Connect with us

NEWS

FBI Charges Florida Man in $220,000 Steam Malware Crypto Theft

The FBI says a Florida student’s Steam malware scheme stole $220,000 in crypto, the same campaign linked to a cancer patient’s stolen donations months earlier.

Published

on

Federal agents arrested a 21-year-old Florida student this week, accusing him of hiding malware inside Steam games that drained at least $220,000 from about 80 crypto wallets. Zyaire Wilkins now faces a federal conspiracy charge over a scheme prosecutors say ran through eight separate games over nearly two years.

One of those games, BlockBlasters, was already notorious. Months before Wilkins’ arrest, security researchers had linked it to a case where a cancer patient watched $32,000 in Twitch donations disappear.

Five Games, One Alleged Playbook

In a criminal complaint unsealed this week, federal agents accused Wilkins, identified in court papers by his full name, Zyaire Dontaevious Zamarion Wilkins, and his co-conspirators of running the scheme between May 2024 and February 2026. They wrote that the group “gained unauthorized access to approximately 80 cryptocurrency wallets and stole cryptocurrencies worth at least $220,000” by publishing malware-laden games on Steam.

Reporting on the case names five of the titles: BlockBlasters, Dashverse, Lampy, Lunara and PirateFi. The complaint reportedly covers eight games in total. The identities of the other three haven’t surfaced publicly.

Each game was built to actually work. Players could download, install and play them like any other Steam title. Malware ran quietly underneath the whole time, lifting saved passwords and other data before reaching into any crypto wallet connected to the machine.

Wilkins and his associates marketed the titles on Discord, LinkedIn and Telegram, according to authorities.

The bureau’s approach to crypto crime has grown increasingly forensic. In one earlier operation, agents built a fake crypto token to catch market manipulators in the act, rather than waiting on a tip.

Roughly 8,000 devices were infected in total, according to the complaint, though only a fraction of those victims apparently held crypto wallets worth draining.

Gift Cards and an Uber Eats Account Led Agents to Wilkins

The case reportedly broke open when the FBI identified another participant in the scheme and brought them in for an interview. That person said they helped raise money to launch and market the malicious games in exchange for a cut of the stolen cryptocurrency, according to the complaint.

From there, investigators traced blockchain transactions to an account with Bitrefill, a service that converts cryptocurrency into retail gift cards. Some of those gift cards, prosecutors say, were spent at Uber Eats. Agents subpoenaed Uber and found the cards tied to an account making deliveries to Wilkins’ home address.

Online, prosecutors say, Wilkins went by the handle Sibel.eth. Agents obtained a search warrant for his residence in North Lauderdale, Florida, and seized his MacBook, cellphones and other devices along with his digital wallets. He declined to answer questions, according to the complaint.

A Cancer Patient’s Donations Were Drained First

BlockBlasters had a life before it showed up in a federal complaint. The German cybersecurity firm G Data traced the malware to an August 30 patch, months after the game had already been live on Steam.

Among those hit was a Latvian Twitch streamer being treated for stage four cancer. He had downloaded a verified copy of BlockBlasters from Steam and watched $32,000 in donations vanish from his wallet, BleepingComputer reported at the time.

Researchers estimated the damage went far beyond one streamer. The malware research group vx-underground put total losses from BlockBlasters above $150,000 across roughly 478 accounts.

The malware itself worked in stages, according to a breakdown of how it evaded antivirus tools:

  • Checked the infected computer for running antivirus software before doing anything else
  • Unpacked a second payload only if it found nothing but Windows Defender active
  • Harvested stored passwords, session cookies and other saved browser data
  • Used those stolen credentials to reach into and drain any connected crypto wallet

Prosecutors haven’t confirmed whether the cancer patient is among Wilkins’ alleged 80 victims. But the game name, the platform and the timeline all line up.

The Pattern Runs Back to Early 2025

The Wilkins complaint fits a pattern. Steam had been fielding malware-laced games for at least a year and a half before his arrest, and the FBI’s own public record shows it.

