All news
cybersecurityregulationproduct

FBI Charges Man in Steam Malware Crypto Theft Scheme

20 Jul 2026

What happened

Federal authorities have arrested Zyaire Wilkins, a 21-year-old Florida resident and student, on charges tied to an alleged scheme that used malware-embedded video games distributed through Steam to steal cryptocurrency and sensitive data. Wilkins was charged with conspiracy to obtain information by computer for private financial gain.

According to the complaint, Wilkins and unnamed co-conspirators published a series of malware-laden games — including titles like BlockBlasters, Dashverse (also referred to as DashFPS), Lampy, Lunara, and PirateFi — over roughly the past two years. The Verge's account also lists Chemia and Tokenova among the malicious titles, while TechCrunch's reporting names only five games, omitting those two. Sources differ on the exact count and list of titles involved.

The malware embedded in these games was designed to steal passwords and other sensitive data, and — more notably — to drain cryptocurrency wallets directly from infected devices. Prosecutors allege the scheme was marketed through mainstream platforms including Discord, Telegram, X (formerly Twitter), and LinkedIn, extending its reach well beyond Steam's own ecosystem.

The numbers behind the scheme

  • At least $220,000 in cryptocurrency allegedly stolen
  • About 8,000 devices reportedly infected
  • 80 crypto wallets allegedly accessed
  • BlockBlasters alone allegedly accounted for more than $150,000 of the stolen funds
  • More than 150 gift cards were purchased using an account linked to Wilkins

An unnamed individual involved in the scheme reportedly told investigators they worked with others to raise money to launch and market the malicious games in exchange for a share of the stolen cryptocurrency — suggesting a coordinated, multi-party operation rather than a lone actor.

Timeline and open questions

Sources diverge on key dates. The Verge reports the malware-embedded games were launched between May 2024 and February 2026, while TechCrunch describes the activity as occurring "over the past two years." The FBI first announced its investigation into a hacker using malware-embedded Steam games in March. Wilkins's arrest is dated to July 14th by The Verge, while TechCrunch reports the arrest happened on "Tuesday," with prosecutors' formal accusations coming "on Wednesday" — it's unclear whether these accounts refer to the same dates.

Several details remain unconfirmed: the number and identity of co-conspirators, how victims' devices actually became infected (whether through Steam's official platform, third-party links, or social engineering), whether Steam has removed the flagged games or updated its developer vetting process, Wilkins's current legal status, and whether the $220,000 in stolen crypto has been recovered.

Why founders should care

This case is likely a signal — not a one-off — for founders operating in consumer software, gaming, or crypto-adjacent spaces:

  • Platform liability risk may be rising. Marketplaces that host third-party or user-generated content, like game stores, could face growing scrutiny over how thoroughly they vet developers and code before distribution.
  • Regulatory attention on crypto-adjacent distribution channels may increase. With federal investigators actively pursuing cases involving crypto theft via consumer software, founders building in this space should expect more compliance and security expectations going forward.
  • Demand for consumer-facing security tools could grow. The scheme's reliance on stealing passwords and draining wallets points to a plausible market opportunity for malware detection, endpoint security, and anomaly-detection tools tailored to protect crypto wallets and gaming platforms.
  • Marketing-channel fraud detection may become a priority. Because the malicious games were reportedly promoted through Discord, Telegram, X, and LinkedIn, platforms in this space may need stronger systems to flag fraudulent third-party promotions before they gain traction.

The bottom line

While many operational details remain unresolved — including how the malware actually reached victims and whether Steam has responded — the case underscores a broader trend worth watching: mainstream platforms hosting third-party content and crypto-facing consumer software are becoming higher-value targets, and likely higher-scrutiny environments, for both attackers and regulators alike.

Sources