# Their credentials. Their infrastructure.

Canonical: https://phishdestroy.io/steam_dossier/steam-access
Language: en
Author: Agent Milo
Publisher: PhishDestroy
Published: 11 October 2026

EVIDENCE FILE 03 / THE INFRASTRUCTURE RECORD OWNERSHIP, GAMBLING & PLATFORM CONTROL  10 OCT 2026 **•**  WORKING PAPER

STEAM ACCESS

The external service still needs the system Valve controls.

User API keys, publisher keys and Steam session JWTs serve different purposes. This file follows the documented credential paths, the infrastructure beneath them and the dated Link Filter responses. Version-pinned code audits remain attached as separate evidence files.

[Inspect the three credentials ↓](https://phishdestroy.io/steam_dossier/steam-access#access)  [Open the code audit ↗](https://phishdestroy.io/steam_dossier/trade-tracking.html)

FOLLOW THE ACCESS RECORD

1. 01 / ISSUE **A Steam credential.**

Account identity, issuer-defined context and expiry.
2. 02 / USE **A service receives access.**

Documented collection and renewal paths, pinned to their versions.
3. 03 / ENFORCE **A route can be examined.**

Saved requests, filter responses and the operator’s declared host.

01

TOKENS & PERMISSIONS

## Three credentials in the trading system

THREE CREDENTIALS / THREE ACCOUNT CONTEXTS

### User key. Publisher key. Session JWT.

Compare who receives each credential, what it accesses and how it enters the skin-trading system.

PHISHDESTROY / THE CONVENIENT CONFUSION

### Congratulations. The player is now the integration.

Automation is forbidden in the Subscriber Agreement. Meanwhile, an outside trading business teaches the player to supply the credentials its automated workflow needs. Whose automation is this—and whose account carries the consequences? [E09 §4.C](https://store.steampowered.com/agreement/?l=english)

FOR THE DEVELOPER

#### Applications. Permissions. IP restrictions.

A publisher needs an API to operate its game. Valve documents application associations, permission groups and optional calling-IP restrictions, and tells publishers to keep their keys on secure servers. A recognizable security model. [E16](https://partner.steamgames.com/doc/webapi_overview/auth)

FOR THE PLAYER

#### Copy this. Hand it over. Repeat.

Why must a person selling a skin become a credential courier? In April 2024, CSGORoll told sellers to obtain a token from their Steam session. In June, it announced an extension to collect, refresh and send that token to its servers. Very convenient—for the business receiving access. [E04](https://www.csgoroll.com/blog/steam-p2p-solution/) [E05](https://www.csgoroll.com/blog/csgoroll-trading-extension/)

What does the player gain: a game feature, or another account credential to hand to an outside operator? The dossier’s history of stolen inventories makes that a security question, not a terminology exercise. When one access route changes, the commercial system finds another route through the customer’s session.  [Read the original key-security investigation ↗](https://phishdestroy.io/steam_dossier/#vulnerability-profile)

CSGORoll’s own blog words: the P2P announcement presents the platform as the anti-scam enforcement layer — it bans scammers and gamblers, it says. In the same document it explains why Valve cannot ban the mechanism, because every trade belongs to a player’s account. Banning the bots, on this architecture, means banning the players. The operator’s security blog and the impossibility argument are the same sentence. [E04](https://www.csgoroll.com/blog/steam-p2p-solution/)

THE PDF / BOARDING-PASS LOGIC

A boarding pass can be a PDF. **So every PDF is a boarding pass?**

JWT describes the token’s format. “WebAPI” is the label used in this workflow. Neither answers the question of whose account authorizes the request. A reassuring name does not turn a player’s session credential into a publisher’s controlled integration.

The format is JWT. The account is the player’s. The outside operator receives the credential. Valve’s answer should explain the access and the protection—not invite the user to admire the vocabulary. [E17](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/jwt-field-excerpt.json) [E05](https://www.csgoroll.com/blog/csgoroll-trading-extension/)  [SIH’s token-return handler: read the actual code ↗](https://phishdestroy.io/steam_dossier/csgofast-sih.html#SC31)

Three columns · swipe horizontally to compare on a smaller screen →

User API Key, Publisher API Key and Session JWT compared using the same seven fields

| 01 STEAM ACCOUNT HOLDER **User API Key** A key registered to a user’s account. [E16 · User-key documentation ↗](https://partner.steamgames.com/doc/webapi_overview/auth) | 02 GAME DEVELOPER / PUBLISHER **Publisher API Key** A key managed by a Steamworks publisher. [E16 · Publisher-key documentation ↗](https://partner.steamgames.com/doc/webapi_overview/auth) | 03 LOGGED-IN STEAM SESSION **Session JWT** The browser’s `webapi_token`. [E04 · CSGORoll’s token instructions ↗](https://www.csgoroll.com/blog/steam-p2p-solution/) |
| --- | --- | --- |
| WHO GETS IT **A Steam account holder.** This is the personal user-key route. [E16](https://partner.steamgames.com/doc/webapi_overview/auth) | WHO GETS IT **A Steamworks publisher.** An administrator creates the key for a publisher group. [E16](https://partner.steamgames.com/doc/webapi_overview/auth) | WHO GETS IT **A logged-in Steam user’s browser.** The token comes from that active session. [E04](https://www.csgoroll.com/blog/steam-p2p-solution/) |
| WHERE IT COMES FROM **Account-key registration.** [steamcommunity.com/dev/apikey ↗](https://steamcommunity.com/dev/apikey) The registration associates a domain with the account’s key. | WHERE IT COMES FROM **Steamworks group administration.** [Steamworks → Users & Permissions → Manage Groups ↗](https://partner.steamgames.com/doc/webapi_overview/auth) The administrator chooses applications and key permissions. | WHERE IT COMES FROM **The browser’s session configuration.** [steamcommunity.com/pointssummary/ajaxgetasyncconfig ↗](https://steamcommunity.com/pointssummary/ajaxgetasyncconfig) CSGORoll’s instructions identify the field `webapi_token`. |
| WHAT IT GIVES ACCESS TO **Account data and user-key methods.** The trade-record reference includes `GetTradeHistory`, `GetTradeOffers` and `GetTradeOffer`. [E44](https://partner.steamgames.com/doc/webapi/IEconService) | WHAT IT GIVES ACCESS TO **Publisher and game-server operations.** Examples include player-ticket verification, purchases and inventory services, within the key’s permissions. [E16](https://partner.steamgames.com/doc/webapi_overview/auth) [E45](https://partner.steamgames.com/doc/webapi/ISteamUserAuth) | WHAT IT GIVES ACCESS TO **Authenticated access in the user’s session context.** CSGORoll documents using it to monitor the seller’s trades. [E04](https://www.csgoroll.com/blog/steam-p2p-solution/) |
| PERMISSIONS & IP CONTROLS **The Steam user’s account context.** Access is determined by which methods accept that key. The historical security record examines broad account access and its abuse. [Read the key-security record ↗](https://phishdestroy.io/steam_dossier/#vulnerability-profile) | PERMISSIONS & IP CONTROLS **App associations and permission groups.** A publisher key can also be restricted to selected calling IP addresses. [E16](https://partner.steamgames.com/doc/webapi_overview/auth) | PERMISSIONS & IP CONTROLS **Subject, audience and session claims.** The supplied JWT includes `sub`, `aud: web:community` and IP-related fields. Steam applies the access rules. [E17](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/jwt-field-excerpt.json) |
| LIFETIME & RENEWAL **A registered, persistent credential.** The historical investigation follows continued access after registration; Valve controls whether the key remains accepted. [Registration and lifecycle evidence ↗](https://phishdestroy.io/steam_dossier/#vulnerability-profile) | LIFETIME & RENEWAL **Managed through the publisher group.** Group configuration, permissions and Valve’s access controls govern its use. [E16](https://partner.steamgames.com/doc/webapi_overview/auth) | LIFETIME & RENEWAL **Temporary session credential.** Roll’s April 2024 instructions require daily replacement. The token carries an expiry time; the current code audit separately identifies the available renewal paths. [E04](https://www.csgoroll.com/blog/steam-p2p-solution/) |
| HOW IT REACHES A SERVER **A key in an API request.** Valve supports a request parameter or the `x-webapi-key` header. [E16](https://partner.steamgames.com/doc/webapi_overview/auth) | HOW IT REACHES A SERVER **A request from a secure publisher server.** The publisher host, `partner.steam-api.com`, requires a publisher key and HTTPS. [E43](https://partner.steamgames.com/doc/webapi_overview) | HOW IT REACHES A SERVER **A token handed to the outside platform.** Roll’s June 2024 announcement describes automatic collection, renewal and upload. Its current version 1.2 instead provides a token-copy popup for manual submission. [E05](https://www.csgoroll.com/blog/csgoroll-trading-extension/) |
| ROLE IN THIS INVESTIGATION **The historical account-access route.** The dossier follows key registration, consent attribution and trade substitution. [Registration and consent exhibits ↗](https://phishdestroy.io/steam_dossier/#consent-analysis) | ROLE IN THIS INVESTIGATION **The game-publisher integration route.** This is the developer-side context people often mean when they say “Steam API.” [E23](https://partner.steamgames.com/doc/sdk/api) [E45](https://partner.steamgames.com/doc/webapi/ISteamUserAuth) | ROLE IN THIS INVESTIGATION **The seller-session route documented by CSGORoll.** Monitoring the Steam exchange feeds the operator’s decision to credit or release its own coins. [E04](https://www.csgoroll.com/blog/steam-p2p-solution/) [E07](https://www.csgoroll.com/blog/trade-protection-update/) |

CSGOROLL’S DOCUMENTED ROUTE

**Column 03: the seller’s Steam session.**  The user supplies the token. The platform monitors the trade and controls the coin settlement.

THE STANDARDS LAG / PUBLIC, DATED, UNANSWERED

### The standards were public. The dates are the record.

Steam ships on the App Store and Google Play, sells through the major card processors, and consumes third-party APIs like any other large platform. Each of those relationships carries a published, dated security requirement that Valve must satisfy to keep operating. Nothing in this table is a private standard, an internal memo or a trade secret — every entry is a public document with a publication date. Set those dates against the dates on which Steam’s own Web API acquired the same protections. [E13](https://phishdestroy.io/steam_dossier/)

Published external security requirements set against the Steam Web API’s own dates

| The published standard | The date it took effect | The Steam Web API on the same question |
| --- | --- | --- |
| Scoped authorisation | OAuth 2.0 — RFC 6749, October 2012. Section 3.3 defines `scope` so a client receives only the access it asks for. It has been the default of every major platform API since. | **Granular scopes arrived on 16 January 2026.** Before that, a single Steam Web API key carried full read and write over the account’s trades regardless of why it was issued — thirteen years and three months after the specification that defines the control. |
| A second factor on privileged access | PCI DSS 3.2, requirement 8.3 — mandatory from 1 February 2018 for all non-console administrative and all remote access to the cardholder data environment. Apple then required two-factor authentication of every Developer Program account holder from 27 February 2019: “developers with the Account Holder role in a developer program will need to enable two-factor authentication to sign in.” | **A second factor was required to create an API key from 4 December 2023.** Until then a stolen session cookie was enough — no prompt on the account holder’s phone, no notification afterwards. Four years and nine months after Apple made Valve itself use a second factor merely to sign in to a developer portal. |
| Credential lifecycle and revocation | Twitch requires of every third-party application: “Your app must validate the OAuth token when it starts and on an hourly basis thereafter” — and retired its legacy v5 API outright on a published schedule, 28 February 2022. | **No published key-lifecycle record.** The 2023 change protected the creation endpoint; no Valve statement located with it addresses keys already registered, and no changelog accompanied the change at all. Whether pre-fix keys were invalidated cannot be established from public data. |

The benchmark, from the parent dossier’s token comparison: a GitHub fine-grained token can be restricted to a single repository, read-only, with a mandatory thirty-day expiry, and it logs IP, user agent and timestamp on every call. The Steam Web API key was a single 32-character string carrying full trade authority — read, cancel, decline — never expiring, with no IP binding and no user-visible audit trail. Valve’s own developers manage open-source software on GitHub daily inside the first model; the monolithic key was what 130 million Steam players were issued. [E13](https://phishdestroy.io/steam_dossier/)

2012 → 2026

**Thirteen years and three months.**  That is the interval between RFC 6749 defining scoped authorisation and the Steam Web API acquiring granular scopes on 16 January 2026. No key-lifecycle record has ever been published.

[The standards table in the parent dossier ↗](https://phishdestroy.io/steam_dossier/#integration-paradox)  [The GitHub / Steam token comparison ↗](https://phishdestroy.io/steam_dossier/#token-comparator)

START WITH THE TERMS

### An API is an interface. Access comes from a credential.

The phrase “Steam API” covers more than integration inside a game. Steam publishes both native game interfaces and HTTP services used by websites and account-based tools. Its own key documentation explicitly separates user keys from publisher keys. [E16](https://partner.steamgames.com/doc/webapi_overview/auth) [E34](https://steamcommunity.com/dev?l=en)

Steamworks SDK

Libraries and interfaces a developer integrates into a game: achievements, friends, leaderboards and other Steam features. [E23](https://partner.steamgames.com/doc/sdk/api)

Steam Web API

HTTP endpoints that software calls for data or operations. The method determines the authentication it requires. [E43](https://partner.steamgames.com/doc/webapi_overview)

API key / session token

The credential presented with a request. User keys, publisher keys and browser-session tokens belong to different account contexts.

JWT

A format that carries claims inside a token. It belongs to the credential layer.

Verification is a platform function.

02 APR 2024

### Steam restricts inventory visibility

Valve’s release notes introduce ten days of invisibility for purchased and traded Counter-Strike items when other users inspect an inventory. [E28](https://store.steampowered.com/news/posts/?appids=730&enddate=1714088148&feed=steam_community_announcements)

10 APR 2024

### Monitoring through a user’s token

After Steam’s API changes interrupted the previous P2P workflow, CSGORoll introduced a replacement: the seller supplies a token from their own logged-in Steam session. [E04](https://www.csgoroll.com/blog/steam-p2p-solution/)

25 JUN 2024

### The extension supplies the server

The extension workflow automatically collects, refreshes and sends the WebAPI token to CSGORoll’s servers. The user’s credential becomes part of the platform’s verification infrastructure. [E05](https://www.csgoroll.com/blog/csgoroll-trading-extension/)

01 OCT 2024

### The method changes. Control stays.

The later workflow adds inventory monitoring, user confirmation and platform-run disputes for token-free trades. The operator still decides how delivery is recognised and settlement proceeds. [E06](https://www.csgoroll.com/blog/new-trading-system/)

HOW THE CONTROL WORKS

### Identity. Monitoring. Settlement.

Identity

Steam OpenID identifies the account used to sign in to the outside service. [E08](https://store.steampowered.com/oldnews/22883)

Monitoring

The documented WebAPI token supplies authenticated access for trade checks. JWT is a format for carrying claims; the receiving service determines the access it accepts. [E05](https://www.csgoroll.com/blog/csgoroll-trading-extension/) [E11](https://www.rfc-editor.org/rfc/rfc7519)

Settlement

The operator links the recognised trade to its own coin ledger and release rules. [E07](https://www.csgoroll.com/blog/trade-protection-update/)

The mechanism connects the user’s Steam activity to an accounting decision controlled by the platform.

EXHIBIT B / THE DECODED FIELDS

### Read the credential behind the label.

The supplied excerpt declares `typ: JWT` and `alg: EdDSA`. Its claims name a Steam account, the `web:community` audience and timestamps. “WebAPI token” is the field name; JWT identifies the token format. [E17](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/jwt-field-excerpt.json) [E11](https://www.rfc-editor.org/rfc/rfc7519)

In June 2024, CSGORoll made the destination explicit: its extension transmits your WebAPI token to our servers. [E05](https://www.csgoroll.com/blog/csgoroll-trading-extension/)

The endpoint’s character: `ajaxgetasyncconfig` is undocumented and internal. Without a session it returns an empty shell — `{"success":1,"data":[]}` — with one, it hands the browser a signed JWT. Valve built it so Steam’s own site could call its own API; it was never built for a casino’s servers. No published contract, no scope negotiation, no revocation path for the third-party use documented here. And the session token travels as an `Authorization: Bearer` header, not in a URL — after the 2024 change it is the credential the trade methods accept. The credential changed; the third party watching your trades did not. [E04](https://www.csgoroll.com/blog/steam-p2p-solution/) [E17](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/jwt-field-excerpt.json)

[Inspect the redacted field record ↗](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/jwt-field-excerpt.json)

SUPPLIED DECODED EXCERPT  IDENTIFIERS REDACTED

typ / alg

JWT / EdDSA

sub

Steam account identifier

aud

["web:community"]

iat · nbf · exp

Issued · valid from · expires

jti

Token identifier

ip_subject ip_confirmer

IP-related claims  Values redacted

Field transcription from the investigation notes. No live credential is reproduced.

EVERY FIELD IN THE SUPPLIED EXCERPT

### Identity, time and issuer-defined context.

How to read the supplied JWT without confusing a field with a permission

| Field | Meaning in this record | Role in the access decision |
| --- | --- | --- |
| `typ` | JWT: the declared token type. | Identifies the format being parsed. |
| `alg` | EdDSA: the declared signing algorithm. [E25](https://www.rfc-editor.org/rfc/rfc8037) | The signing layer protects integrity. |
| `iss` | Issuer identifier. | Who issued the claims. |
| `sub` | Subject: the Steam account identifier in the supplied notes. | Which account the token concerns. |
| `aud` | Intended recipient; the excerpt contains `web:community`. | Audience validation, alongside the endpoint’s authorisation rules. |
| `iat` | Issue time. | When the token was created. |
| `nbf` | Earliest acceptance time. | The token is not valid before this time. |
| `exp` | Expiry time. | The token must cease to be accepted at expiry. |
| `jti` | Token identifier. | Identifies this token instance. |
| `oat`, `rt_exp` | Additional timestamps listed in the supplied Steam payload. | Issuer-defined session metadata. Their exact processing is part of Steam’s implementation. |
| `ip_subject`, `ip_confirmer` | IP-related fields, with addresses redacted. | Issuer-defined network context; enforcement depends on the receiving service. |

Standard claim definitions: RFC 7519, §4.1. Additional claim names: §4.3. The field values and names come from the supplied, redacted excerpt. [E11](https://www.rfc-editor.org/rfc/rfc7519) [E17](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/jwt-field-excerpt.json)

SIGNED JWT / THREE PARTS  ANNOTATED STRUCTURE

A compact signed JWT joins three base64url-encoded parts with dots. Select a part to see what it contributes. [E24](https://www.rfc-editor.org/rfc/rfc7515)

01 HEADER

02 PAYLOAD

03 SIGNATURE

```text
{
  "typ": "JWT",
  "alg": "EdDSA"
}
```

#### What kind of object is this?

The header declares the JWT type and EdDSA signature algorithm. These are the header values recorded in the supplied excerpt. The algorithm belongs to the signing layer. [E17](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/jwt-field-excerpt.json) [E25](https://www.rfc-editor.org/rfc/rfc8037)

TYPE + SIGNING METHOD

```text
{
  "sub": "[SteamID redacted]",
  "aud": ["web:community"],
  "iss": "[issuer value omitted]",
  "iat": "[issued timestamp]",
  "nbf": "[valid-from timestamp]",
  "exp": "[expiry timestamp]",
  "oat": "[additional timestamp]",
  "rt_exp": "[additional timestamp]",
  "jti": "[token ID omitted]",
  "ip_subject": "[redacted]",
  "ip_confirmer": "[redacted]"
}
```

#### Whose session context travels with it?

`sub` identifies the subject; `aud` identifies intended recipients. The standard timestamps record issuance, earliest acceptance and expiry. Steam’s additional fields carry issuer-specific session context. [E11](https://www.rfc-editor.org/rfc/rfc7519)

The field-by-field table above separates standard JWT claims from Steam’s additional session metadata. All supplied field names are also preserved in the downloadable excerpt.

IDENTITY + AUDIENCE + TIME

ENCODED HEADER + PAYLOAD **Signature integrity**

#### Readable claims, verifiable integrity.

A signature covers the encoded header and payload. Verification checks that signed input with the appropriate key. Base64url encoding makes those first two parts readable; encryption is a separate mechanism. [E24](https://www.rfc-editor.org/rfc/rfc7515)

This exhibit presents the supplied fields. The signature is represented structurally because the notes contain no complete signed token.

DECODING → CONTENT / VERIFICATION → INTEGRITY

FOLLOW THE ACCESS / CONTROL MODEL

A user's Steam session becomes part of the platform's verification workflow Steam issues a session credential. CSGORoll receives it through the documented manual or extension workflow, uses trade checks, and applies its own balance-release rules.

Swipe the diagram to inspect both sides.

01 / SESSION CONTEXT

#### The credential starts in the user’s Steam session.

Its account identifier, audience and timestamps travel in the token. CSGORoll’s documented seller workflow obtains this credential from the logged-in browser.

[E04 · Read the documented workflow ↗](https://www.csgoroll.com/blog/steam-p2p-solution/) [E17 · Supplied fields](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/jwt-field-excerpt.json)

EXPIRY / RENEWAL / CONTINUED MONITORING

#### A short-lived token can support an ongoing commercial connection.

Roll’s April 2024 instructions require daily replacement. Its June 2024 announcement describes background collection, refresh and upload. The currently distributed Roll package uses a manual-copy popup; Empire’s separately audited extension implements session renewal. These are different implementations of the same dependency: the platform needs continuing information from the user’s Steam account to settle its own ledger. [E04](https://www.csgoroll.com/blog/steam-p2p-solution/) [E05](https://www.csgoroll.com/blog/csgoroll-trading-extension/)

CODE AUDIT / 10 OCTOBER 2026

#### Follow the session credential into the extension.

The current CSGORoll-linked package and SIH 2.11.12 were inspected for token extraction, renewal triggers, server transmission and trade-control paths. The appendix pins each finding to a version, file and hash, and separates the 2024 workflow from the currently distributed code.

[Read the extension code audit ↗](https://phishdestroy.io/steam_dossier/extension-audit.html)

**Before the session-token workflow: the user-key registration problem +**

The Steam Dossier’s historical API-key case traces a credential registered through a compromised authenticated browser session. The consent action was not a person’s deliberate grant: the account holder never saw the key-registration page, and a script executed the headless POST that submitted the registration fields with the stolen session cookie — machine-injected consent. Steam Support nonetheless attributes the key to the account holder. Valve holds the registration and request records; publish who performed the consent action behind the key it attributed.  [Inspect the consent and registration record ↗](https://phishdestroy.io/steam_dossier/#consent-analysis)

The documented trade-substitution pattern then follows monitoring, cancellation and a replacement offer, with the user’s confirmation attached to the substituted transaction. A persistent account credential and an active session become parts of the same abuse chain.  [Follow the documented substitution sequence ↗](https://phishdestroy.io/steam_dossier/#hijack-simulation)

Valve’s public Web API documentation describes website developers and account-key registration. Its API Terms are dated July 2010. This history belongs to user-account access and web services, alongside the separate Steamworks game-integration pathway. [E33](https://steamcommunity.com/dev/apiterms) [E34](https://steamcommunity.com/dev?l=en)

The issuance record: Valve’s user-key page issued a 32-character hex key to any logged-in account in a single click — no terms confirmed, no verification, no email notification. A day-old account with nothing in it qualified. [E16](https://partner.steamgames.com/doc/webapi_overview/auth) [E34](https://steamcommunity.com/dev?l=en)

The key had no expiry, no scopes and no IP binding: all-or-nothing account access, passed as a bare `?key=` parameter in the URL — logged by proxies, cached by servers, preserved in links. “Endless session” is not a metaphor; it was the documented property of the credential. With that key a site could call `GetPlayerSummaries`, `GetOwnedGames` and the full `IEconService` trade set — reading the account’s economy with the owner’s eyes. For years this was the standard deposit path of every skin site. [E44](https://partner.steamgames.com/doc/webapi/IEconService)

The silent fix: until 4 December 2023, a stolen session cookie alone could register that full-privilege key — no password, no Steam Guard prompt, no notification to the person whose account it was. On that date Valve began requiring mobile confirmation for key registration, closing the cookie-only route — without a changelog, detected by users rather than announced, about seven years after Valve’s 2016 statement and roughly six after the scam panels the archive preserves. And Valve has published nothing about the keys minted before the fix: no statement located with the change addresses keys already registered, and whether pre-fix keys were invalidated cannot be established from public data. The key itself was built never to expire — the zombie-key reservoir, credentials minted from stolen cookies, invisible to their owners, absent from any record a data subject could inspect. The question every refund refusal turns on — is a key created on this account years ago still live? — is one only Valve can answer, and it has not. [E13](https://phishdestroy.io/steam_dossier/)  [Read the vulnerability profile and the fix record ↗](https://phishdestroy.io/steam_dossier/#vulnerability-profile)

The 2024 closure: Valve closed the key-protected trade methods — and the credential economy did not shrink, it migrated. Within days CSGORoll was instructing sellers to paste a live session token instead. Valve closed one door and the commercial system walked through the user’s own session. [E04](https://www.csgoroll.com/blog/steam-p2p-solution/)

[Read the historical registration and trade-method exhibits ↗](https://phishdestroy.io/steam_dossier/#api-reference)

THE HIJACK WALKTHROUGH / RECONSTRUCTION OF THE PRE-2023 PATTERN

### The victim never visits the key page.

The parent dossier’s interactive hijack simulation, promoted into this record. Before 2023, the stolen Steam session could register a persistent Web API key. That key let the attacker monitor and cancel the victim’s pending offer; the attacker’s clone account then sent the replacement. The victim’s mobile confirmation completed the substituted trade. The entry is ordinary phishing: a compromised friend account sends the link, the victim enters credentials and a Steam Guard code into a lookalike portal, and the phishing server captures the active `steamLoginSecure` session cookie. The second factor has been used, not bypassed — two-factor authentication protects the moment of login, not what the resulting session can do afterwards. The timings below are illustrative, not live measurements of the current platform; the sequence is the record. [E13](https://phishdestroy.io/steam_dossier/)

PHASE B / SILENT KEY REGISTRATION

#### The key is registered by a script.

> `POST` steamcommunity.com/dev/ajaxregisterkey `Cookie:` steamLoginSecure=<stolen session> `Body:` agreeToTerms=agreed&domain=`localhost`

The victim never saw the key-registration page. A script holding the stolen cookie executes the headless POST — and because a script has no real domain to give, it sends `localhost`, the value later found on the hijacked account. Valve returns a full-privilege master key. Pre-2023 this required no password, no Steam Guard approval and no notification, and the key came with no scope limit: a session cookie converted into a durable credential.

PHASE C / THE TRADE SWAP

#### The legitimate trade is cancelled and cloned.

The script polls `IEconService/GetTradeOffers`. The moment the victim initiates a legitimate trade, the script cancels it — sub-second, no prompt to the account holder — and a clone bot sends an identical offer carrying the same name and avatar, dressed with the recipient’s real profile data from `ISteamUser/GetPlayerSummaries`. Steam sees valid API calls carrying a valid key issued to that account. Every call is correctly authenticated.

THE EXPLOIT COMPLETED

#### The confirmation is genuine. The offer is not.

Expecting the mobile prompt for their original trade, the victim approves the replacement. The confirmation is authentic — made by the account holder, on a registered device — but the offer it confirms is not the one the user initiated. That is the record Steam Support reads when the complaint arrives, and the reason the archived complaints were closed as user error.

Four documented endpoints do the whole job — none of them is a flaw

| Endpoint | Role in the sequence | What it contributes |
| --- | --- | --- |
| `IEconService/GetTradeOffers` | Polls the account | Monitors the account’s trade offers — the details of newly created, pending or modified offers, including offer IDs and the recipient’s profile. [E44](https://partner.steamgames.com/doc/webapi/IEconService) |
| `IEconService/CancelTradeOffer` | Voids the real trade | Programmatically invalidates the legitimate offer before the account holder completes the mobile confirmation. |
| `ISteamUser/GetPlayerSummaries` | Dresses the clone | Returns the legitimate recipient’s profile name and avatar URL, so a prepared clone account can be dressed to match. |
| `dev/ajaxregisterkey` | Mints the credential | Historically, any active `steamLoginSecure` cookie session could register a key — no Steam Guard confirmation on the mobile device, no notification to the account holder. [E34](https://steamcommunity.com/dev?l=en) |

The consent checkbox was never clicked by a human. Under GDPR Article 7 and Article 4(11), consent must be a freely given, specific, informed and unambiguous indication of the data subject’s wishes — a headless POST carrying a stolen cookie is none of those things. It is a forged signature on a transfer of liability. The dossier’s position is that a terms-acceptance field submitted by a hostile script, with no page shown to the account holder, cannot meet that definition; whether it does is for the supervisory authority. [E13](https://phishdestroy.io/steam_dossier/)

FOUR ENDPOINTS NONE IS A FLAW

**A stolen session could mint durable account access.**  No server exploit was required. The stolen session registered the key; the key supplied monitoring and cancellation; the clone account supplied the replacement offer. Steam accepted the credentials at each step. The defect was the authority granted without an effective check on who was exercising it. [E13](https://phishdestroy.io/steam_dossier/)

[Step through the hijack simulation in the parent dossier ↗](https://phishdestroy.io/steam_dossier/#hijack-simulation)

FIRST ABUSE / NOTIFICATION / FIX / REAPPEARANCE

#### The abuse mechanisms returned more than once. Publish the trail per mechanism.

The API-key registration route was restricted and reappeared through session tokens. Session theft was answered and returned through extensions reading the same cookies. For each mechanism, the record request aimed at Valve is the same trail: first abuse, first user notification, fix date, reappearance — and the losses carried in between. [E04](https://www.csgoroll.com/blog/steam-p2p-solution/) [E05](https://www.csgoroll.com/blog/csgoroll-trading-extension/)

THE DOCUMENTED CONNECTION

1. 01 **Steam session**

The seller is logged in.
2. 02 **Token handoff**

The platform receives the session token.
3. 03 **Trade monitoring**

Delivery is checked through the documented workflow.
4. 04 **Platform balance**

Recognition and coin release follow the operator’s rules.

PUBLIC VISIBILITY / ITEM LINEAGE

#### The original-ID tracking route was removed.

The former `IEconItems_730/GetPlayerItems` endpoint exposed an item’s original identifier, which could be matched across inventory changes. Its closure in 2017 removed that public identifier from the tracking route. The engineering history describes the replacement approach using float, seed and paint properties. That matching method does not restore the original-ID record. [E48](https://blog.csfloat.com/how-floatdb-tracks-items/)

The consequence for this investigation is control over evidence: the user is asked to explain where an item went while the authoritative transfer records remain inside Steam. The dossier follows the loss of public tracing and what it means for a victim seeking a remedy.

[Read the item-lineage and evidence-access record ↗](https://phishdestroy.io/steam_dossier/#evidence-blackout)

IDENTITY / CREDENTIAL / ECONOMIC RESULT

### Follow what each step gives the platform.

Three different operations in one user journey

| Step | What moves through the system | What the operator obtains |
| --- | --- | --- |
| Steam OpenID | Steam returns an authenticated SteamID to the service’s login flow; the request declares the service’s return address. | An authenticated Steam identity for the site’s user record. [E34](https://steamcommunity.com/dev?l=en) |
| Session-token handoff | The seller’s browser-session token is copied or collected by the extension. | The credential used in the documented trade-monitoring workflow. [E05](https://www.csgoroll.com/blog/csgoroll-trading-extension/) |
| Settlement decision | A Steam transfer is recognised under the platform’s verification rules. | The basis for crediting, withholding or releasing its own coin balance. [E07](https://www.csgoroll.com/blog/trade-protection-update/) |

The intermediary has moved into the account-access and accounting layers. Direct item delivery leaves that control in place.

**The concrete interfaces: account data, trade records and publisher servers +**

The Web API is organised as host → interface → method → version. A method is an operation; its required credential determines the account context accepted for that operation. The reference documentation therefore has to be read at both levels. [E43](https://partner.steamgames.com/doc/webapi_overview)

Concrete technical examples behind the terminology

| Reference | What it describes | Why it matters here |
| --- | --- | --- |
| `api.steampowered.com` | HTTP services organised into named methods, with public and authenticated operations. | A website or server can make these calls; the interface extends beyond code running inside a game. |
| `IEconService` | Trade history and offer records, including `GetTradeHistory`, `GetTradeOffers` and `GetTradeOffer`. | These methods document a user authentication key: a concrete account-access role outside game-client integration. [E44](https://partner.steamgames.com/doc/webapi/IEconService) |
| `ISteamUserAuth/AuthenticateUserTicket` on `partner.steam-api.com` | Publisher-side verification of a user’s authentication ticket. | The application’s identity and the publisher’s credential are explicit parts of the request. [E45](https://partner.steamgames.com/doc/webapi/ISteamUserAuth) |
| `partner.steam-api.com` | A separate HTTPS host for secure publisher servers; every request requires a publisher key. | Valve documents its availability, firewall setup and access requirements separately from the public host. [E43](https://partner.steamgames.com/doc/webapi_overview) |

The publisher contour is engineered like a real API boundary: a key required on every request, 403 and a hard IP rate-limit without it, a host outside the shared Akamai cache, HTTPS only, documented CIDR ranges for firewalls — and publisher access scoped to the partner’s own AppIDs: leaderboards, micro-transactions, workshop moderation and finance calls through `ISteamMicroTxn`, `ISteamLeaderboards`, `IPublishedFileService` and `IPartnerFinancialsService`. Everything the user-key page lacked in 2010–2024 exists one layer up — for publishers. [E43](https://partner.steamgames.com/doc/webapi_overview) [E16](https://partner.steamgames.com/doc/webapi_overview/auth)

Publisher-key documentation adds group administration, application associations, method permission groups and optional IP allowlists. CSGORoll’s documented token handoff instead starts with the seller’s Steam Community session. That is the access relationship the investigation follows. [E16](https://partner.steamgames.com/doc/webapi_overview/auth) [E04](https://www.csgoroll.com/blog/steam-p2p-solution/)

[Original Web API overview ↗](https://partner.steamgames.com/doc/webapi_overview)  [JWT format reference ↗](https://www.jwt.io/)

NEW / EMPIRE, ROLL & FAST

### Trade tracking. Session access.

Empire’s login-cookie extraction and inactive session-renewal tab; Roll’s two extension identities; Fast’s current SIH installation and permission flow. The code is pinned to downloaded packages and public frontend files.

[Open the new investigation ↗](https://phishdestroy.io/steam_dossier/trade-tracking.html)

02

THE INFRASTRUCTURE BELOW THE PLATFORM

## Valve supplies the rails.

Two central authorities. Different parts of the same exchange.

Valve governs the Steam account and item infrastructure. The outside operator governs its own ledger and access rules. Moving the item directly between users leaves both dependencies in place.

Steam’s agreement confines Wallet funds to its ecosystem and makes their use subject to Valve’s rules. The outside operator adds another controlled balance and another set of conditions around the same item economy. [E09](https://store.steampowered.com/agreement/?l=english)

13 JUL **2016**  VALVE / PUBLIC STATEMENT

### The mechanism was already named.

Valve identified Steam authentication and automated account activity in skin gambling, said it had no business relationships with those sites, and stated that using those services to operate a gambling business was prohibited.

[E08 · Read Valve’s statement ↗](https://store.steampowered.com/oldnews/22883)

[S / D CONTINUE THE INFRASTRUCTURE INVESTIGATION ### Their rules. Their system. The Steam Dossier examines the written rules, observed routes and enforcement record. ↗](https://phishdestroy.io/steam_dossier/)

USERS, DEVELOPERS AND THE RIGHT TO DECIDE

#### Documentation does not give the community control.

Valve’s API terms reserve the ability to change the service or end access, including access for a particular application. Developers can build an integration and users can participate in it, but both remain dependent on decisions made by Valve. A public interface, a discussion board or a wiki does not transfer authority over those decisions to its readers. [E33](https://steamcommunity.com/dev/apiterms)

That is the communication and accountability problem: the people affected need an attributable rule, change record and reasoned remedy, while the power to accept a credential, move an item or restore access stays with the platform.

[Inspect our captured support, developer and wiki records ↗](https://phishdestroy.io/steam_dossier/steam_evidence_archive)

THREE POSITIONS / ONE ITEM ECONOMY

### The right being defended runs through the system being restricted.

13 JUL 2016

#### The real-money boundary

> “Steam does not have a system for turning in-game items into real world currency.”

> “We have no business relationships with any of these sites. We have never received any revenue from them. And Steam does not have a system for turning in-game items into real world currency.”

The full statement is the quote to test: ten years later, every clause is testable against the fee record, the sponsorship record and the $1 million sale. [E08](https://store.steampowered.com/oldnews/22883) [E38](https://ag.ny.gov/sites/default/files/court-filings/new-york-v-valve-corporation-complaint-2026.pdf)

> “Using the OpenID API and making the same web calls as Steam users to run a gambling business is not allowed by our API nor our user agreements.”

In 2026 the same web calls are made with a session token pasted by the user — and the calls are the user’s own. Valve wrote the rule in a form its own architecture evades. [E04](https://www.csgoroll.com/blog/steam-p2p-solution/)

[Erik Johnson / Valve’s original statement ↗](https://store.steampowered.com/oldnews/22883)

THE RULEBOOK

#### The commercial-use boundary

Steam’s rules reserve commercial permissions and explicitly list gambling under prohibited commercial activity. The participant’s account supplies the access through which an outside service can operate.

[Steam Online Conduct ↗](https://store.steampowered.com/online_conduct/)

11 MAR 2026

#### The transferability defence

Valve presents continued transfers as a consumer right. The same transfers let items leave one account for another while an outside platform handles the cash or coin side of the exchange.

[Valve’s public response ↗](https://help.steampowered.com/en/faqs/view/6300-A6C4-519D-A3F5)

Reading these positions together reveals the selective boundary. The system’s public description can stop at Steam’s Wallet, while its items travel through cash-priced outside markets. The right invoked for the collector is also the infrastructure used by the commercial service. The investigation follows the whole route across that boundary.

2016 / 2026 ONE SYSTEM

**Both cannot be the company’s understanding of its own system.**  2016 — “Steam does not have a system for turning in-game items into real world currency.” 2026 — transferability is a right Valve refuses to remove, while the complaint records a $1 million sale. [E08](https://store.steampowered.com/oldnews/22883) [E14](https://help.steampowered.com/en/faqs/view/6300-A6C4-519D-A3F5) [E38](https://ag.ny.gov/sites/default/files/court-filings/new-york-v-valve-corporation-complaint-2026.pdf)

[Subscriber Agreement analysis ↗](https://phishdestroy.io/steam_dossier/#tos-structural-void)  [Clauses against recorded platforms ↗](https://phishdestroy.io/steam_dossier/#legal-ledger-workspace-section)  [The market above Steam’s ceiling ↓](https://phishdestroy.io/steam_dossier/gambling-system.html#price-gap)

OCT **2016**  VALVE / WSGC RESPONSE

### Forty notices. Account-level enforcement.

Valve told the Washington State Gambling Commission it had sent cease-and-desist notices to more than forty sites and disabled associated Steam accounts, while defending Steam trading and OpenID. The response is the direct anchor for the closing demand below: publish when access was disabled, what returned and under whose control.

[E19 · Valve’s October 2016 response ↗](https://fr.scribd.com/document/328063293/Valve-s-Oct-18th-response-to-Washington-State-Gambling-Commission-s-cease-and-desist)

The July 2016 notices set a ten-day deadline. Our dossier follows that demand through the October response and into a route register where 26 main-domain warnings coexist with separate authentication hosts. The register counts 44 separate auth-host domains carrying Steam logins for third-party platforms beside those 26 blocked main domains — each a domain registered apart from the platform’s main address; the split is systematic, not incidental. [E13](https://phishdestroy.io/steam_dossier/) The oldest recorded split route reaches back to a March 2014 host registration. The register preserves those dated checkpoints and identifies the mechanism Valve’s enforcement should have interrupted. Publish when access was disabled, what returned and under whose control.

[Open letter and Washington record ↗](https://phishdestroy.io/steam_dossier/#wsgc-public-address)  [July 2016 notices and dated history ↗](https://phishdestroy.io/steam_dossier/#case-study-section)  [The route register ↗](https://phishdestroy.io/steam_dossier/#proxy-bypass-explainer)

03

THE VISIBLE ENFORCEMENT LAYER

## Same filter. Different treatment.

20 URLS CHECKED

We submitted the addresses in this investigation to Steam’s own Link Filter. CSGORoll, CSGOEmpire and Hellcase received an ordinary external-link notice with a continue link. The exact `www.csgoroll.com` variant also supplied a continue link. Sixteen other supplied addresses received a hard block. The difference is visible in Valve’s response. [E18](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/linkfilter-2026-10-10.json)

**Steam’s browser, Big Picture and the destination warning +**

Valve’s original Big Picture presentation includes a built-in web browser. DARKNAVY’s June 2024 technical research describes Steam’s `steamwebhelper` as a Chromium Embedded Framework application rendering Store, Community and Friends content. [E46](https://store.steampowered.com/bigpicture/) [E47](https://www.darknavy.org/blog/exploiting_steam_usual_and_unusual_ways_in_the_cef_framework/)

The browser surface and the Link Filter perform different jobs: one renders the page; the other controls Steam’s warning and onward link. The investigation follows that visible destination decision. For the supplied gambling addresses below, the wrapper either blocks the route or supplies a continue link. The wider dossier examines the client, overlay and Big Picture context.

The Link Filter’s character is a man-in-the-middle layer on every link Steam users exchange: Steam intercepts the destination, renders its own warning page, and decides whether to hand the user onward. The same interception Valve once needed bots for, repackaged as a “safety” feature whose block list Valve controls.

[Read the embedded-browser and authentication-route investigation ↗](https://phishdestroy.io/steam_dossier/#proxy-bypass-explainer)

CSGOROLL.COM / SAVED RESPONSE

### “Notice: You are leaving Steam.”

“Continue to external site”

The returned page includes an onward link.

[Open this Steam check ↗](https://steamcommunity.com/linkfilter/?url=https://csgoroll.com)

SKINPORT.COM / SAVED RESPONSE

### “Link Blocked!”

NO CONTINUE LINK

The returned page withholds the onward link.

[Open this Steam check ↗](https://steamcommunity.com/linkfilter/?url=https://skinport.com)

CAPTURED 10 OCT 2026 · 19:02–19:03 UTC / WWW CHECK 20:27 UTC

Public HTTPS responses, without a signed-in Steam session.

Saved Steam Link Filter responses for the supplied addresses

| Address submitted | Observed response | Continue link | Original URL |
| --- | --- | --- | --- |
| [csgoroll.com ↗](https://steamcommunity.com/linkfilter/?url=https://csgoroll.com) | Continue link present | Yes | [Steam response ↗](https://steamcommunity.com/linkfilter/?url=https://csgoroll.com) |
| [www.csgoroll.com ↗](https://steamcommunity.com/linkfilter/?url=https://www.csgoroll.com/) | Continue link present | Yes | [Steam response ↗](https://steamcommunity.com/linkfilter/?url=https://www.csgoroll.com/) |
| [csgoempire.com ↗](https://steamcommunity.com/linkfilter/?url=https://csgoempire.com/) | Continue link present | Yes | [Steam response ↗](https://steamcommunity.com/linkfilter/?url=https://csgoempire.com/) |
| [hellcase.com ↗](https://steamcommunity.com/linkfilter/?url=https://hellcase.com) | Continue link present | Yes | [Steam response ↗](https://steamcommunity.com/linkfilter/?url=https://hellcase.com) |
| [csgostrong.com ↗](https://steamcommunity.com/linkfilter/?url=https://csgostrong.com) | Link Blocked | No | [Steam response ↗](https://steamcommunity.com/linkfilter/?url=https://csgostrong.com) |
| [csgo500.com ↗](https://steamcommunity.com/linkfilter/?url=https://csgo500.com) | Link Blocked | No | [Steam response ↗](https://steamcommunity.com/linkfilter/?url=https://csgo500.com) |
| [csgocosmos.com ↗](https://steamcommunity.com/linkfilter/?url=https://csgocosmos.com) | Link Blocked | No | [Steam response ↗](https://steamcommunity.com/linkfilter/?url=https://csgocosmos.com) |
| [csgocasino.net ↗](https://steamcommunity.com/linkfilter/?url=https://csgocasino.net) | Link Blocked | No | [Steam response ↗](https://steamcommunity.com/linkfilter/?url=https://csgocasino.net) |
| [csgo2x.com ↗](https://steamcommunity.com/linkfilter/?url=https://csgo2x.com) | Link Blocked | No | [Steam response ↗](https://steamcommunity.com/linkfilter/?url=https://csgo2x.com) |
| [csgohouse.com ↗](https://steamcommunity.com/linkfilter/?url=https://csgohouse.com) | Link Blocked | No | [Steam response ↗](https://steamcommunity.com/linkfilter/?url=https://csgohouse.com) |
| [csgoatse.com ↗](https://steamcommunity.com/linkfilter/?url=https://csgoatse.com) | Link Blocked | No | [Steam response ↗](https://steamcommunity.com/linkfilter/?url=https://csgoatse.com) |
| [csgocash.com ↗](https://steamcommunity.com/linkfilter/?url=https://csgocash.com) | Link Blocked | No | [Steam response ↗](https://steamcommunity.com/linkfilter/?url=https://csgocash.com) |
| [csgobig.com ↗](https://steamcommunity.com/linkfilter/?url=https://csgobig.com) | Link Blocked | No | [Steam response ↗](https://steamcommunity.com/linkfilter/?url=https://csgobig.com) |
| [csgomassive.com ↗](https://steamcommunity.com/linkfilter/?url=https://csgomassive.com) | Link Blocked | No | [Steam response ↗](https://steamcommunity.com/linkfilter/?url=https://csgomassive.com) |
| [skins2.com ↗](https://steamcommunity.com/linkfilter/?url=https://skins2.com) | Link Blocked | No | [Steam response ↗](https://steamcommunity.com/linkfilter/?url=https://skins2.com) |
| [csgopot.com ↗](https://steamcommunity.com/linkfilter/?url=https://csgopot.com) | Link Blocked | No | [Steam response ↗](https://steamcommunity.com/linkfilter/?url=https://csgopot.com) |
| [csgowild.com ↗](https://steamcommunity.com/linkfilter/?url=https://csgowild.com) | Link Blocked | No | [Steam response ↗](https://steamcommunity.com/linkfilter/?url=https://csgowild.com) |
| [skinport.com ↗](https://steamcommunity.com/linkfilter/?url=https://skinport.com) | Link Blocked | No | [Steam response ↗](https://steamcommunity.com/linkfilter/?url=https://skinport.com) |
| [gamdom.com ↗](https://steamcommunity.com/linkfilter/?url=https://gamdom.com) | Link Blocked | No | [Steam response ↗](https://steamcommunity.com/linkfilter/?url=https://gamdom.com) |
| [csgofast.hk ↗](https://steamcommunity.com/linkfilter/?url=https://csgofast.hk) Supplied test address | Link Blocked | No | [Steam response ↗](https://steamcommunity.com/linkfilter/?url=https://csgofast.hk) |

Showing all 20 recorded responses.

All 20 returned HTTP 200. The classification above comes from the page heading and the presence or absence of an actual continue anchor. Links open the current Steam response; the downloadable record preserves the dated observations.

[Download the checks and timestamps ↗](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/linkfilter-2026-10-10.json)

THE ENFORCEMENT QUESTION

The filter can withhold a destination link. For these three sites it supplied one. **What rule explains that dividing line?**

[26 THE WIDER ROUTE REGISTER ### A blocked homepage. An available login route. The Steam Dossier’s September register follows 26 filter-split pairs from the main domain to a separate Steam authentication host. ↗](https://phishdestroy.io/steam_dossier/#proxy-bypass-explainer)

THE ADDRESS-STRING TEST

### What does the filter react to?

We also submitted the `csgofast` name in five literal forms. Steam blocked the bare host, the .com and .hk forms, and a subdomain under example.com. The same text in the query-string example received an ordinary notice. [E36](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/linkfilter-pattern-2026-10-10.json)

The filter’s own character is undocumented: Steam has never documented how the Link Filter decides. It appeared around 2016, without announcement, and its block list is not published. The only way to test the enforcement layer Valve actually ships is to submit addresses and record the answers — which is what this register does.