  1. May 2024: Prosecutors say Wilkins and his co-conspirators begin the scheme that would eventually span eight games.
  2. February 2025: Valve pulls PirateFi from Steam after researchers catch it stealing browser passwords.
  3. March 2025: The FBI publicly announces an investigation into malware-laced Steam games and asks victims to come forward, an appeal that reportedly named titles later cited in the Wilkins complaint.
  4. August 2025: BlockBlasters receives the patch that starts delivering credential-stealing malware to players.
  5. September 2025: Researchers publicly tie BlockBlasters to crypto wallet drains, including the cancer patient’s loss.
  6. February 2026: The alleged scheme’s activity, as described in the complaint, comes to an end.
  7. July 14, 2026: FBI agents arrest Wilkins at his Florida home.

More than a year passed between the FBI’s public appeal for victims and Wilkins’ arrest.

One Review at Upload, No Check on Updates

Valve’s process for vetting Steam games has a structural blind spot. The company reviews a game when it’s first uploaded but applies far less scrutiny to updates pushed afterward, according to an explanation of how the review process works.

That gap is exactly how BlockBlasters turned malicious months after launch. It shows up across every incident tied to this case.

Game or Case What Happened When Reported Losses
PirateFi Removed by Valve after researchers found it stealing browser passwords February 2025 Not publicly quantified
BlockBlasters Malicious patch added after launch; malware checked for antivirus software before deploying Patched August 2025; flagged publicly in September 2025 More than $150,000 across about 478 accounts
Wilkins complaint (eight titles total) Named in a federal conspiracy charge covering BlockBlasters, Dashverse, Lampy, Lunara, PirateFi and others Alleged May 2024 to February 2026 $220,000 across about 80 wallets

In both the PirateFi and BlockBlasters cases, Valve pulled the title only after players had already lost money.

What Happens to Wilkins Now?

Wilkins faces a single federal count of conspiracy to obtain information by computer for private financial gain, a charge that carries up to 10 years in prison if he’s convicted. Prosecutors haven’t named or charged any of his alleged co-conspirators, and his defense attorney did not respond to a request for comment on the case.

The bureau has built tech-fraud cases on unconventional evidence trails before. Earlier this year it warned that dating app matches were turning into armed robberies.

The eight games named in the complaint are gone from Steam now. Valve has not said whether its review process will change before the next one goes up.

Frequently Asked Questions

What should I do if I downloaded one of the malware-linked games?

Security researchers who studied BlockBlasters recommend running a full antivirus scan right away, changing any passwords stored in a browser on that machine, and moving funds out of any crypto wallet that was open or connected while the game was running. Revoke wallet approvals granted around the time of installation, since stolen credentials can be used long after the fact.

Did the hackers target specific crypto holders or random players?

Reporting on the BlockBlasters campaign found the operation went beyond random downloads. Researchers said the group identified people on social media who managed large cryptocurrency holdings and aimed the malicious game directly at them.

Were other people charged besides Zyaire Wilkins?

No additional defendants have been publicly named or charged as of this reporting. The complaint references unnamed co-conspirators and describes at least one other participant who was interviewed by investigators.

Is it still safe to download games from Steam?

The overwhelming majority of the platform’s library carries no risk. The PirateFi and BlockBlasters cases show that Valve’s review at upload doesn’t guarantee a game stays clean through later updates, so keeping crypto wallets and sensitive accounts off a gaming PC remains the safer practice.

Logan Pierce is a writer and web publisher with over seven years of experience covering consumer technology. He has published work on independent tech blogs and freelance bylines covering Android devices, privacy focused software, and budget gadgets. Logan founded Oton Technology to publish clear, no nonsense tech news and reviews based on real hands on testing. He has personally tested and reviewed dozens of mid range and budget Android phones, written extensively about app privacy, and built and managed multiple WordPress publications over the past decade. Logan holds a bachelor's degree in English and studied digital marketing at a certificate level.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending