Security
Account and trade security
Most losses in item trading come from impersonation, not from broken software. This page lists what we will never ask you for, how to confirm you are on our site, and what to check before you accept any trade offer.
Steam credentials should only be entered on official Steam services. No exchange service, including this one, ever needs them.
What we never ask for
Your Steam password
The exchange process does not require it. Nobody from BEXU163 will ask for it in any email or on any page.
Steam Guard or recovery codes
We never ask for a Steam Guard code, a mobile confirmation or a recovery code. These exist to protect your account from exactly this kind of request.
Session cookies or API keys
We do not ask you to paste a session cookie, an API key or an authentication token, and we never ask you to install anything.
Remote access to your device
Support is by email only. We will not ask to control your computer, screen-share or run commands on your behalf.
Check the domain before you type anything
The only domain used by this service is bexu163.com, always over HTTPS. Look at the address bar before entering anything into a form: a lookalike domain with an extra word, a different ending or a swapped character is the most common way trading fraud starts.
Email from us is sent only from [email protected]. If you receive a message that appears to come from us on another address, treat it as unrelated to this service and report it to that address.
Check the trade offer itself
- Open the offer inside Steam. Go to your own trade offers in the Steam client or on the Steam website instead of following a link from an email or a chat message.
- Read both sides of the offer. Confirm every item that would leave your inventory and every item that would arrive, including wear, pattern and any stickers.
- Compare with the written terms. The offer must match what we described in email. If it differs in any way, decline it.
- Do not confirm unknown operations. If you receive an offer you did not expect, or a confirmation request you did not start, decline it and write to us.
- Take your time. Nobody at BEXU163 will pressure you to confirm quickly. Urgency is a warning sign, not a service level.
How we protect the data you send
- The site is served over HTTPS, with HTTP Strict Transport Security enabled.
- Forms are protected by a signed anti-forgery token, server-side validation, length limits and rate limiting.
- Submitted requests are written to a directory that is not reachable over the web, and access to it is denied at the server level.
- The site loads no third-party scripts, fonts or trackers, so the data you enter is never exposed to another provider.
- The only cookie used is a strictly necessary session cookie, set when a form is submitted and never for tracking.
We describe these measures rather than claiming that any system is perfectly secure. If you believe you have found a security problem on this site, please report it to [email protected] and we will look into it.
If something has already gone wrong
If you think your Steam account has been compromised, act in Steam first: change your password, revoke other sessions and contact Steam Support. Then write to us with your reference number so we can close any open request associated with your details.