibility, revocation and abuse detection are account-security questions.
Steamworks partners use publisher credentials for supported backend operations, including game-related services. A player’s personal key is a different credential.
OpenID confirms identity to a website. A Steam session or refresh token has a different purpose. These mechanisms should not be presented as one interchangeable “API key”.
Valve documents both user and publisher Web API keys. The entire Web API is therefore not separate from Steamworks. API key documentation ↗ archived 2026-09-15 ↗ · Game-session authentication ↗ archived 2026-08-29 ↗
THE HUMAN SIDE / AN ILLUSTRATIVE PHISHING PATH
A message from a friend. A request to vote. A “thank you” page. To the player, the task is finished. A compromised session can outlast that moment.
ON THE PLAYER’S SCREEN
OUT OF SIGHT
The player did not set out to create an automation credential or delegate control. Returning to a game is not evidence that the account is safe. Valve holds the session logs, the API key creation record, and the device correlation data. The victim does not. That asymmetry is the accountability problem.
An API key and a logged-in session are separate credentials with different capabilities. Revoking a key does not terminate an active session. Valve’s own documentation describes both; Valve holds the logs that would show which credential was active at the time of any disputed action. The demand is disclosure of that record — not an inference the investigation has invented. Maintainer documentation on token handling ↗ archived 2026-09-24 ↗ · Valve key documentation ↗ archived 2026-09-15 ↗
03 / THE OFFICIAL MARKET HAS A CEILING
A price above the listing cap cannot be realised through one Community Market listing at that full price.
An illustration of the published limit, not a valuation or recommendation to trade.
Wallet funds cannot be withdrawn to a bank account. These constraints create the demand that third-party skin markets fill: a demand the listing and wallet caps produce, while Valve's own rules prohibit commercial operators from meeting it.
Steam’s market limits ↗ archived 2026-09-21 ↗04 / INSIDE THE SUPPORT BOUNDARY
Valve’s privacy policy expressly provides for sharing personal data with third-party support providers, as necessary for support.
Privacy Policy §5.2 ↗ · Valve's own policy authorises third-party support access. The open questions are: what permissions were granted, what audit trails exist, and what happened when access was allegedly abused.
Valve acknowledged widespread account theft and described protective measures.
Valve publication ↗ archived 2026-08-09 ↗Valve keeps a small in-house Steam Support Leadership team and stated it "hired a couple different companies" to handle support (Erik Johnson, Valve, to Kotaku); its privacy policy § 5.2 authorises those third parties' access to user data. Which contractor holds account-recovery access, Valve has never disclosed — community discussion names vendors such as Concentrix, but none is Valve-confirmed. The outsourced desk was in place years before either admission below.
Kotaku: Valve on its support ↗ archived 2025-07-11 ↗Valve's CS:GO team accepts responsibility in writing for an account compromised through its own help-request process, and reverses the trades.
Open the outsourcing case ↓33 months later, Steam Support writes that a technician "failed to follow our process which resulted in your account restored to someone else." Same channel. Same outcome.
Dexerto, 14 Nov 2025 ↗CASE FILE / HFB & THE OUTSOURCING ALLEGATIONS
In the support reply reproduced by Dexerto, Valve's CS:GO team accepts responsibility for an account compromised through the help-request process — its own channel, not a phishing page and not the user. The items were recovered and the trades reversed, which is the remedy Valve tells other victims does not exist. HFB's inventory was reported at $2,000,000+ on the day and $3,000,000+ in the follow-up; Qkss lost $1,000,000+ the same way and got nothing.
“compromised through a support help request, for which the CS:GO team takes responsibility”Read the reporting and reproduced message ↗ archived 2025-08-18 ↗
The reply covers the compromised account and the reversal of its trades. Valve reversed them — so the trades were reversible. The original authenticated ticket is not in this collection.
The contractor dismissed its entire Steam-support staff — reported by Mzkshow via Dexerto, not a Valve personnel statement. Thirty-three months later Steam Support wrote to another collector that "a support technician that handled the help request failed to follow our process which resulted in your account restored to someone else." Valve's own sentence, about the same channel.
The second admission, 14 Nov 2025 ↗Neither the contractor nor the location is established by these sources. That is not a hole in the reporting — it is a disclosure Valve has not made about who held access to user accounts.
Contemporary account of the case ↗Three questions Valve has not answered: who could override account recovery, what the access audit found, and what changed afterwards.
Two 2024 Reddit posts relay further Mzkshow investigations — a July 2024 VAC-ban removal case and a December 2024 $13,000 inventory case. These are separately reported incidents. The accountability question in each is identical: who had override access, what did the audit find, and what changed.
05 / FOLLOW THE LOSS
Ten cases, June 2022 to March 2026. Every amount is the figure its named source published — $6,300,000, $2,000,000+, $1,000,000+, ≈$320,000, ≈$300,000, and down to €288. Valve holds the transaction log, the session record and the support audit trail for each one, and has produced none of them.
Attribution and amounts remain as reported by each source. Valve holds the transaction logs, session records and support audit trail for every one of these cases. Produce them. A preserved Reddit post does not settle the question — Valve's own records do.