https://www.gamesindustry.biz/articles/2018-11-13-valve-rewards-man-usd20-000-for-discovering-unlimited-free-game-codes-bug
https://hackerone.com/reports/391217

Using the /partnercdkeys/assignkeys/ endpoint on partner.steamgames.com with specific parameters, an authenticated user could download previously-generated CD keys for a game which they would not normally have access. Audit logs were not bypassed using this method, and an investigation of those audit logs did not show any prior or ongoing exploitation of this bug.

5 years ago

Comment has been collapsed.

Good on that guy. He did something that Valve couldn't do and got paid for it.

5 years ago
Permalink

Comment has been collapsed.

Sign in through Steam to add a comment.