NEWS
FBI Charges Florida Man in $220,000 Steam Malware Crypto Theft
The FBI says a Florida student’s Steam malware scheme stole $220,000 in crypto, the same campaign linked to a cancer patient’s stolen donations months earlier.
Federal agents arrested a 21-year-old Florida student this week, accusing him of hiding malware inside Steam games that drained at least $220,000 from about 80 crypto wallets. Zyaire Wilkins now faces a federal conspiracy charge over a scheme prosecutors say ran through eight separate games over nearly two years.
One of those games, BlockBlasters, was already notorious. Months before Wilkins’ arrest, security researchers had linked it to a case where a cancer patient watched $32,000 in Twitch donations disappear.
Five Games, One Alleged Playbook
In a criminal complaint unsealed this week, federal agents accused Wilkins, identified in court papers by his full name, Zyaire Dontaevious Zamarion Wilkins, and his co-conspirators of running the scheme between May 2024 and February 2026. They wrote that the group “gained unauthorized access to approximately 80 cryptocurrency wallets and stole cryptocurrencies worth at least $220,000” by publishing malware-laden games on Steam.
Reporting on the case names five of the titles: BlockBlasters, Dashverse, Lampy, Lunara and PirateFi. The complaint reportedly covers eight games in total. The identities of the other three haven’t surfaced publicly.
Each game was built to actually work. Players could download, install and play them like any other Steam title. Malware ran quietly underneath the whole time, lifting saved passwords and other data before reaching into any crypto wallet connected to the machine.
Wilkins and his associates marketed the titles on Discord, LinkedIn and Telegram, according to authorities.
The bureau’s approach to crypto crime has grown increasingly forensic. In one earlier operation, agents built a fake crypto token to catch market manipulators in the act, rather than waiting on a tip.
Roughly 8,000 devices were infected in total, according to the complaint, though only a fraction of those victims apparently held crypto wallets worth draining.

Gift Cards and an Uber Eats Account Led Agents to Wilkins
The case reportedly broke open when the FBI identified another participant in the scheme and brought them in for an interview. That person said they helped raise money to launch and market the malicious games in exchange for a cut of the stolen cryptocurrency, according to the complaint.
From there, investigators traced blockchain transactions to an account with Bitrefill, a service that converts cryptocurrency into retail gift cards. Some of those gift cards, prosecutors say, were spent at Uber Eats. Agents subpoenaed Uber and found the cards tied to an account making deliveries to Wilkins’ home address.
Online, prosecutors say, Wilkins went by the handle Sibel.eth. Agents obtained a search warrant for his residence in North Lauderdale, Florida, and seized his MacBook, cellphones and other devices along with his digital wallets. He declined to answer questions, according to the complaint.
A Cancer Patient’s Donations Were Drained First
BlockBlasters had a life before it showed up in a federal complaint. The German cybersecurity firm G Data traced the malware to an August 30 patch, months after the game had already been live on Steam.
Among those hit was a Latvian Twitch streamer being treated for stage four cancer. He had downloaded a verified copy of BlockBlasters from Steam and watched $32,000 in donations vanish from his wallet, BleepingComputer reported at the time.
Researchers estimated the damage went far beyond one streamer. The malware research group vx-underground put total losses from BlockBlasters above $150,000 across roughly 478 accounts.
The malware itself worked in stages, according to a breakdown of how it evaded antivirus tools:
- Checked the infected computer for running antivirus software before doing anything else
- Unpacked a second payload only if it found nothing but Windows Defender active
- Harvested stored passwords, session cookies and other saved browser data
- Used those stolen credentials to reach into and drain any connected crypto wallet
Prosecutors haven’t confirmed whether the cancer patient is among Wilkins’ alleged 80 victims. But the game name, the platform and the timeline all line up.
The Pattern Runs Back to Early 2025
The Wilkins complaint fits a pattern. Steam had been fielding malware-laced games for at least a year and a half before his arrest, and the FBI’s own public record shows it.
- May 2024: Prosecutors say Wilkins and his co-conspirators begin the scheme that would eventually span eight games.
- February 2025: Valve pulls PirateFi from Steam after researchers catch it stealing browser passwords.
