Open Desktop Authenticator

A fake SDA download emptied my Steam inventory

This happened to one of us, about five years ago. It is the reason this project exists, and the reason the rest of this site is written the way it is. Nothing here is hypothetical.

I had already done it right once

I was starting out in trading and I needed Steam Guard on my PC. I got Steam Desktop Authenticator the correct way: from the project's own releases page. The fake sites existed even then, but they were buried — you had to go looking to find one.

That is the part I want to be clear about, because it is the part that gets missed. I knew where the real one lived. I had already downloaded it from there.

Then I reinstalled Windows

Months later I rebuilt the machine, and set about reinstalling everything I used. I searched for SDA the way anyone does. This time one of those sites was sitting at the top of the results.

I did not examine it. I was reinstalling twenty things that afternoon and this was the one I had used for months already. It looked like the thing I remembered. I downloaded it, set it up, imported my accounts, and it worked — codes, trades, confirmations, all of it, exactly as before.

It working is the whole trick. A build that failed would have been deleted within a minute. This one did its job perfectly and copied my maFile out at the same time.

Two weeks of nothing

Then about a fortnight later I was in a lecture at university and my phone started going. Not one notification — a stream of them, emails arriving faster than I could read the subject lines.

What they actually did

Half my inventory was under a trade hold, so they could not simply trade it away. I had genuinely believed that made me relatively safe. It does not, and here is the route they used instead:

  1. They listed and sold the entire inventory on the Community Market. Trade holds do not stop a market sale. Everything went, and the proceeds landed in my Steam Wallet.
  2. They spent the balance on their own listings. They had already put up items worth a few cents each, priced enormously. My wallet bought them. The money left for an account they controlled and I was holding the worthless items.
  3. None of it could be undone. Wallet funds cannot be withdrawn to a bank and market purchases are not refundable. By the time I had read the first email it was already finished.

Around three thousand dollars, converted into items genuinely worth cents. They did not even leave the balance — they emptied it to the last penny, and bought a few stickers worth about five dollars with what was left. I have never been able to read that as anything other than deliberate.

What I would tell myself

Why this exists

Because it is still happening, in the same way, to people being no more careless than I was. The name still outranks the source, the fake builds still work perfectly on the day you install them, and the two-week delay still means almost nobody connects the theft back to the download.

So this application is built to be checked rather than trusted: public source, reproducible builds, published checksums, and a security page that says what it cannot protect you from. It cannot update itself, because that is the same door left open.

If you use something else, use something else. Just verify what you downloaded — and if a page like this ever becomes your story, the recovery steps are here and the first one matters more than all the rest.

Last reviewed .