The Steam Mobile app can sign you in to Steam by scanning a QR code, with no password and no Steam Guard code. That convenience is the whole scam: if the code you scan was produced by someone else's sign-in attempt, approving it signs their device into your account. One rule prevents it. Only scan a code on a Steam sign-in screen you opened yourself.
How Steam's QR sign-in works
QR sign-in arrived with Valve's rebuilt Steam Mobile app, which went into beta in August 2022. Valve's support page describes it as a way to skip typing your account name and password, relying instead on the two-factor credentials already stored in the app on your phone.
The steps are short. You open the Steam Guard tab in the app, choose to scan a QR code and point the phone at the sign-in panel on your PC or in a browser. The app then shows a confirmation page with details of the attempt, including a map and the approximate location of the device you're signing in to. Approve it and that device is signed in.
The detail that matters is which device that is. A sign-in QR code stands for a pending sign-in on whatever screen is showing it. Scanning it with the Steam app doesn't take you anywhere; it vouches for that screen.
How the scam turns it around
A scammer starts a genuine Steam sign-in on a machine they control, takes the QR code Steam gives them and puts it on a page or stream you'll see. Because the code really comes from Steam, your app behaves exactly as it normally does. If you approve, you've told Steam that the scammer's machine is yours, and they're in without ever learning your password.
Discord documents the same trick on its own platform. Its security guidance warns that scanning a scammer's code with Discord's scanner lets the attacker log straight in, "bypassing your password and any 2FA you may have configured." Steam's QR sign-in works on the same principle, so the same warning applies.
Where the codes turn up
| Date | Lure | What the QR code did | Reported by |
|---|---|---|---|
| November 2024 | A stranger asked for a vote for a university esports team | Sat inside a fake login pop-up as an image that refreshed itself and appeared to point at Steam's real servers | utf9k, a developer's blog |
| February 2025 | Hijacked YouTube channels posing as s1mple, NiKo and donk during IEM Katowice and PGL Cluj-Napoca | Shown on looping fake livestreams, leading to "free skin" sites that asked for a Steam login | Bitdefender |
| June 2026 | Fake FACEIT "verification" pages | Deliberately blurry, likely to push visitors towards a fake "Sign in through Steam" window | Malwarebytes |
You don't need to analyse a code to spot these. Where it appears is enough: a vote page, a stream overlay or a "verification" form is never a Steam sign-in screen, so a code shown there belongs to someone else.

The location check helps, but not always
Valve's confirmation screen is your last chance to catch the trick. If the map or location doesn't match where you are, deny the request.
A matching location isn't proof, though. A researcher who took apart a Steam phishing kit in July 2025 found it started each relayed sign-in from a residential internet connection close to the victim, because a distant location makes the Steam app suspicious and adds extra steps. In that kit the victim typed a password and approved a sign-in prompt rather than scanning a code, but the approval screen was the same kind of check. The page then asked the victim to "approve the confirmation" once more, and that second prompt was a password reset that let the attackers lock the owner out.
So the real question isn't where the request seems to come from. It's whether you just pressed "sign in" on your own screen. If you didn't, deny it.
The rule, and the habits around it
- Scan only codes you summoned. That means the sign-in window of the Steam client, or a Steam sign-in page you reached by typing the address. Valve lists the official sign-in domains as
www.steampowered.com,store.steampowered.com,steamcommunity.comandhelp.steampowered.com. - Never scan from a stream, video, chat message or giveaway. A code someone else shows you is their sign-in, not yours.
- Deny prompts you didn't start. That covers push notifications and confirmation requests as well as QR approvals, and anything that looks like a password or account change most of all.
- Treat a broken or blurry code as a warning. In the June 2026 campaign it was a nudge towards a fake login window. Our guide to spotting Steam phishing sites explains how those windows are drawn.
Valve's wider rules still apply. Never share your Steam Guard codes, never type them into a site Valve doesn't run, and remember that Steam Support will never ask for them.

If you already approved one
Act from a device you trust. Open Authorized Devices in your Steam account settings and use Sign out everywhere, then change your Steam password and check the security of your email account. Revoke any Steam Web API key you didn't create; attackers use one to watch your trades, as our API key scam guide explains.
Then check what has already happened. If CS2 items left your account in trades during the last seven days, you can reverse those trades from your Trade History under trade protection, at the cost of a 30-day trading and Market cooldown. If you've been locked out, start recovery at help.steampowered.com: Valve says you can always recover an account through Steam Support, even if someone changed its email, password and phone number. Our account security checklist covers the settings worth fixing afterwards.
Sources
- Steam Guard Mobile Authenticator — Steam Support
- Account Security Recommendations — Steam Support
- Valve is testing a new Steam mobile app — PC Gamer
- A fascinating attempt at Steam phishing — utf9k
- Streamjacking Scams On YouTube Leverage CS2 Pro Player Championships to Defraud Gamers — Bitdefender
- Fake verification pages are stealing Steam accounts from players — Malwarebytes
- Breaking the Steam Scam — patyk.lol
- Securing Your Discord Account — Discord



