Steam resolves password-reset exploit that compromised some accounts July 21-25
Some Steam Accounts Hijacked Following Security Lapse — Over the past week, a number of Steam accounts—including those of some prominent streamers and DOTA 2 pros—were temporarily stolen courtesy of a pretty glaring hole in Valve's security.
Context & Ripple Effects
This closure ends a bad week for Valve: between July 21 and 25, attackers used a hole in Steam's password-reset flow to take over accounts, including those of prominent streamers and DOTA 2 pros whose public profiles made them high-value targets. It lands in a year where account theft is already a running theme on the platform — Steam had just tightened trading security amid what Ars Technica reported as 77,000 monthly hijackings, and Twitch had forced a full password reset after its own compromise months earlier.
First-order effects
- Affected users — including the named streamers and DOTA 2 pros — regain control of their accounts once Valve closes the reset path, though any items or trades moved during the July 21–25 window may not be recoverable through the fix alone.
- Valve now has to explain why a core recovery flow, not an exotic attack surface, was the entry point for hijacks of its most visible users.
Second-order effects
- High-profile victims amplify the problem: streamers and pro players broadcasting the theft pressures Valve to accelerate fixes like the trading-security changes it rolled out amid the monthly hijacking volume, since stolen inventory is directly monetizable.
- Rival platforms and adjacent services like Twitch face the same attacker playbook, keeping pressure on the whole streaming-and-inventory ecosystem to harden reset and credential flows rather than treat breaches as isolated events.
Third-order effects
- If the 2015 pattern holds — this exploit, the trading crackdown, the December caching incident, and Valve's apology for the Christmas outage that affected 34,000 users — Steam's account-security posture becomes a recurring trust liability that shapes how seriously users guard high-value inventories, pushing platforms toward per-flow security controls as standard practice.
The trend: Steam is spending 2015 lurching from one account-security failure to the next, turning platform-side credential handling into a competitive trust issue for game marketplaces.