Steam’s role as a trusted delivery channel is central to a new federal malware case, not merely a detail about where a game was sold. The FBI has arrested Zyaire Dontaevious Zamarion Wilkins, a 21-year-old from North Lauderdale, Florida, who is accused of helping distribute video games embedded with malware and then drain victims’ cryptocurrency wallets. According to Local 10’s account of the federal complaint, the alleged operation launched eight games, infected roughly 8,000 customer devices, gained access to about 80 crypto wallets, and stole at least $220,000 between May 2024 and February 2026. The case alleges a familiar fraud mechanism with an unusual distribution advantage: software presented as an ordinary game could make the initial download appear safe.

The charging complaint reportedly refers only to a “popular digital distribution software company,” rather than naming Steam. But several game titles listed in the complaint–BlockBlasters, Dashverse, Lunara, and PirateFi–overlap with the titles in the FBI Seattle Division’s public Steam malware victim notice. That notice identifies BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi, and Tokenova, and says the suspected threat actor primarily targeted users from May 2024 through January 2026. Earlier reporting by TechCrunch described the FBI investigation as involving malware embedded in games hosted on Steam.

The alleged workflow did not depend on a game itself being valuable. Investigators say Wilkins and others marketed the games through Discord, Telegram, X, and LinkedIn, while bots singled out people with large cryptocurrency holdings and sent them prompts to download the software. Once installed, the malware allegedly harvested private data and credentials; the conspirators then searched that information for what could unlock crypto accounts. The complaint further alleges that Wilkins, using the handle “Sibel.eth,” bought a remote-access Trojan for $10,000 and discussed “draining campaigns” with an unidentified primary developer–campaigns designed to trick victims into approving transactions that could empty a wallet immediately.

That combination matters because it separates the compromise into stages: establish trust with a functional-looking game, extract credentials or session data after installation, identify accounts worth targeting, then convert access into transactions. GameSpot’s report says the alleged promotional campaign reached victims through social and messaging platforms before the infected download. The FBI form, meanwhile, asks potential victims for the game name and download date, whether someone contacted them before or after installation, wallet and transaction information, and evidence of compromised Steam, email, or crypto accounts.

Investigators say they linked “Sibel.eth” to Wilkins by tracing payments from the scheme’s Bitcoin wallet to Bitrefill, where more than 150 gift cards–mostly for Uber Eats–were purchased. An FBI subpoena to Uber then connected the cards to an account delivering to Wilkins’s Florida home and University of West Florida addresses, according to Local 10. Agents executing a search warrant at his home seized devices and three cryptocurrency wallet seed phrases; the complaint says Wilkins declined to speak with law enforcement. It also says a review of his cryptocurrency activity showed about $382,000 sent or received, a figure that is not itself presented as the amount stolen in this case.

The arrest is an important enforcement step, but it does not close the wider investigation. The complaint does not identify the alleged primary developer, and the government’s claims have not been tested in court. The FBI is still soliciting reports from people who installed any of the named games, both to identify victims and to support the investigation. For users, the case is a reminder that a listing on a familiar software storefront can reduce suspicion without eliminating the risk that a later build, update, or targeted invitation is carrying something else.


Discover more from TekCrispy

Subscribe to get the latest posts sent to your email.

Leave a comment

Leave a Reply