What does a secure Steam account look like?
A secure Steam account has five things in place, and each one blocks a different way of getting robbed.
| Layer | What it blocks | Where Valve documents it |
|---|---|---|
| Steam Guard Mobile Authenticator, older than 7 days | Logins from new devices and any trade or market action without your phone | Mobile Authenticator FAQ |
| Phone number on the account | Losing the account when you lose the phone | Same FAQ |
| A locked-down email account with its own two-factor login | Password resets by someone who got into your email | Steam Guard FAQ |
| No unknown authorized devices, no Steam Web API key you did not create | Someone who already got in from staying in | Account Security Recommendations |
| Habits: real domains only, read every confirmation | Fake login pages and swapped trade offers | Same page and the trade redirection page |
Valve's security page opens with the reason all of this matters: "Your account cannot be stolen if you follow these recommendations and refrain from sharing your account." That is close to true. Almost every hijack we hear about involves a password typed into the wrong page, a code shared, or a program installed from a link. The layers above are there so that one mistake does not cost you everything.
The rest of this guide walks through setting up each layer, then gives the order of operations if you are already hijacked.
How do you set up the Steam Guard Mobile Authenticator?
The mobile authenticator is a feature of the Steam Mobile app. Valve's FAQ describes it as a code that "changes every 30 seconds, can be used only once, and is unguessable", and adds that it also lets you approve logins with a tap and confirm trades and market listings from your phone.
Setup:
- Install the Steam Mobile app on your phone from the official app store.
- Add a phone number to your Steam account first. In Steam, open Account Details, then Contact Info, then add a phone number and confirm the SMS code. Valve's FAQ says this makes recovery "quite a bit easier" and lets you move the authenticator to a new phone later.
- Open the app, go to the Steam Guard section, and follow the setup. Valve has a step-by-step walkthrough linked from the authenticator FAQ.
- Save the recovery code. The app shows you a code starting with R. Write it down somewhere that is not your phone. If you lose the phone, this code is how you keep the account.
- Wait 7 days before trading. Valve's restrictions FAQ says trades made in the first 7 days after adding the authenticator can still get a hold of up to 15 days. Our trade hold calculator tells you the exact date you are clear.
Two warnings from Valve's FAQ worth repeating. Never share your authenticator codes with anyone, and never type them into a site not run by Valve. And "Steam Support will never ask for any of your codes."
Also, do not remove the authenticator to fix a problem. Removing it blocks trading and the market for 15 days.
Why does the authenticator matter so much for trading?
Because Valve built the whole trading system around it.
Without the authenticator, items leaving your account on most games are held for up to 15 days so you can catch a thief. With it, you confirm each trade on your phone and items move at once. Valve's holds FAQ says the point is that "you and only you can quickly and securely trade or sell your items." The details of the hold system are in Steam trade hold explained.
For CS2 specifically, the Trade Protected Items FAQ says items are not subject to trade holds at all, because trade protection covers them. But that does not make the authenticator optional. Most marketplaces will not trade with an account that lacks it, and the phone confirmation is the one place you can see a redirected trade before it completes.
The authenticator is also your best defence against the most common theft method. A scammer with your password still cannot log in from their device or confirm a trade without your phone. The only way around it is to trick you into typing a code into a fake page, which is why the habits section below matters as much as the setup.
How do you lock down the email behind your Steam account?
Your Steam account is only as safe as the email account attached to it. Valve's Steam Guard FAQ says it plainly: "This second layer of security depends on your email account also being secure." If someone controls your email, they can reset your Steam password without knowing the old one.
Do these for the email account:
- Use a long, unique password that you do not use anywhere else.
- Turn on two-factor login at the email provider.
- Check the email account's own recovery options. A forgotten backup email or an old phone number is a way in.
- Look at the email account's active sessions and sign out any you do not know.
If you ever get a Steam email you did not expect, such as a password reset or a "new device" notice, treat it as a sign that someone is trying. Do not click links in it. Open Steam yourself and check.
Which settings should you check right now?
Fifteen minutes, once, then a quick look every month or so.
