An easy-to-exploit hole was found in Valve’s Steam platform that abused the Smart2Pay system to add unlimited funds to gamers’ digital wallets. Security researcher DrBrix reported the bug last Monday and Valve paid him $7,500 for identifying the bug. The hack allowed an attacker to intercept the POST request sent from the API sent from Valve to Smart2pay. This was done via modifying the Steam users email address used by the payment firm. The attacker can turn $1 into $100 simply by changing the format of the request.”]
Source: https://threatpost.com/valve-bug-unlimited-funds/168710/

