When you trade with a site, the account on the other side of the offer is usually a "bot": an ordinary Steam account whose actions are carried out by software instead of a person at a keyboard. Knowing how those accounts work explains why bot offers look the way they do, and why pretending to be a bot is one of the oldest ways to steal skins.
A bot is just a Steam account
There's no special account type for bots. A bot has a profile, a SteamID, an inventory and a trade offer page like anyone else's, and the items it holds sit in that inventory under the same rules as yours. Item-for-item swaps with a site work this way too; CS2Sell's Trade page, for example, swaps your items for items from its bot inventory.
What makes it a bot is the software driving it. Valve publishes a Web API for Steam trading. Its IEconService interface includes methods that use an account's key to list sent and received trade offers, fetch a single offer, summarise pending offers and read the account's trade history. Valve's support pages describe the API as a tool users and websites can use to automate requests for data from Steam, or to make changes to the account the key belongs to.
Developers build on top of that with libraries. One open-source example, a trade offer manager for Node.js, checks Steam for changes to offers on a timer and reports changes such as an offer being accepted, declined, countered or cancelled.
Confirmations: the authenticator, run in software
Every trade offer that sends items out of an account has to be confirmed. Valve says there's no longer any way to opt out. With the Steam Guard Mobile Authenticator you confirm in the Steam Mobile app; without it, Steam emails a confirmation request.
Bots face the same rule, so their software does what the app does. The authenticator works from two stored secrets, and an open-source library documents both: a "shared secret" that generates the rotating Steam Guard sign-in codes, and an "identity secret" that produces the keys used to load, accept or cancel confirmations. In other words, a bot doesn't skip confirmation. It taps "confirm" in code.
You can see this in an offer's life cycle. The same library's list of offer states, which mirrors Steam's, includes one for an offer that has been created but is still waiting for its sender's confirmation. Only after that confirmation does the offer reach you as active. Unanswered offers expire after two weeks, according to Valve.

Holds, then protection
For years, the authenticator also decided how fast items moved. Valve's rule is still that trades created before the Mobile Authenticator is added, or in its first seven days, are held for 15 days. Bots that confirm through an authenticator avoid that.
CS2 is now an exception anyway. Since Valve introduced trade protection on July 15, 2025, its FAQ says Counter-Strike 2 items aren't subject to trade holds or escrow at all and move between accounts immediately. Instead, every CS2 item received in a trade is protected for seven days: it can be used in game but can't be traded on, modified, consumed or moved into a Storage Unit.
That applies in both directions. Items you send to a bot can't be traded on by the bot for a week, and items a bot sends you can't leave your inventory for a week. During that window the trade can be reversed from the Trade History page, which undoes every protected trade from the past seven days and puts a 30-day trading and Market cooldown on the account that reverses. Our guides to trade protection and what a reversal does cover the details.
How impostors copy bots
Because a bot is just an account, anyone can make one that looks like it. Valve's scam FAQ describes the simplest version: a user impersonating a trade bot tells you that you have to trade them some items, then blocks you and keeps them.
The more damaging version needs access to your account first. In what Valve calls trade redirection, a scammer who has compromised your account waits for you to start a real trade, cancels it, and sends a near-identical one to an account they control that copies the real partner's name and avatar. A Steam Web API key on your account makes it easy for them to watch your offers, as our API key scam guide explains.
Bot trades are an easy target for this because selling to a bot is one-sided by design: you send items and get paid on the site. Valve's simplest protection, never confirming an unbalanced trade, can't help there, so the account details on the confirmation screen have to do the work.

Telling a genuine bot offer from a copy
- Start every trade from the site yourself. A genuine bot offer arrives because you asked for it. An account that messages you first and says you need to send items is the impersonation Valve describes.
- Check the timing and contents. The offer should arrive right after you requested it and contain exactly the items the site showed you, on both sides.
- Read the account details. Valve says a trade offer shows the other account's Steam level and age, and that the Steam Mobile confirmation screen shows everything you need to spot a redirected trade. A copy created today looks like a new account, whatever its name says.
- Watch for swaps. If an offer you just received is cancelled and a near-identical one appears from a different account, stop. That's the redirection pattern, and it means someone else has access to your account.
- Keep your trade URL tidy. Valve lets anyone with your unique trade URL send you offers. If it has spread too far, our trade URL guide shows how to reset it.
If anything about a confirmation doesn't match, decline it, then check steamcommunity.com/dev/apikey for a key you didn't create and secure your account before trading again.
Sources
- Steam Trade Offers — Steam Support
- Trade Protected Items — Steam Support
- Scam: Trade Redirection — Steam Support
- Scam FAQ (Confidence Scams and Trade Scams) — Steam Support
- Steam Guard Mobile Authenticator — Steam Support
- IEconService Interface — Steamworks Documentation
- node-steam-totp — GitHub
- node-steam-tradeoffer-manager — GitHub



