Fake Steam link steals your account in one click and infects friends
While Valve is busy counting their counter-strike skin money, a massive security hole is burning down their storefront. Yes, clicking a simple link is now enough to lose years of gaming achievements. Absolutely stellar work.
A security researcher named Victor, known for previously exposing major security flaws in Discord, discovered a critical vulnerability in the PC gaming giant's platform. This digital nightmare has been rated a terrifying nine out of ten on the industry-standard CVSS vulnerability scale.
The loophole functions like a digital flu. Attackers send a malicious link disguised as a standard game or store page. Once clicked, the user is seamlessly redirected to the official home page, making it look like a harmless glitch. In reality, the victim's login tokens are already in the hands of the hackers.
It gets worse because the malware behaves like an old-school internet worm. Once an account is hijacked, the exploit automatically starts sending the same toxic link to everyone on the victim's friends list, turning trusted gaming buddies into unwitting vectors of infection.
The company behind the store, Valve, has yet to issue a security patch to fix the loophole.
The digital gaming ecosystem remains hostage to a single careless click while a multi-billion-dollar corporation takes its sweet time to deploy a basic hotfix. It turns out that hoarding thousands of virtual hats won't protect an account when the front door of the store doesn't even have a working lock.
Source: Victor on X
Comments
This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.