Posted July 19, 2020
![avatar](http://images.gog.com/f9f94ef0b16e99a6735350bc30373dcceb48f40d088439b8d5fc74f2c4a6dcaf_avm.jpg)
it takes 2-3 times to enter your login with 2FA code and your steam account will be transferred to another owner. I bet you have seen multiple forum threads on steam about stolen account after using fake logins on 3d party sites. this is the same method any attacker can use in galaxy 2.0 plugins. thanks to its bad stability and constant disconnects one can easily overlook when galaxy asks you to login into your steam account and then shows login prompt again (like, it didn't worked last time), user enters it again with new 2FA code. what happens next? once data gathered and passed outside, bot already used your 2FA code to steal your account, plugin will crash galaxy to clear files. "Oh, this thing crashed, it is still beta". will you notice anything strange in that?
Post edited July 19, 2020 by djoxyk