For every legitimate game giveaway on the internet, there are a dozen fakes designed to steal your account, your data, or your money. As a site that runs giveaways ourselves, we have seen every trick in the book. Here is exactly how to tell the real ones from the scams.
The 6 red flags of a fake giveaway
1. It asks for your Steam password
This is the big one. Legitimate sites use Steam’s official OpenID sign-in β a redirect to steamcommunity.com where you log in on Valve’s own page. If a website shows its own username/password form for “Steam login,” it is a phishing site. Close it immediately. Always check the address bar: the login page must be on steamcommunity.com, exactly.
2. You “won” a giveaway you never entered
Random Discord DMs, Steam comments, or emails announcing a prize you never signed up for are always scams β usually leading to a fake login page or a “small delivery fee.”
3. Payment is required to receive a free prize
“Verification fees,” “delivery charges,” “deposit to prove you’re human” β a genuine free giveaway never involves your credit card, ever.
4. Key generators and “cracked key” tools
Working Steam key generators do not exist and have never existed. Keys are validated server-side by Valve. Every downloadable “generator” is malware, most commonly an info-stealer that grabs your saved browser passwords.
5. Impossible prizes at impossible volume
“Everyone wins a AAA game!” A $60 key costs the giveaway organizer real money. Legitimate giveaways have limited winners per round and are transparent about the odds.
6. Survey walls that never end
Sites that make you complete offer after offer “to unlock your key” are monetizing your time and data β the key at the end of the tunnel does not exist.
What legitimate giveaways look like
- Official Steam OpenID login (on steamcommunity.com), never a password form on the site itself.
- Clear rules: entries per round, how winners are drawn, when keys are delivered.
- Visible, verifiable winners and a public draw process.
- No payment information requested at any point.
- A real privacy policy and a way to contact the operators.
If you already got scammed
- Change your Steam password immediately from a clean device, and enable the Steam Mobile Authenticator.
- Check your account’s authorized devices and API key (steamcommunity.com/dev/apikey β it should be empty unless you created one) and revoke anything you do not recognize.
- If you downloaded anything, run a full antivirus scan and change passwords saved in your browser.
- Report the site or user to Steam Support and to the platform where you found it.
Stay skeptical, check the address bar, and remember the golden rule: if a giveaway needs your password or your money, it is not a giveaway.
Anatomy of a real scam: how the con actually unfolds
Knowing the shape of the con makes it instantly recognizable. The most common variant in 2026 works like this: you get a Discord DM or Steam comment saying you won a giveaway (that you never entered). The link leads to a page that looks exactly like a Steam login β same layout, same fonts β but the address is something like steamcommunlty with a subtle misspelling. You “sign in”, nothing seems to happen, and you shrug it off. Within hours, your account is listing your inventory items for sale and messaging your friends with the same scam link, because the fake login page captured your credentials and session.
The defense is mechanical, not psychological: real Steam sign-in only ever happens on steamcommunity.com or store.steampowered.com. Check the address bar character by character before typing anything. If you have Steam Guard Mobile enabled, a legitimate login never asks you to type a code from the app into a website β you confirm inside the app itself.
What to do if you already got scammed
- Change your Steam password immediately from a device you trust β this invalidates the stolen session.
- Deauthorize all other devices in Steam Guard settings, then check that your email and phone number on file have not been changed.
- Revoke any API keys at steamcommunity.com/dev/apikey β hijackers register API keys to intercept trades even after a password change. If a key exists that you did not create, revoke it.
- Cancel pending trades and market listings, and warn friends the account may have messaged.
- Contact Steam Support β item recovery is not guaranteed, but account recovery is nearly always possible, and reporting the phishing domain helps get it blacklisted.
Most importantly: getting phished is embarrassing, so most victims stay quiet β which is exactly what keeps the scam profitable. Tell your friends what the message looked like. Every person who knows the pattern is a dead end for the scammer.
The thirty-second verification habit
Before entering any giveaway, run this quick check: does the site have a real about page, contact page, and privacy policy? Does the winner selection process get explained anywhere? Can you find past winners or an active community around it? A legitimate operation answers all three in under a minute of looking β scam sites, built to be disposable, almost never bother. It is a small habit, but it filters out the overwhelming majority of traps before you have typed anything at all.