Technology

Someone Hid Malware in Steam Games to Steal People's Cryptocurrency. The FBI Made an Arrest.

Martin HollowayPublished 2w ago4 min readBased on 5 sources
Reading level
Someone Hid Malware in Steam Games to Steal People's Cryptocurrency. The FBI Made an Arrest.

Federal authorities arrested a 21-year-old Florida man on July 14, 2026. They say he helped put fake games on Steam, a popular platform for buying and playing video games, and that those games contained hidden software designed to steal cryptocurrency from players. Zyaire Wilkins of North Lauderdale, Florida, was charged with conspiracy to obtain information by computer for private financial gain, according to a criminal complaint filed in a Washington court, where Steam's parent company Valve is based (The Verge; Local10).

The FBI identified seven game titles tied to the investigation: BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi, and Tokenova. Cryptocurrency is digital money that people store in software programs called wallets. The hidden malware gave the accused access to about 80 of these wallets. The software infected roughly 8,000 computers, and total losses are alleged to be at least $220,000 (The Verge).

The conspirators promoted the games on Discord, Telegram, X/Twitter, and LinkedIn to get more people to download them, according to the complaint, available on DocumentCloud (The Verge; DocumentCloud). The scheme relied on the fact that people trust Steam. Millions of users download games from the platform without worrying about whether a listed title is safe.

One game, BlockBlasters, allegedly accounted for more than $150,000 in stolen cryptocurrency on its own. Among its victims was a streamer raising funds for cancer treatment (The Verge).

Investigators found Wilkins by following the money. They got his cryptocurrency wallet address from messages he exchanged with an alleged co-conspirator. That wallet was linked to a Bitrefill account. Bitrefill is a service that lets people turn cryptocurrency into gift cards. The account had been used to buy more than 150 gift cards, including Uber Eats credits. Those purchases allowed authorities to identify Wilkins's phone number and physical address (The Verge).

The FBI has published a victim-information form at forms.fbi.gov/victims/Steam_Malware, encouraging anyone affected by the listed game titles to come forward (The Verge; FBI). Valve Corporation did not immediately respond to The Verge's request for comment (The Verge).

The case is U.S. v. Wilkins. Local10 (WPLG, the Miami/Fort Lauderdale ABC affiliate) first reported the arrest on July 15, 2026 (The Verge; Local10).

The scheme followed a pattern we have seen before in cybercrime: trick people into downloading something, use a trusted platform so they let their guard down, secretly copy their login details and wallet keys, then find a way to turn the stolen cryptocurrency into real-world spending money. Eight games published on Steam over nearly two years, reaching roughly 8,000 infected devices, suggests either limited review by the platform or a deliberate effort to make each game look legitimate. The complaint does not say whether Valve's review process flagged any of the titles before law enforcement became involved.

The way Wilkins allegedly cashed out is also revealing. Cryptocurrency transactions are recorded on a public ledger called a blockchain, but the people behind those transactions are not identified by name. They use wallet addresses instead. The weak link is what happens when someone tries to convert cryptocurrency into something they can spend in everyday life. In this case, buying gift cards through Bitrefill connected a nameless wallet to a phone number and a physical address. The blockchain may not name you, but the place where you convert crypto into gift cards usually does.

The victim profile is worth noting. The allegation that BlockBlasters stole from a streamer raising cancer-treatment funds is a reminder that this kind of malware does not care who it hits. The $150,000 tied to that one game also suggests that losses were concentrated in a few wallets rather than spread across many small thefts. That matters for how investigators contact victims and how restitution might work.

The FBI's decision to publish a public victim form signals that the bureau expects more victims than the 80 wallets listed in the complaint. Anyone who downloaded BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi, or Tokenova from Steam during the alleged period should consider their cryptocurrency wallets compromised and take steps to secure them.

For platform operators, the case is a reminder that any app-store-style distribution model carries some risk of abuse, no matter how trusted the brand. Eight titles over 21 months is not a catastrophic failure rate for a catalog the size of Steam's, but each title was a direct line from a trusted download to a victim's wallet. Whether Valve adjusts its review process in response is an open question. The company has not commented publicly.