- March 2025: The FBI publicly announces an investigation into malware-laced Steam games and asks victims to come forward, an appeal that reportedly named titles later cited in the Wilkins complaint.
- August 2025: BlockBlasters receives the patch that starts delivering credential-stealing malware to players.
- September 2025: Researchers publicly tie BlockBlasters to crypto wallet drains, including the cancer patient’s loss.
- February 2026: The alleged scheme’s activity, as described in the complaint, comes to an end.
- July 14, 2026: FBI agents arrest Wilkins at his Florida home.
More than a year passed between the FBI’s public appeal for victims and Wilkins’ arrest.
One Review at Upload, No Check on Updates
Valve’s process for vetting Steam games has a structural blind spot. The company reviews a game when it’s first uploaded but applies far less scrutiny to updates pushed afterward, according to an explanation of how the review process works.
That gap is exactly how BlockBlasters turned malicious months after launch. It shows up across every incident tied to this case.
| Game or Case | What Happened | When | Reported Losses |
|---|---|---|---|
| PirateFi | Removed by Valve after researchers found it stealing browser passwords | February 2025 | Not publicly quantified |
| BlockBlasters | Malicious patch added after launch; malware checked for antivirus software before deploying | Patched August 2025; flagged publicly in September 2025 | More than $150,000 across about 478 accounts |
| Wilkins complaint (eight titles total) | Named in a federal conspiracy charge covering BlockBlasters, Dashverse, Lampy, Lunara, PirateFi and others | Alleged May 2024 to February 2026 | $220,000 across about 80 wallets |
In both the PirateFi and BlockBlasters cases, Valve pulled the title only after players had already lost money.
What Happens to Wilkins Now?
Wilkins faces a single federal count of conspiracy to obtain information by computer for private financial gain, a charge that carries up to 10 years in prison if he’s convicted. Prosecutors haven’t named or charged any of his alleged co-conspirators, and his defense attorney did not respond to a request for comment on the case.
The bureau has built tech-fraud cases on unconventional evidence trails before. Earlier this year it warned that dating app matches were turning into armed robberies.
The eight games named in the complaint are gone from Steam now. Valve has not said whether its review process will change before the next one goes up.
Frequently Asked Questions
What should I do if I downloaded one of the malware-linked games?
Security researchers who studied BlockBlasters recommend running a full antivirus scan right away, changing any passwords stored in a browser on that machine, and moving funds out of any crypto wallet that was open or connected while the game was running. Revoke wallet approvals granted around the time of installation, since stolen credentials can be used long after the fact.
Did the hackers target specific crypto holders or random players?
Reporting on the BlockBlasters campaign found the operation went beyond random downloads. Researchers said the group identified people on social media who managed large cryptocurrency holdings and aimed the malicious game directly at them.
Were other people charged besides Zyaire Wilkins?
No additional defendants have been publicly named or charged as of this reporting. The complaint references unnamed co-conspirators and describes at least one other participant who was interviewed by investigators.
Is it still safe to download games from Steam?
The overwhelming majority of the platform’s library carries no risk. The PirateFi and BlockBlasters cases show that Valve’s review at upload doesn’t guarantee a game stays clean through later updates, so keeping crypto wallets and sensitive accounts off a gaming PC remains the safer practice.
-
AI1 month agoSpaceX’s Google Deal Turns a Rocket Company Into a Cloud Landlord
-
APPS1 month agoDGO App Brings Rs 549 Mobile Pass for FIFA World Cup 2026 in Nepal
-
CRYPTO1 month agoXPL Rallies 30% Ahead of Plasma One Card Tier Launch
-
NEWS1 month agoGoogle Search Profiles Build a Follow Graph Inside Discover
-
GAMING4 weeks agoCD Projekt Red Co-CEO: Redemption Arc Isn’t Done, Witcher 4 in 2027
-
AI4 weeks agoOracle Cuts 21,000 Jobs in a Year, Cites AI in 10-K Filing
-
AI1 month agoMoonshot AI Targets $30 Billion in China’s Fastest AI Funding Sprint
-
AI3 weeks agoFable 5 and Mythos 5 Return as US Lifts Anthropic Export Controls