Five literal address inputs and saved Steam responses

| Literal target submitted | Saved result |
| --- | --- |
| [https://csgofast ↗](https://steamcommunity.com/linkfilter/?url=https://csgofast) | Link Blocked |
| [https://csgofast.com ↗](https://steamcommunity.com/linkfilter/?url=https://csgofast.com) | Link Blocked |
| [https://csgofast.hk ↗](https://steamcommunity.com/linkfilter/?url=https://csgofast.hk) | Link Blocked |
| [https://example.com/?name=csgofast ↗](https://steamcommunity.com/linkfilter/?url=https://example.com/?name=csgofast) | Continue link present |
| [https://csgofast.example.com ↗](https://steamcommunity.com/linkfilter/?url=https://csgofast.example.com) | Link Blocked |

10 October 2026 · 19:09–19:10 UTC. The displayed links preserve the exact literal requests used for this comparison.

[Download this five-input check ↗](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/linkfilter-pattern-2026-10-10.json)

THE PHISHING AUDIT / 120 DOMAINS · 24 SEPTEMBER 2026

### The filter reads the gambling list fluently. It has never ingested a phishing feed.

The parent dossier submitted 120 confirmed Steam-specific phishing domains to Valve’s own Link Filter in three historical cohorts, tested live on 24 September 2026. On the desktop, external defenses such as Google Safe Browsing and Microsoft SmartScreen intercept known phishing with full-screen warnings; inside Steam’s embedded browser — Big Picture, the in-game overlay, the Steam Deck — those defenses do not exist, and the Link Filter is the one barrier left. [E13](https://phishdestroy.io/steam_dossier/) [E46](https://store.steampowered.com/bigpicture/) [E47](https://www.darknavy.org/blog/exploiting_steam_usual_and_unusual_ways_in_the_cef_framework/)

120 confirmed Steam-phishing domains, three cohorts, one filter

| Cohort | What was submitted | Passed clean |
| --- | --- | --- |
| 2021–2022 legacy phishing | Classic trade-offer and item-drop campaigns. Even 4 to 5 years after being cataloged by community watchdogs, seven in ten of these hosts still open with no block. | **70.0%** (28/40) |
| 2023–2024 CS2-era phishing | Campaigns impersonating Counter-Strike 2 releases and fake community appeals — `cs2-steam.com`, `appealsteamcommunity.help` — pass straight through. | **77.5%** (31/40) |
| 2025–2026 edge phishing | Serverless edge deploys and favicon clones on EdgeOne, Vercel and Cloudflare Pages — `steamgifter.online` and its kin — pass virtually unobstructed. | **92.5%** (37/40) |
| Gambling mains positive control | The control every phishing audit needs: the filter’s own category. | **7 / 7 blocked** |

The filter’s one demonstrated fluency is the gambling list. Independent threat-intelligence platforms surface live Steam phishing kits in seconds by searching for Steam’s official favicon hash; Valve does not sync with external feeds, does not run hash-based threat hunting, and manually intervenes when compelled by regulators — the 2016 WSGC gambling order — or to protect its trademarked domain strings. The filter reads the gambling list fluently; it has never ingested a phishing feed. [E13](https://phishdestroy.io/steam_dossier/)

TELEMETRY, NOT PROTECTION

**A layer that passes 92.5% of live 2025–2026 phishing hosts is not a shield.**  It presents a polite “You are leaving Steam” notice with a clickable proceed button, shifts the blame onto the click, and collects the telemetry of the click — while the theft passes through.

[Read the 120-domain longitudinal phishing audit ↗](https://phishdestroy.io/steam_dossier/#linkfilter-coverage)

[THE CENTRAL INVESTIGATION **Valve & enforcement ↗**](https://phishdestroy.io/steam_dossier/valve-and-enforcement.html)  [NEXT EVIDENCE FILE **Identity demands & AML ↗**](https://phishdestroy.io/steam_dossier/aml-data.html)

04

THE PUBLIC RECORD

## Inspect the evidence.

28 RECORDS

Sources cited in this article appear first. Select “All records” to inspect the complete 107-record register shared by the investigation; the dedicated evidence files retain their own detailed registers.

**Methodology & source notes**

Research date: 10 October 2026. The credential comparison separates user API keys, publisher keys and session JWTs. Historical workflows retain their dates; the supplied JWT fields are transcribed with identifiers redacted. The package-specific checks continue in  [the extension audit](https://phishdestroy.io/steam_dossier/extension-audit.html)  and  [the three-operator comparison](https://phishdestroy.io/steam_dossier/trade-tracking.html) .

The Link Filter records preserve literal request URLs, timestamps, observed headings and continue links. Diagrams illustrate the documented paths; they do not execute account operations. The public-response and ownership analysis remains in  [Valve and enforcement](https://phishdestroy.io/steam_dossier/valve-and-enforcement.html) .

## Cited source records

### E04 · WebAPI P2P Solution

Publisher: CSGORoll
Date: 10 Apr 2024
Reviewed: 10 October 2026

[Original record](https://www.csgoroll.com/blog/steam-p2p-solution/)

A dated account of token collection for monitoring trades, including session dependence and expiration.

Record scope: Technical record dated 10 April 2024; the subsequent workflow changes appear in E05–E07.

### E05 · WebAPI Trading Extension

Publisher: CSGORoll
Date: 25 Jun 2024
Reviewed: 10 October 2026

[Original record](https://www.csgoroll.com/blog/csgoroll-trading-extension/)

The announcement says the extension automatically collects and refreshes the Steam WebAPI token and transmits it to the operator’s servers.

Record scope: The token collection, refresh and server-transmission workflow announced on 25 June 2024.

### E06 · New Escrow, Dispute and Penalty Systems for Trades

Publisher: CSGORoll
Date: 01 Oct 2024
Reviewed: 10 October 2026

[Original record](https://www.csgoroll.com/blog/new-trading-system/)

Platform-defined manual completion after ten minutes, disputes, escalating penalties and inventory-based verification; a token-free route was described for certain skins.

Record scope: Dated record of the manual verification, dispute and penalty workflow introduced in October 2024.

### E07 · Trade Protection Update

Publisher: CSGORoll
Date: 16 Jul 2025
Reviewed: 10 October 2026

[Original record](https://www.csgoroll.com/blog/trade-protection-update/)

Coin-release timing during the seven-day protection window, tier-dependent instant access and consequences for reversals.

Record scope: The coin-release mechanism described on 16 July 2025; tiers and limits are adjustable under that policy.

### E08 · In-Game Item Trading Update

Publisher: Valve
Date: 13 Jul 2016
Reviewed: 10 October 2026

[Original record](https://store.steampowered.com/oldnews/22883)

Valve’s account of identity verification and automated trading used by gambling services, its stated prohibition and its denial of business relationships with those sites.

Record scope: Valve’s public statement from July 2016, retained here as a historical infrastructure record.

### E09 · Steam Subscriber Agreement

Publisher: Valve
Date: Live agreement
Reviewed: 10 October 2026

[Original record](https://store.steampowered.com/agreement/?l=english)

Valve’s licence grant, the absence of ownership interest in marketplace subscriptions, and Steam Wallet restrictions.

Record scope: Relevant clauses: §1.C (personal account), §2.A/2.G (licence and commercial use), §3.C/3.D (Wallet and marketplace), §4.D and §9.C (enforcement).

### E11 · RFC 7519 — JSON Web Token

Publisher: IETF / RFC Editor
Date: May 2015
Reviewed: 10 October 2026

[Original record](https://www.rfc-editor.org/rfc/rfc7519)

JWT represents claims in a token format. A service uses its own verification and authorisation rules when accepting the token.

Record scope: Technical definition of the JWT format; endpoint permissions are determined by the receiving service.

### E13 · The Steam Dossier — rules, routes and accountability

Publisher: PhishDestroy
Date: Related investigation
Reviewed: 10 October 2026

[Original record](https://phishdestroy.io/steam_dossier/)

The parent investigation supplies the historical registration and consent exhibits, transfer-substitution sequence, route register, ownership and recovery records, and correspondence used by this companion investigation.

Record scope: The parent PhishDestroy investigation; linked as the wider editorial and infrastructure context.

### E14 · About the New York Attorney General lawsuit against Valve

Publisher: Valve
Date: 11 Mar 2026
Reviewed: 10 October 2026

[Original record](https://help.steampowered.com/en/faqs/view/6300-A6C4-519D-A3F5)

The public collectibles comparison, optional and cosmetic framing, transferability argument, account-ban total, privacy objections and legislative position.

Record scope: Corporate public response dated 11 March 2026; linked alongside the filed complaint and the investigation’s analysis.

### E16 · Authentication using Web API Keys

Publisher: Valve / Steamworks
Date: Live documentation
Reviewed: 10 October 2026

[Original record](https://partner.steamgames.com/doc/webapi_overview/auth)

User-key registration and publisher keys with app associations, permission groups and configurable IP restrictions.

Record scope: Sections: User Keys, Publisher Keys and Creating a Publisher Web API Key.

### E17 · Decoded JWT fields — redacted transcription

Publisher: Author-supplied notes
Date: Supplied with this investigation
Reviewed: 10 October 2026

[Original record](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/jwt-field-excerpt.json)

Declared JWT type, EdDSA algorithm, Steam account subject, web:community audience and supplied timestamp and IP-related field names.

Record scope: Field transcription with account and IP identifiers redacted. Signature bytes were not supplied.

### E18 · Link Filter — 20-URL observation record

Publisher: PhishDestroy / public Steam responses
Date: 10 Oct 2026 · 19:02–19:03 / 20:27 UTC
Reviewed: 10 October 2026

[Original record](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/linkfilter-2026-10-10.json)

Four ordinary notices with continue anchors and sixteen hard blocks for the exact supplied wrapper URLs, including both CSGORoll hostname variants.

Record scope: Unauthenticated HTTPS requests; classification by returned page heading and continue-anchor presence. Exact URLs and timestamps preserved.

### E19 · October 2016 response to the Washington State Gambling Commission

Publisher: Valve / legal correspondence
Date: October 2016
Reviewed: 10 October 2026

[Original record](https://fr.scribd.com/document/328063293/Valve-s-Oct-18th-response-to-Washington-State-Gambling-Commission-s-cease-and-desist)

Valve’s explanation of Steam trading, OpenID, notices to more than forty sites and account-level enforcement.

Record scope: Public document copy linked by the Steam Dossier; the letter itself is dated 17 October 2016.

### E23 · Steamworks API Overview — native game integration

Publisher: Valve / Steamworks
Date: Live documentation
Reviewed: 10 October 2026

[Original record](https://partner.steamgames.com/doc/sdk/api)

The native Steamworks SDK, C++ interfaces, libraries, initialization and game feature integration.

Record scope: The game-integration layer contrasted with the HTTP Web API and its account credentials.

### E24 · RFC 7515 — JSON Web Signature

Publisher: IETF / RFC Editor
Date: May 2015
Reviewed: 10 October 2026

[Original record](https://www.rfc-editor.org/rfc/rfc7515)

Compact signed-token structure, encoded header and payload, signature input and verification.

Record scope: Sections 3.1 and 5 describe compact serialization and signing/validation.

### E25 · RFC 8037 — EdDSA in JOSE

Publisher: IETF / RFC Editor
Date: Jan 2017
Reviewed: 10 October 2026

[Original record](https://www.rfc-editor.org/rfc/rfc8037)

The EdDSA algorithm identifier used for signatures in the JOSE framework.

Record scope: Section 3.1; relevant to the declared alg value in the supplied header.

### E28 · Release notes — inventory visibility

Publisher: Valve / Counter-Strike
Date: 2 Apr 2024
Reviewed: 10 October 2026

[Original record](https://store.steampowered.com/news/posts/?appids=730&enddate=1714088148&feed=steam_community_announcements)

Purchased and traded Counter-Strike items made invisible for ten days to other users viewing a Steam inventory.

Record scope: Dated official release-note archive, entry for 2 April 2024.

### E33 · Steam Web API Terms of Use

Publisher: Valve
Date: Page marked last updated July 2010
Reviewed: 10 October 2026

[Original record](https://steamcommunity.com/dev/apiterms)

The established API-key signup framework, applications and websites, confidentiality obligations and Valve’s access controls.

Record scope: The terms describe the account-key service and the API access relationship.

### E34 · Steam Web API Documentation

Publisher: Valve / Steam Community
Date: Public developer documentation
Reviewed: 10 October 2026

[Original record](https://steamcommunity.com/dev?l=en)

Website-developer use of Steam data, user-key registration and the Steam OpenID identity mechanism.

Record scope: The public web-service documentation linked to Steam Community account-key registration.

### E36 · Link Filter — literal-address comparison

Publisher: PhishDestroy / public Steam responses
Date: 10 Oct 2026 · 19:09–19:10 UTC
Reviewed: 10 October 2026

[Original record](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/linkfilter-pattern-2026-10-10.json)

Returned headings and continue anchors for five literal csgofast-related address probes.

Record scope: Exact request strings and responses are preserved, including separate percent-encoded request results.

### E38 · People of New York v. Valve Corporation — filed complaint

Publisher: New York Attorney General / NYSCEF
Date: 25 Feb 2026
Reviewed: 10 October 2026

[Original record](https://ag.ny.gov/sites/default/files/court-filings/new-york-v-valve-corporation-complaint-2026.pdf)

Court, filing date, index 450952/2026, allegations, statutory bases and requested remedies.

Record scope: NYSCEF document 2; 52-page court-stamped complaint. Requested relief appears on PDF pages 50–51.

### E41 · Steam Online Conduct — commercial activity

Publisher: Valve
Date: Live rules
Reviewed: 10 October 2026

[Original record](https://store.steampowered.com/online_conduct/)

Gambling is explicitly included under the commercial-activity prohibition.

Record scope: Read beside the account-enforcement record and Valve’s public transferability language.

### E43 · Web API Overview — public and publisher hosts

Publisher: Valve / Steamworks
Date: Live documentation
Reviewed: 10 October 2026

[Original record](https://partner.steamgames.com/doc/webapi_overview)

HTTP method structure, public and authenticated operations, publisher host requirements and access configuration.

Record scope: The host and request layer underlying the credential comparison.

### E44 · IEconService — trade history and offer records

Publisher: Valve / Steamworks
Date: Live documentation
Reviewed: 10 October 2026

[Original record](https://partner.steamgames.com/doc/webapi/IEconService)

GetTradeHistory, GetTradeOffers and GetTradeOffer as concrete examples of account-economy methods.

Record scope: Method reference used to explain what a trading API exposes.

### E45 · ISteamUserAuth — publisher ticket authentication

Publisher: Valve / Steamworks
Date: Live documentation
Reviewed: 10 October 2026

[Original record](https://partner.steamgames.com/doc/webapi/ISteamUserAuth)

AuthenticateUserTicket on the publisher host, its publisher key, application ID and ticket parameters.

Record scope: A concrete example of the publisher-server access relationship.

### E46 · Introducing Big Picture — the built-in web browser

Publisher: Valve
Date: Original product presentation
Reviewed: 10 October 2026

[Original record](https://store.steampowered.com/bigpicture/)

Valve’s presentation of web browsing within the original Big Picture interface.

Record scope: Historical product presentation, used to identify the browser surface discussed in the submitted notes.

### E47 · Exploiting Steam: Usual and Unusual Ways in the CEF Framework

Publisher: DARKNAVY
Date: 27 Jun 2024
Reviewed: 10 October 2026

[Original record](https://www.darknavy.org/blog/exploiting_steam_usual_and_unusual_ways_in_the_cef_framework/)

Firsthand technical description of steamwebhelper and its Chromium Embedded Framework architecture.

Record scope: Documents Steam’s embedded Chromium architecture and its exploitation history, dated June 2024. The shipped configuration, patch cadence and present protection of steamwebhelper are part of the record requested from Valve.

### E48 · How FloatDB Tracks Skins — the original-ID endpoint and its closure

Publisher: CSFloat engineering
Date: 3 Jul 2020
Reviewed: 10 October 2026

[Original record](https://blog.csfloat.com/how-floatdb-tracks-items/)

The former original-ID field, closure of its endpoint in 2017 and the replacement matching approach using float, seed and paint properties.

Record scope: Firsthand technical history of item tracking and its limitations.

