Trade redirection is a Steam trade scam in which a legitimate trade offer made from a compromised account is canceled and replaced with an offer that sends the items to an account controlled by the scammer. The scammer's account often copies the legitimate recipient's name and profile picture. The scam succeeds if the user accepts the replacement offer in Steam Mobile without verifying the recipient's actual account details.
The attack cannot be carried out using only a Steam Web API key. According to Valve’s current documentation, a standard user key allows trade offers and trade history to be viewed, but it cannot be used to create, accept, decline, or cancel offers. Valve’s guidance on trade redirection states that redirecting an offer requires the scammer to have gained full access to the Steam account.
The most important safeguard is the final check on your phone. If the offer you just created is canceled, or you are not completely sure that the recipient shown in the confirmation is the correct account, do not accept anything. Stop the trade and secure your Steam account before trying again.
How does trade redirection work?
The attack begins before any visible trade takes place. First, the scammer must gain enough access to the account or device to use Steam on the victim’s behalf. After that, the chain of events usually unfolds as follows:
The security of the Steam account or device is compromised. The user may sign in on a fake Steam website, approve an unfamiliar QR code login, or install malicious software or a browser extension. The attacker gains login credentials, an active session, or access to an already authorized device.
The victim initiates the legitimate trade. The offer may be intended for a skin-trading bot, a buyer, a friend, or the user's other account. At this point, Steam's trade page may make everything appear to be in order.
The scammer cancels the original offer. Using access to the compromised account, the attacker acts before the final confirmation. According to the current official documentation, an API key alone is not sufficient for this action.
A fake trade offer is created in its place. The scammer's recipient account may be anonymous, or its name and profile picture may have been copied to resemble the intended recipient. The offer includes the same skins being sent by the victim, so at a quick glance, it may look as expected.
The victim accepts the wrong offer on their phone. Steam Guard is not technically bypassed. Instead, the user is tricked into personally giving final approval to the scammer's offer.
A fully completed trade cannot be changed afterward. The redirection takes place between creating the legitimate offer and giving final confirmation. If the original offer is completed with the intended recipient, the scammer cannot simply change its recipient afterward.
The original trade offer can be declined and a replacement created almost immediately. Valve does not describe the technical methods used by scammers, but the speed suggests that detecting and replacing offers can be automated. An API key may be used to read trade data, but declining an offer and creating a new one require broader access to the Steam account.
How Does a Scammer Gain Access to a Steam Account?
Trade redirection is not caused by an API key leak, but usually by compromised login credentials or device access. Valve identifies phishing and malware as common methods used to hijack accounts.
A fake Steam login page can look almost identical to the real one. The link may come from a fake tournament invitation, voting request, free skin offer, or trade request sent on Discord. The site asks for your Steam credentials or displays a QR code. Approving the QR code in Steam Mobile confirms a login—it is not a routine website verification.
Malware may be disguised as a skin tool, inventory management app, browser extension, cheat software, or another gaming-related download. Valve warns that modern malware may wait for the right moment before taking action and use an already authorized device without requiring a new Steam Guard login.
A compromised email account also increases the risk. If you use the same password for Steam and your email, an attacker may try to recover the account or hide security notifications sent by Steam.
What role does the API key play in the scam?
The API key is associated with trade redirection because, in older scam scenarios, the attacker created a key on the victim's account and used it to monitor trade offers. However, it is only one possible indicator of a compromised account, not a universal key capable of redirecting trades on its own.
Valve’s current IEconService API allows a standard user key to retrieve, for example, sent and received offers, individual offer details, and trade history. The current documentation does not list any user-key methods for sending, accepting, declining, or canceling offers.
That’s why an unfamiliar API key is still a red flag, but removing it alone is not enough to secure the account. If an attacker has an active Steam session, an authorized device, or malware on the computer, they may have access that extends beyond the key.
