win.gg
Win.gg Counter-Strike Hackers stealing CSGO skins through iOS vulnerability, Steam API

Hackers stealing CSGO skins through iOS vulnerability, Steam API

M Alzamora
M Alzamora Published 29/11/2020

Most serious skin collectors and players have thier Steam account protected by two-factor authentication, but it turns out that having the securty feature on Steam isn’t enough. The hijacking of two high-profile accounts in the past year show that a user’s inventory isn’t always as secure as they think it to be.

On November 28, professional CSGO player Paytyn “Junior” Johnson woke up to find that almost his entire inventory had been cleaned out. He’d been the victim of one of two possible attacks that allowed hackers to access not only his Steam account, but also bypass Steam Guard, the platform’s two-factor authenticatior located on a user’s phone. But thanks to a simple backup option, Junior may have lost out on a hefty number of skins.

Hackers access pro’s Steam account, steal skins

Hackers are rumored to be able to gain access to Steam accounts using the backup images of iPhones, allowing them to empty an account’s inventories through a pretty serious flaw. The entire purpose 2FA is to have a second chance to regain control of a compromised account, so users are partly to blame as well. Here’s how it works.

I wake up getting spammed notifications my steams been hacked, I was able to logon and deauthorize the account and changed every password I have, in a span of 5 minutes of me changing everything somehow all of my skins (around 20k) got sent through to another account without 1/2

— Paytyn (@1juniorcs) November 27, 2020

Many players use Apple’s iCloud storage to store photos and contacts, but they can also decide to back up both apps and their settings to the cloud as well. If a player chooses to backup the Steam App, they’re also saving both their log-in credentials, incuding the username and password, as well as Steam Guard itself.

If the player includes applications in their backups, then it’s a fairly trivial process for a hacker that has access to the iCloud account to download this backup. Once there, several utilities exist where users can generate two-factor codes on the desktop instead of from mobile, a move that completely defeats the purpose of 2FA. What happens then is fairly simple, as the hacker uses those three pieces of information to empty the account, either to third-party websites or to a middleman account. Junior eventually recovered his account, but said he hasn’t received any of his lost skins as of yet.

Why do you need Steam Guard and other two-factor authentication?

As of 2016, Valve announced that with 2FA in place and the proliferation of third-party sites, they would no longer regenerate skins for players who had them stolen. Valve’s concern was that not only could a user pretend to be robbed, eventually getting the “stolen” skins back from a second account or the money from its sale, but that third-party skin sites were making a killing while the developer watched money move outside the Steam ecosystem. Since Valve takes a 15% cut of every CSGO item sold on the Steam Marketplace, so Valve obviously prefers to keep everything in-house.

How do Steam accounts get stolen?

There are three main ways. The first would be if a user’s email address and password were stolen. With those pieces of information, a hacker could reset the email connected to the account. Steam recommends that players never “use the same password for both their email and their Steam Account.”

The second way is through the process mentioned above, where the hacker has access to both the Steam Guard backup and the user’s email and password. The third way is through malware. Keyloggers and viruses are some of the main ways hackers can access the data needed to clean out an account.

Will Valve return stolen skins to thier owners like Stewie2k?

There’s still hope for Junior’s skins. Team Liquid’s Jake “Stewie2k” Yip had his own account hacked in a similar way during the 2019 StarLadder Berlin Major. Luckily, Valve restored access to the pro’s account and returned to him his skins, so it’s possible that Junior will be just as lucky. Even CSGO observer DJ “Prius” Kuntz revealed that he was a victim of a similar attempt during a stint at IEM Katowice.

Much love & appreciation for the quick recovery @CSGO . Stole thousands of dollars of skins without trade ban & i have no idea how. Hats off for the hacker, dedicated your life for these things…got what you want. Seems like @CSGO got it all under control though ❤️

— Jake (@Stewie) September 5, 2019

There are an entire host of scams used on Steam to trick people out of thier items, so it’s best to follow the simple rules of the internet to keep things safe.

Finally, enabling Steam Family Sharing is an odd way to work around the issue, but it requires players to enter another four digit pin in order to do anything through the Steam Service. Prius reccomendeds it as a way to further lock down an account, but it need to be enabled correctly to function. Users can find out more about Family Sharing and how it can protect them through Steam’s FAQ.