- Authorized devices. Go to your Steam account's authorized devices page. Valve's security page says: "If anything seems odd, use the Sign out everywhere option." If you are not sure, just do it. You will log back in on your own devices.
- Steam Web API key. Visit steamcommunity.com/dev/apikey. If a key exists and you did not create it for a reason you understand, revoke it. A key you did not create means someone had login access. See Steam API key scams.
- Email and phone on the account. Confirm both are still yours.
- Steam Guard status. Under Account Details, Steam Guard should show the mobile authenticator, not email codes.
- Trade URL. If you think it has been shared widely, generate a new one. Anyone with the old URL can still only send you offers, not take anything, but it cuts down spam offers.
- Trade History. Look through it. Anything you do not recognise from the last 7 days can be reversed.
- Family View and inventory privacy. Optional. A private inventory reduces targeting but breaks marketplaces. Set it to public only while you are actively selling if you like.
What habits keep a Steam account safe?
Setup gets you most of the way. Habits get you the rest. Valve's security page lists the big ones in capitals, and they are worth keeping in that spirit.
- Never give out your password. Not to a friend, not to a "Steam admin", not to a group you want to join. Valve says no reputable gaming group and no server admin needs it.
- Never click unknown links, and check links from friends. Their account may be hijacked. The scam link checker is built for this.
- Never follow instructions to talk to "Steam Support" on Discord or any chat. Valve says its staff do not use chat systems, even if the message comes from a friend's account or claims to fix a false report.
- Only log in on Steam's domains. steampowered.com, store.steampowered.com, steamcommunity.com, help.steampowered.com. Anything else is fake. Full detail in fake Steam login pages.
- Do not install software from links. Valve's security page warns that Steam-targeting malware hides in cheats, pirated games, fake betas and "inventory managers", and can wait until your wallet or inventory is worth taking.
- Read every trade confirmation. Check the receiving account's age and level, not just its name. This is the one habit that beats trade redirection.
- Do not lend items and do not use middlemen. Valve's trading practices page says a borrowed item usually does not come back and a middleman can just keep both sides.
- Log out on shared computers. Valve's list includes this one. If you forget, deauthorize the device from your account.
None of these are hard. They are just the difference between an account that gets robbed and one that does not.
What do you do if your Steam account was hijacked?
Order matters more than speed. Do these in sequence.
- Get control back. Change your Steam password from a clean device. If you cannot log in, or the email or phone on the account changed, use Steam's account recovery through the Support site. Valve's Scam FAQ says you can always recover your account this way, even if the scammer changed all the details, and you should never pay a ransom.
- Sign out everywhere from the authorized devices page.
- Secure the email account. New password, two-factor on, sessions cleared.
- Revoke any Steam Web API key.
- Scan the computer for malware. If the hijack came from something you installed, steps 1 through 4 are undone the next time it runs.
- Check Trade History. For CS2 items traded away in the last 7 days, you can reverse all Trade Protected trades yourself from that page. Every trade in the window is reversed together and your account gets a 30-day trade and market cooldown. Read trade protection and reversals explained before you press it, but for a stolen inventory, press it.
- Report the accounts involved using "Report Player" on their profiles. Valve says a profile report is faster and more useful than a ticket.
Then accept the hard part. For items outside the 7-day window or from other games, Valve's Item Restoration Policy says Support does not restore items that left an account, because they have usually been traded on and restoring them would mean duplicating them or taking them from an innocent buyer. Anyone offering to recover items for a fee is a second scam.
How does trade protection fit into account security?
Trade protection, live for CS2 since 16 July 2025, is a safety net under all of the above. It gives you a 7-day window to undo trades made from your account, whether by you under pressure or by a thief. The cost is that reversing undoes every trade in the window and blocks trading for 30 days.
Think of it this way. The authenticator, the email lock and the habits are the locks on the door. Trade protection is the insurance. You want the locks so you never need the insurance, and you want to know the insurance exists so you act fast if the locks fail.
The window only helps if you notice within a week. So the last habit is the simplest one: look at your inventory and Trade History now and then, especially after anything odd like an unexpected login email. Seven days is plenty if you are paying attention and nothing if you are not.
