News
Platform news and market context
News
Platform news and market context
FBI Links $220K Crypto Theft from Malware in 8 Steam Games to Suspect via Uber Eats Deliveries
The FBI is investigating a campaign where eight malware-infected games on Steam allegedly stole over $220,000 in cryptocurrency from around 80 wallets, with authorities reportedly tracing the stolen funds through Uber Eats gift card purchases back to a suspect.

The Federal Bureau of Investigation is actively searching for potential victims of a malware scheme involving eight video games, in a case that highlights how cryptocurrency custody can be compromised even before a user opens their digital wallet. The investigation demonstrates the dual nature of software-mediated wallet risk, with investigators reportedly uncovering the suspect's identity by following a trail of Bitcoin-funded Uber Eats deliveries.
The Alleged Malware Campaign
According to a federal complaint reported by Local 10, an operation involving eight games resulted in the infection of approximately 8,000 devices. This campaign allegedly provided unauthorized access to around 80 cryptocurrency wallets, leading to the theft of at least $220,000.
On July 14, federal agents arrested 21-year-old Zyaire Dontaevious Zamarion Wilkins, as reported by Local 10. The complaint accuses Wilkins of financing and obtaining the malware, as well as assisting in the marketing of the compromised games. While the complaint refers to the distribution platform only as a “popular digital distribution software company,” the FBI has since linked the activity to Steam. Wilkins is presumed innocent until proven guilty in a court of law.
An official FBI notice identifies the eight games as:
- BlockBlasters
- Chemia
- Dashverse
- DashFPS
- Lampy
- Lunara
- PirateFi
- Tokenova
The FBI has bracketed the suspected activity on the Steam platform as occurring between May 2024 and January 2026. The broader campaign, as detailed in the complaint cited by Local 10, allegedly extends through February 2026.
Method of Attack
The complaint outlines that the group allegedly promoted these games across platforms such as Discord, Telegram, X (formerly Twitter), and LinkedIn. Automated bots were purportedly used to identify individuals with significant cryptocurrency holdings and then send them targeted messages encouraging them to download the infected games.
Once installed, the malware was designed to capture private information and user credentials. The group also reportedly discussed methods for deceiving victims into authorizing transactions that would completely empty their wallets.
The case of PirateFi, one of the titles listed by the FBI, illustrates how a download from a trusted source could lead to wallet data exposure. A cyber advisory from February 2025 noted that PirateFi was available on Steam from February 6 to February 12, 2025. This game allegedly contained the Vidar infostealer, a type of malware capable of harvesting credentials, session cookies, and sensitive crypto wallet information.
Platform and User Security Blind Spots
This attack chain exposes vulnerabilities at two distinct layers of control. According to Valve's onboarding documentation, initial software builds undergo checks for malicious behavior. However, the company's review documentation specifies that games, once approved, can be updated later without necessitating another formal review. While these documents do not clarify the exact method by which the games in this case evaded security measures, they indicate that effective scrutiny must encompass both initial submissions and subsequent updates.
For cryptocurrency users, this incident underscores that relying solely on an official marketplace as a boundary of trust is insufficient. A critical security practice is to keep wallet secrets and authenticated sessions isolated from gaming endpoints, thereby limiting the data an infostealer can access. Furthermore, deliberately and carefully reviewing all transaction prompts addresses the separate risk of being tricked into approving a malicious transfer. Neither of these user-side controls, however, can substitute for vigilant marketplace screening.
Following the Money
The investigative trail that allegedly led to Wilkins reveals the other side of the attack. According to Local 10, investigators traced Bitcoin payments from a wallet linked to the scheme to Bitrefill, an online service. The funds were used to purchase over 150 digital gift cards, the majority of which were for Uber Eats.
Subsequently, a subpoena issued to Uber allegedly connected these gift cards to a specific account. Deliveries made through this account were traced to addresses associated with Wilkins. Although the transparency of the blockchain did not stop the thefts from occurring, it purportedly preserved a traceable forensic path once the funds intersected with a service tied to a real-world identity. This case demonstrates that securing the software distribution pipeline is a crucial part of pre-incident custody security, while on-chain records and off-ramp data can provide invaluable evidence for post-incident investigations.
Discussion about this post
No comment yet
Be the first to share your opinion!