The FBI arrested Zyaire Wilkins, 21, of North Lauderdale, Florida. According to prosecutors, he paid for malware that was embedded in eight games on Steam. The malware stole crypto from about 8,000 hacked computers over about two years. A federal complaint says the infected titles passed Steam’s review process but became malicious later through updates.
According to the FBI, the malware was an infostealer. During gameplay, it silently collects stored passwords, current session tokens, and information from crypto wallets. The infections were distributed among eight titles from May 2024 to February 2026. The games are BlockBlasters, Dashverse, Lunara, PirateFi, Chemia, Lampy, DashFPS, and Tokenova. Steam pulled all eight games in early 2026. Some titles came out clean and passed platform checks. The malicious payload came later, in a post-launch update, a sequence that bypasses the first review altogether. Bitdefender called the titles “indie games distributed through Steam” that “harbored malware inside.”
FBI says the suspect used the malware to steal crypto credentials
The FBI mentioned that the operation did not wait for victims to wander in. According to the complaint, bots flagged wallets with large balances. They then sent the targets direct messages on Discord, Telegram, X and LinkedIn, directing them to the infected downloads. BlockBlasters alone netted more than $150,000 from 261 to 478 victims, according to forensic researcher ZachXBT and the malware repository vx-underground.
In September 2025, Twitch streamer RastalandTV lost ~$32,000; most of the funds were donated by viewers to cancer treatment. FBI investigators say Wilkins didn’t build the tool by himself. According to the complaint, he paid $10,000 for a remote access Trojan under the darkweb handle “Sibel.eth.” He worked with a lead developer who has not been charged and remains unnamed. It was the spending that gave away the scheme. The conspirators converted stolen crypto to more than 150 Bitrefill gift cards.
Most of them were for Uber Eats orders. That food delivery account led to Wilkins, whose wallets showed ~$382,000 in crypto flowing through them, the complaint said. Wilkins is charged with conspiracy to obtain information by computer for private financial gain. That carries a jail sentence of up to 10 years. His court date was on July 15th.
As Cryptopolitan reported this month, 34-year-old Armenian national Karen Serobovich Vardanyan pleaded guilty this month to conspiracy and computer fraud for his part in a Ryuk ransomware campaign on July 8. That campaign extracted more than $15 million in bitcoin from U.S. companies. Cryptopolitan also reported on a separate situation in which a fake Polymarket trading bot delivered credential-stealing malware to 50+ developers.
Security researchers have one piece of direct advice for anyone who installed the named titles. If you keep crypto on the same computer you game on, consider a hardware wallet. Assuming the computer is compromised, run a full antimalware scan from a clean device and reset every password and session token. In PirateFi in particular, researchers suggest a full OS reinstall, according to PCMag.


