Skip to main content
  1. Home
  2. Computing
  3. Gaming
  4. News

Fixed Steam bug allowed users’ accounts to be hijacked simply by knowing the username

Add as a preferred source on Google

If you’re lucky, you might have noticed that some people had their Steam accounts temporarily hijacked over the weekend. If you’re not so lucky, your Steam account was among those hijacked.

Fortunately, the exploit has already been resolved, but by the time Valve fixed the bug at the heart of the problem, the damage had already been done. What makes this particular security issue different isn’t the severity of the problem, but the ease with which pretty much anyone could take over a Steam account once they knew of the exploit.

Recommended Videos

A YouTube user by the account name Elm Hoe illustrated the method in a video. It started by requesting a password reset on the targeted account. On the next screen the user is prompted to enter an authentication code in order to proceed with the reset. The exploit worked by simply not entering a code and skipping ahead.

At this point, the attacker was free to change the account password to one of their choosing, locking the actual owner of the account out in the process. Luckily, this exploit didn’t last for long: Valve learned of the exploit on July 25, and it seems that accounts had only been hijacked using this method starting July 21.

Once Valve learned of the bug it was quickly fixed, and any accounts that were suspect had their passwords reset. “Please note that while an account password was potentially modified during this period the password itself was not revealed,” the company said in a statement to Kotaku.

Valve was also quick to point out that any user accounts with Steam Guard enabled were protected from another person actually logging into their account, even if the account’s password was modified. It’s worth noting that this is yet another reason why you should have two-factor authentication enabled everywhere it is possible to do so.

For a look at how exactly the exploit was accomplished when it was still in the wild, see the video below.

Steam | How accounts are getting hacked. (FIXED)
Kris Wouk
Former Contributor
Kris Wouk is a tech writer, gadget reviewer, blogger, and whatever it's called when someone makes videos for the web. In his…
Apple’s biggest MacBook Pro redesign in years may skip the chip everyone expected
The next MacBook Pro may bring OLED and touch support without M6 Pro silicon
MacBook Pro on Table

Apple is expected to launch a refreshed MacBook Pro later this year, but according to Bloomberg, it won't come equipped with a next-gen processor. Instead, Apple is going to equip the highly anticipated device with Pro and Max variants of the current-gen M5 silicon.

It was widely speculated that when the redesigned MacBook with an OLED display and touch-screen capability debuts, it will also mark the arrival of the M6 series processors. Well, it appears that Apple has changed its silicon strategy pretty significantly.

Read more
You may have to wait until 2027 for Macs with Apple’s best chips
Lighting, Purple, Computer Hardware

If you’ve been holding off on buying a new MacBook Pro because the next generation of Apple Silicon is just around the corner, you might want to reset your expectations.

A new report by Bloomberg’s Mark Gurman suggests Apple is making its biggest change yet to the Mac chip roadmap. Instead of releasing a full family of M6 processors like it has with every generation since the original M1, the company is reportedly planning to launch only the standard M6 chip first. The more powerful Pro and Max variants? They may not arrive until 2027, and they’ll reportedly skip the M6 branding altogether.

Read more
I found these two Prime Day flagship laptop deals for display snobs and practical buyers
Samsung has the sharper discount and OLED screen, while Microsoft is the simpler Windows clamshell buy under $1,000.
Samsung Galaxy Book5 Pro 360 front view showing tend mode.

A flagship laptop deal has to survive the full spec check: chip, RAM, storage, display, seller, and final price. These two listings pass that test in different ways, which is why they’re the first pair I’d compare before chasing louder Prime Day discounts.

Samsung Galaxy Book5 Pro 360

Read more