FBI arrests Florida man accused of hiding malware in Steam games to steal crypto

A 21-year-old Florida man has been arrested by the FBI on suspicion of uploading fake video games to Steam that secretly stole cryptocurrency from players. According to TechCrunch, Zyaire Wilkins was taken into custody on Tuesday, with federal prosecutors formally accusing him and several unnamed co-conspirators of hacking crimes the following day.

The scheme was straightforward but effective. Wilkins and his partners allegedly published multiple games on Valve’s Steam platform, each one designed to look and play like a real game. Once installed, the malware inside would steal passwords, harvest personal data, and drain cryptocurrency wallets. The FBI says the group infected roughly 8,000 computers and stole at least $220,000 in crypto by hacking around 80 wallets.

The fake games at the center of the case include BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi. Wilkins and his co-conspirators allegedly marketed them across Discord, LinkedIn, and Telegram to attract downloads. Wilkins’ lawyer did not respond to a request for comment.

The investigation had actually been in motion for months. Back in March, the FBI publicly announced it was looking into a hacker using malware-embedded Steam games and asked anyone who had downloaded those titles to come forward with evidence. That outreach appears to have played a role in building the case.

Valve had already started pulling some of the games before the arrest. PirateFi and several others were removed from Steam after being flagged as malicious. The games were convincing enough that players could actually load and play them, which made them harder to spot as threats.

The trail to Wilkins came together through a mix of crypto tracing and a surprisingly mundane link: food delivery. Here is how investigators connected the dots:

  • Federal agents interviewed an unnamed individual linked to the scheme, who described how participants split stolen crypto in exchange for helping fund and promote the games.
  • Investigators identified a specific crypto account tied to the operation and traced payments from it to gift card purchases, including for Uber Eats.
  • After subpoenaing Uber, agents found those gift cards connected to an account that had made deliveries to Wilkins’ address.
  • Wilkins used the online handle ‘Sibel.eth’, which helped link his real identity to the scheme.

Agents then obtained a search warrant for his home and seized a MacBook, several phones, other devices, and digital wallets. Wilkins refused to answer any questions during the search.

This case sits within a broader pattern of cybercriminals using gaming platforms as cover for malware distribution. Steam has hundreds of thousands of titles, many from independent developers with little vetting, which makes it an attractive target. Players are often conditioned to trust the platform, meaning they are less likely to question whether a game is safe to install. That trust is exactly what this scheme exploited.

The crypto angle also reflects how theft has shifted. Draining wallets directly is faster and harder to reverse than traditional fraud, and the pseudonymous nature of crypto transactions can make tracing difficult. In this case, though, gift card purchases tied to a real delivery address proved to be the weak link.