You can recognize the redirect by these signs
A scam is often revealed by a small change just before confirmation:
the original offer you made unexpectedly appears as canceled
you receive a new offer to confirm, even though you didn't create another one
The trade history shows two identical offers, with the original marked as declined.
the recipient of the new offer is anonymous or uses the same profile picture as the intended recipient
the recipient's name and profile picture look correct, but their Steam level, account age, length of friendship, or other profile information does not match
The recipient's account is new or has little activity
in the offer, you send valuable items without receiving anything in return in the Steam trade
someone pressures you to accept quickly, transfer your skins for “verification,” or claims your account is at risk
Your Steam profile name, description, or other content has been changed without your permission
According to Valve, Steam Support will not alter your profile content to threaten you with a ban. An unexpected warning on your profile indicates that your account has been compromised, not that Steam Support has taken legitimate action.
If your trade history shows two identical offers and one of them has been declined, do not accept the remaining offer. Open the details of both offers and compare the recipient accounts. The same profile picture or a similar name does not prove that they are the same user. If you see a pair of offers like this, treat your Steam account as compromised and secure it before continuing to trade.
Verify the recipient in Steam Mobile
A name and profile picture are not reliable ways to identify a Steam account. Both can be copied in seconds. Open the confirmation in full and compare the recipient details shown there with the account you actually intended to send the items to.
Steam displays information in the trade offer, such as how long you have been friends, the Steam level, and the account age. If you are trading with a bot, compare the recipient with the bot shown by the service for that same transaction. Do not rely on an old Discord message, profile picture, or search result.
If any of the details do not match, reject the confirmation. Do not try to fix the situation by immediately creating a third offer, as the attacker may still have access to the account.
What should you do if you suspect an attack?
If the original offer was canceled or you see a confirmation request you did not initiate, do not accept it. Use a trusted device and, if possible, a different, clean device:
Reject any confirmation you don't recognize. Without final confirmation, the items will not be transferred as part of the trade offer.
Sign out of Steam on all devices. Check the list of devices authorized by Steam Guard and use the option to sign out everywhere.
Change your Steam password. Only do this in the official Steam app or at help.steampowered.com.
Secure your email. Change your email password and review its two-factor authentication, login history, and any forwarding rules.
Check your API key. While logged in, go to steamcommunity.com/dev/apikey and revoke any key you don't recognize or need.
Check your computer and browser. Remove any suspicious programs and browser extensions, and run a malware scan. Do not log back in until you are sure the device is secure.
Check your trade offers and profile changes. Review open and recent trade offers directly on Steam.
Changing your password will not provide lasting protection if malware or a malicious browser extension remains on your device. That is why securing your account, email, and device are all part of the same recovery process.
If the CS2 skins have already been transferred to the scammer
Steam Trade Protection currently protects received CS2 items for seven days. If an account is compromised and CS2 items are transferred without authorization, Steam allows the user to reverse all Trade Protected trades from the past seven days via the Trade History page.
Initiating a Trade Reverse returns items from protected trades to their previous owners. At the same time, all protected trades from that period are reversed, open trade offers are canceled, and Market listings are removed. The account that initiated the reversal will receive a 30-day restriction from trading and using the Community Market.
This is not intended for reversing a single bad trade you regret. Only use the rollback option in cases of account hijacking or fraud, and read the consequences shown by Steam before confirming. If the items are not covered by Trade Protection or the rollback option is not available, use the official Steam Support channel.
A secure way to verify a high-value trade
Treat the offer open in your browser and the confirmation on your phone as two separate checkpoints. In the browser, verify the items and the recipient. On your phone, double-check that you are confirming the same offer and that it has not been replaced by another one.
If a service asks for your API key, Steam password, Steam Guard code, or approval of a QR code login just to trade skins, stop the process.
Trade redirection loses its power when you refuse to confirm the wrong offer. Slow down at the exact moment the other party urges you to hurry: verify the recipient’s account details, the contents of the offer, and whether the original offer is still valid.
CS2 SkinsAugust 13, 2026
CS2 Gamma Doppler: Phases 1–4 and Emerald
Learn how to tell apart CS2 Gamma Doppler Phases 1–4 and Emerald, and how to verify the correct knife variant from the inspect details.