FBI arrests 21-year-old who hid crypto-stealing malware in eight Steam games

By: Anton Kratiuk | today, 13:47

The FBI arrested a 21-year-old Florida man on July 14, 2026, for allegedly embedding crypto-stealing trojans inside eight games published on Steam. Zyaire Dontaevious Zamarion Wilkins is accused of running the scheme from May 2024 to February 2026, infecting roughly 8,000 computers and compromising around 80 cryptocurrency wallets to steal at least $220,000. All eight games have since been removed from Steam.

The scheme

The operation was precise rather than opportunistic. Wilkins and at least one unnamed co-conspirator would submit a clean game to Steam, push a malicious post-launch update containing infostealer trojans, then deploy bots across Discord, Telegram, X, and LinkedIn to identify users holding large crypto balances and send them targeted messages promoting the games. Of the 8,000 machines infected, around 80 wallets were successfully drained — an 8% hit rate that points to deliberate high-value targeting, per CryptoTicker.

The malware bundle — Vidar, HijackLoader, and Fickle Stealer — was reportedly purchased for $10,000 from a dark-web seller operating under the handle "Sibel.eth." One game, BlockBlasters, alone accounted for more than $150,000 in theft. Among its victims was a Twitch streamer running a cancer fundraiser who had $32,000 drained mid-stream, according to SSLs Cybersecurity.

The arrest

Investigators traced the stolen bitcoin through a chain of more than 150 Bitrefill gift card purchases used to pay for Uber Eats deliveries. Those deliveries were linked to Wilkins' home address — a straightforward forensic trail that led directly to his door. He now faces a federal conspiracy charge carrying up to 10 years in prison. A co-conspirator has not been charged.

Platform trust

The named games — BlockBlasters, Dashverse, Lunara, PirateFi, Chemia, Lampy, DashFPS, and Tokenova — were all exclusive to Steam and were pulled from the storefront in early 2026. The FBI's complaint does not name Valve directly, but the case exposes a real gap: a game can pass initial review cleanly, then receive a malware-laden update with far less scrutiny. Valve has not issued a public statement on what review changes, if any, followed the removals.

If you downloaded any of the eight games between mid-2024 and early 2026, running a full malware scan and auditing your crypto wallet access logs would be a reasonable precaution.