FBI Arrests Florida Man for Using Malware-Laden Steam Games to Drain Crypto Wallets

The FBI arrested a 21-year-old Florida man for using malware-laden Steam games to steal over $220,000 from cryptocurrency wallets.

By Central
The FBI unsealed a criminal complaint charging Zyaire Wilkins with conspiracy and computer intrusion.
Highlights
  • The FBI arrested a 21-year-old Florida man for using malware-laden Steam games to steal over $220,000 from crypto wallets.
  • The malicious games, including BlockBlasters and PirateFi, were promoted on Discord, LinkedIn, and Telegram.
  • The FBI traced cryptocurrency payments from the scheme to the purchase of Uber Eats gift cards linked to the suspect.

The FBI has arrested a 21-year-old Florida man accused of uploading malware-laden video games to Steam, the popular PC gaming platform, in a scheme that infected approximately 8,000 victims and drained at least $220,000 from cryptocurrency wallets. The case highlights a growing threat where seemingly legitimate software on trusted platforms is weaponized to target digital assets.

Federal prosecutors unsealed a criminal complaint Wednesday charging Zyaire Wilkins, a Florida resident and student, with conspiracy and computer intrusion crimes. According to the complaint, Wilkins and unnamed co-conspirators published several malicious games on Steam over the past two years, including titles such as BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi. The games appeared legitimate enough to install and play but contained hidden malware designed to steal passwords and drain cryptocurrency wallets.

How the Malware Campaign Worked

The attackers distributed their malicious games through multiple channels, promoting them on Discord, LinkedIn, and Telegram to attract victims. Once a user downloaded and installed a game, the embedded malware infected the computer and began harvesting credentials and other sensitive data. The FBI alleges that the group specifically targeted cryptocurrency wallets, ultimately compromising around 80 wallets and stealing more than $220,000 in digital currency.

Valve, the company behind Steam, has removed several games from the platform in the past year after discovering they contained malware, including PirateFi. The FBI had previously announced in March that it was investigating a hacker using malware-embedded Steam games and called for affected users to come forward and provide evidence.

Investigation Traced Payments to the Suspect

Federal agents identified another person involved in the scheme and interviewed them. That individual told investigators they worked with others to raise money for launching and marketing the malicious games in exchange for a share of the stolen cryptocurrency. The FBI traced cryptocurrency payments from a specific account used in the scheme to the purchase of gift cards, including for Uber Eats. Subpoenaing Uber allowed investigators to link those gift cards to an account making deliveries to Wilkins, who used the online alias Sibel.eth.

Agents executed a search warrant at Wilkins’ residence, seizing a MacBook laptop, cellphones, other devices, and digital wallets. According to the complaint, Wilkins refused to speak or answer questions.

What Affected Users Should Do Now

If you downloaded any of the named games or suspect you may have been affected by this campaign, take immediate action to secure your accounts. Change all passwords associated with your Steam account, email, and any cryptocurrency wallets, and ensure you use strong, unique passwords for each service. Enable two-factor authentication on every account that supports it, particularly crypto exchanges and wallet services. Monitor your cryptocurrency wallets and financial accounts for unauthorized transactions, and consider moving any remaining funds to a wallet generated on a clean, uncompromised device. If you downloaded any of the malicious games, run a full scan with a reputable, multi-layer endpoint protection solution that includes behavioral analysis and real-time threat detection. The FBI has also requested that affected individuals come forward through its victim notification form to aid the ongoing investigation. For future protection, only download games from official sources, scrutinize the developers and publishers behind lesser-known titles, and maintain robust antivirus software with active monitoring capabilities.

Share This Article