A fake SDA download emptied my Steam inventory
A member of our team recounts losing their Steam inventory after installing a counterfeit SDA download. Their experience motivated this project. The story below records their recollection; it is not an independently verified incident report.
First-hand basis. A member of the MASTERPANEL LLC team wrote this from their own experience. The person is deliberately unnamed, but the publisher is accountable for the page. It is a personal account, not a forensic analysis of the counterfeit binary. We have not published the binary, transaction records or evidence identifying the recipient accounts. Timing is the person's recollection. The suspected copying of a maFile and control of the receiving accounts are conclusions, not independently established facts.
I had already done it right once#
I was starting out in trading and I needed Steam Guard on my PC. I got Steam Desktop Authenticator the correct way: from the project's own releases page. The fake sites I remember seeing then were below the genuine result in my searches.
That is the part I want to be clear about, because it is the part that gets missed. I knew where the real one lived. I had already downloaded it from there.
Then I reinstalled Windows#
Months later I rebuilt the machine, and set about reinstalling everything I used. I searched for SDA the way anyone does. This time one of those sites was sitting at the top of the results.
I did not examine it. I was reinstalling twenty things that afternoon and this was the one I had used for months already. It looked like the thing I remembered. I downloaded it, set it up, imported my accounts, and it worked — codes, trades, confirmations, all of it, exactly as before.
Working codes did not establish that the download was safe. I believe this was when my maFile was copied. The evidence accompanying this account does not establish exactly what the program sent or when.
Two weeks of nothing#
Then about a fortnight later I was in a lecture at university and my phone started going. Not one notification — a stream of them, emails arriving faster than I could read the subject lines.
What they actually did#
I remember about half my inventory being unavailable to trade. I thought that made me relatively safe. This account does not identify the exact item restrictions, so they cannot be generalised to today's Steam rules. What I saw next was Market activity:
- They listed and sold the entire inventory on the Community Market. As I remember it, the items were sold and the proceeds landed in my Steam Wallet.
- The balance bought overpriced listings. My account bought items I understood to be worth only a few cents. I believe the sellers were connected to the attacker; I do not have independent proof of who controlled them.
- I did not recover the value. By the time I read the first emails, the transactions I describe here had already happened.
I remember low-value stickers among the final purchases. The account was left with items worth very little compared with what had been there.
Today's rules are not inferred from this story. Valve documents both trade and Market holds, and completed Market purchases are final. Eligible CS2 trades have a separate seven-day Trade Protection reversal route. Do not assume that a trade restriction always permits selling, or that every kind of stolen-item transaction is irreversible.
What I would tell myself#
- Reinstalls deserve the same checks as first installs. Familiarity with a product can make it easy to skip checking a new download.
- A restriction is not a substitute for securing the account. Check what the specific restriction covers and respond to exposed credentials immediately.
- Bookmark the real release page. Not the search. The search is the attack surface.
- Check the file, not the website. A convincing page proves nothing. Check the checksum and provenance where available to establish release origin. They do not establish that the program is safe.
Why this exists#
SDA's own repository warns about fake downloads. My experience is a reason to take that warning seriously. It is not evidence that today's search results or the timing of other thefts match mine.
So this application is built to be checked rather than trusted: public source, builds produced in public CI, and a security page that says what it cannot protect you from. Published checksums and build provenance ship with each release. Reproducible builds do not yet. The direct Windows downloads are signed and timestamped as MASTERPANEL LLC using Microsoft Azure Artifact Signing. Linux packages use the checksum-list signature and provenance checks; the download page says where each one stands. ODA has no built-in updater; updates to the Store edition are managed by Microsoft Store.
If you use something else, use something else. Just verify what you downloaded — and if a page like this ever becomes your story, follow the recovery steps here from a trusted device and check promptly for pending or reversible transactions.