Steam wallet flaw could turn $1 into hundreds

steam
(Image credit: Future)

Games on Steam can be pretty expensive, but that’s not a problem if you can turn a single dollar into an unlimited amount of funds. Steam recently awarded a $7,500 bug bounty to a security researcher who discovered an interesting — and potentially very lucrative — bug in Steam Wallet. By taking advantage of an online payment company’s API, an enterprising cybercriminal could trick Steam into adding a theoretically unlimited amount of money into a user’s account.

That information comes from a highly technical report in HackerOne, via The Daily Swig. Security researcher “drbrix” outlined all of his findings, and disclosed precisely how to take advantage of the bug. (For anyone who was hoping to replicate the trick, don’t bother; Steam patched it out of existence weeks ago, according to comments in the HackerOne thread.)

 Briefly, here’s how the flaw worked: First, a user would open his or her Steam Wallet, and add a payment method. One possible method is a Dutch online payment company called Smart2Pay. By modifying the Smart2Pay API directly, drbrix discovered that he could edit the payment amount after making any form of legitimate deposit. In other words: He could pay $1 to Smart2Pay, then convince Steam that he had added $100 to his account.

Apparently, $100 is as high as the modification request would go, but that means you could essentially buy 10 brand-new, full-price games for $6. It’s not hard to see how this flaw could have created a lot of mischief, had anyone ever taken advantage of it in the wild.

The good news is that it doesn’t seem like anyone took advantage of this exploit, save drbrix while he was testing it. The better news is that users don’t have to do anything special to fix it; the vulnerability was on Valve’s end. It’s not clear whether Smart2Pay has also patched its API, but it’s also not clear whether such a patch would be necessary.

For his efforts, drbrix earned a $7,500 bug bounty from Steam, which a Valve representative cited as “a real business risk” in the HackerOne comments.

While there’s nothing that everyday users need to worry about here, this story does serve as a best-case scenario for how companies can address flaws in live software. A researcher found a flaw, reported it through the correct channels, and received a generous bounty for his efforts. Valve acknowledged the issue and patched it immediately. There are much more nightmarish ways this could have gone.

As for your own Steam Wallet, the usual precautions apply here. Both Steam and PayPal offer two-factor authentication, and you should employ both. While you won’t be able to turn $1 into $100, you can take advantage of frequent Steam sales to get major titles for relatively little money.

Marshall Honorof

Marshall Honorof is a senior editor for Tom's Guide, overseeing the site's coverage of gaming hardware and software. He comes from a science writing background, having studied paleomammalogy, biological anthropology, and the history of science and technology. After hours, you can find him practicing taekwondo or doing deep dives on classic sci-fi. 

Read more
A magnifying glass on top of the Steam logo in a web browser
Valve recommends a full PC reset after malware-infected game discovered on Steam
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
Steam Deck OLED
Massive Steam sale offering PC games from under $1 — here's 18 must-buy titles I'd go for
A honey logo and MKBHD side-by-side
Honey extension accused of scamming millions and content creators — should you delete it now?
Indiana Jones and the Great Circle screenshot
The best Steam games in 2025
A hacker typing quickly on a keyboard
Hackers are posing as Apple and Google to infect Macs with malware — don’t fall for these fake browser updates
Latest in PC Gaming
Half-Life 2 RTX
I just went back to Ravenholm in Half-Life 2 RTX — Nvidia’s new RTX remix tech makes it 10x more terrifying
Nvidia ACE
I played with Nvidia's AI NPC prototypes — now they're real, and I fear I'll never finish a game again
Half-Life 2 RTX demo from Orbital Studios
Nvidia launches RTX Remix with new tools to help modders upscale old games with DLSS 4
AMD Radeon RX 9070 XT
Where to buy AMD Radeon RX 9070 and RX 9070 XT — I recommend these retailers in US and UK
Alienware Aurora R16
11 insider tips to make your games fun faster (without a new GPU)
nvidia rtx 50 series
Where to buy RTX 5070 Ti — live updates and stock checker
Latest in News
ChatGPT on iPhone
ChatGPT was down — updates on quick outage
Emma D'Arcy in House of the Dragon season 2
‘House of the Dragon’ season 3 has officially begun filming — what it could mean for the potential release window
AirPods Max in various colors
AirPods Max is getting a big update with lossless audio and ultra-low latency — here's how it works
A mosquito resting on a plant
Experts predict a spring surge in these 9 pest populations — here's what's forecast for your area
Apple Watch SE (2022) shown on wrist
Apple Watch SE 3 reportedly in ’serious jeopardy’ — here’s why
Galaxy S25 Plus held in the hand.
Samsung could delay One UI 7’s release in the US — here’s what we know