M Alzamora M Alzamora
About M Alzamora

There are few things that writer M Alzamora loves more in life than Pokemon. And there are even fewer things that she loves more than her favorite Pokemon, Eevee. But M’s appreciation for gaming isn’t just limited to Nintendo’s famous pocket monsters. She’s interested in every type of game across every genre of gaming, and she has the credentials to prove it. M’s work has also been seen on Working Classicists and gaming sites.

View full profile
Read Also
Will Valve add Cache in the CS2 Premier Season 5 Active Duty map pool? Esports Betting
Will Valve add Cache in the CS2 Premier Season 5 Active Duty map pool? Wasif Ahmed Following the highly anticipated return of Cache to Counter-Strike 2 earlier this season, the competitive community has almost started believing that the legendary industrial map would soon make its way into the Active Duty map pool for Premier Season 5. This expectation followed a pattern set by Train, which Valve brought back late last year before quickly pushing it into the main professional tournament rotation. However, in a recent Twitter ...
IEM Cologne Grand Final: Team Falcons vs FURIA best betting predictions Counter-Strike
IEM Cologne Grand Final: Team Falcons vs FURIA best betting predictions Owen Harsono Coming into the IEM Cologne Major, nobody would have expected a grand final series between Team Falcons and FURIA, but here we are. Will NiKo finally win his first Major, or will FalleN win another one before retiring at the end of the year? Here are our IEM Cologne Major Grand Final predictions. Tournament: IEM Cologne Major 2026 Stage: Grand Final Game: Counter-Strike 2 Format: Best-of-five Betting tip: Team Falcons ...
Team Spirit vs Team Falcons IEM Cologne Major: betting predictions and picks Counter-Strike
Team Spirit vs Team Falcons IEM Cologne Major: betting predictions and picks Owen Harsono We’re in for a treat, as Team Spirit will take on Team Falcons for a spot in the IEM Cologne Major grand final. Will NiKo finally get another shot at winning a Major, or will donk and company prevent him from accomplishing his lifelong goal? Here are our IEM Cologne Major Team Spirit vs Team Falcons predictions. Tournament: IEM Cologne Major 2026 Stage: Semi-Final Game: Counter-Strike 2 Format: Best-of-three Betting ...
Vitality vs Falcons betting predictions and best picks: IEM Cologne Major 2026 Counter-Strike
Vitality vs Falcons betting predictions and best picks: IEM Cologne Major 2026 Owen Harsono We’re treated to a possible grand final matchup here in the quarterfinal of the IEM Cologne Major, with Team Vitality taking on Team Falcons in an elimination match. These are two of the highest-profile teams in the game right now, but only one of them can continue their chase for the trophy. Here are our IEM Cologne Major Team Vitality vs Team Falcons predictions. Tournament: IEM Cologne Major 2026 Stage: ...
IEM Cologne Major 2026 playoffs preview: matchups & predictions Counter-Strike
IEM Cologne Major 2026 playoffs preview: matchups & predictions Owen Harsono The top eight teams at the IEM Cologne 2026 Major are set. Most of the favorites easily secured their spots, but we also have promising underdogs sneaking into the bracket. To keep you up to speed, here’s everything you need to know about the IEM Cologne Major playoffs. We started with 32 teams and are now only down to eight. After a grueling Stage 3, teams have been seeded into ...
IEM Cologne Major 2026 CS2 Playoffs Pick’Em Predictions Counter-Strike
IEM Cologne Major 2026 CS2 Playoffs Pick’Em Predictions Owen Harsono It’s that time of the year again, as the next Counter-Strike 2 Major is right around the corner. The IEM Cologne 2026 Major is set to start on June 2, meaning you still have some time to lock in your Pick’Em predictions. The Pick’Em Challenge is one of the most exciting parts of the CS2 Majors, as it allows you to test your knowledge and predict which teams make it ...
IEM Cologne Major Stage 3 preview: who’s making it to the playoffs? Counter-Strike
IEM Cologne Major Stage 3 preview: who’s making it to the playoffs? Owen Harsono The IEM Cologne Major is the biggest tournament of the year, and after two stages of play, it’s finally time to unleash the big boys. Stage 3 will feature the 16 best teams in the world, but only eight can advance to the Playoffs and play on the big stage. Here’s our IEM Cologne Major Stage 3 preview. Before we got to Stage 3, a lot of things happened in ...