Connect with us

NEWS

FBI Arrests Florida Student Behind $220,000 Steam Malware Scheme

FBI charges tie a Florida student to a $220,000 Steam malware scheme, the fourth such wave to hit the platform since 2023 as Valve stays silent.

Published

on

The FBI arrested a 21-year-old Florida college student on July 14, accusing him of hiding password-stealing malware inside eight video games that made their way onto Steam. Zyaire Dontaevious Zamarion Wilkins now faces up to ten years in prison in a scheme prosecutors say infected roughly 8,000 computers and drained about $220,000 from 80 cryptocurrency wallets.

Investigators did not need blockchain wizardry alone to find him. They followed the stolen bitcoin through a gift card service and into Uber Eats orders delivered to Wilkins’ own front door, the detail that turned a faceless crypto drainer operation into a federal complaint with a name attached.

A Food Delivery Receipt Cracked the Case Open

Federal agents say the scheme’s Bitcoin wallet paid for more than 150 gift cards through Bitrefill, a service that converts crypto into spendable credit. Most of those cards went toward Uber Eats orders. A subpoena to Uber matched the cards to an account with deliveries at Wilkins’ family home in North Lauderdale, Florida, and at his address near the University of West Florida, where he is a student, according to Tom’s Hardware and Miami station WPLG Local 10.

The 15-page complaint never names the storefront directly, calling it only a “popular digital distribution software company.” Every title it lists, including BlockBlasters and PirateFi, was sold on Steam until Valve pulled it.

Agents searched Wilkins’ North Lauderdale house about a week before the arrest. They seized several devices, a MacBook laptop, cellphones, and three cryptocurrency wallet seed phrases, one tied to Monero, a privacy coin the FBI called difficult to trace. Wilkins refused to answer questions, according to the complaint. His own transaction history showed roughly $382,000 in cryptocurrency moving in and out of his accounts.

He was arrested on a Tuesday and charged the next day with conspiracy to obtain information by computer for private financial gain, a count that carries up to ten years in prison. Wilkins appeared in federal court in Fort Lauderdale on July 15. The FBI is still asking anyone who installed one of the eight games to submit tips through its Steam malware victim form, saying the details help identify Wilkins’ still-unnamed collaborators. The case itself is being prosecuted roughly 3,000 miles from Wilkins’ home, in Seattle federal court, close to Valve Corporation’s headquarters in Bellevue, Washington.

Bots Hunted Crypto Whales, Then a $10,000 Trojan Did the Rest

The malware did the technical work. The marketing took real coordination. According to the complaint, Wilkins and his associates pushed the infected games on Discord, Telegram, X, and LinkedIn, then used bots to scan those platforms for accounts holding large amounts of cryptocurrency and message them directly.

Wilkins allegedly operated under the dark web alias “Sibel.eth” on the encrypted app Signal, where he communicated with the person the FBI calls the operation’s primary developer. That person has not been publicly named or charged. Chats recovered from the developer’s devices show Wilkins paid $10,000 for a remote access trojan and discussed what the two called “draining campaigns,” including how to trick victims into approving transactions that would instantly empty their wallets, according to WPLG Local 10, which first reported details of the complaint.

Separately, TechCrunch reported that after identifying another person connected to the operation, agents interviewed that individual, who admitted helping raise money to launch and market the malicious games in exchange for a cut of the stolen cryptocurrency. Public filings do not make clear whether this is the same person described elsewhere as the primary developer.

The FBI believes Wilkins financed the operation and later sold the malware itself to other cybercriminals on underground forums, a detail suggesting the code outlived any single game it was hidden in.

A Cancer Patient’s Livestream Turned Into the Case’s Turning Point

Of the eight games, BlockBlasters caused the most visible harm. The 2D platformer launched cleanly on Steam in the summer of 2024. An update in late August 2025 quietly added crypto and credential stealing code, active for close to a month before anyone noticed, according to the SteamDB tracking site.

The theft went public on September 21, 2025. Raivo Plavnieks, a Latvian Twitch streamer known as RastalandTV who was livestreaming to raise money for stage 4 sarcoma treatment, took a viewer’s suggestion to try the game. His wallet, holding roughly $32,000 in donations raised through a Pump.fun token called $CANCER, was drained live on air.

Blockchain investigator ZachXBT and the malware research group vx-underground began tracing the theft within days. ZachXBT put the damage at more than $150,000 stolen from 261 Steam accounts. vx-underground later counted 478 victims, a gap the two trackers never fully reconciled. ZachXBT posted a blunt message aimed squarely at the platform.

You clowns allow malware on your platform that has resulted in $150K+ stolen from victims.

Valve pulled BlockBlasters within days of the theft going viral. It has not issued a public statement on the incident, and it did not respond to interview requests from TechCrunch, Tom’s Hardware, PCGamesN, or WPLG Local 10 while each outlet reported on this month’s arrest.

Steam Has Broken This Way Four Times Since 2023

The Wilkins case is not Steam’s first brush with malware wrapped inside a working game. Researchers count at least four earlier incidents on the platform, each following a similar shape: a title clears Valve’s initial review, then either ships with hidden code or receives a malicious update later.

Incident Date Malware Method Reported Impact
Dota 2 custom game modes February 2023 Chrome n-day exploit for remote code execution Players targeted through modified game modes
Slay the Spire mod December 2023 “Epsilon” infostealer dropper injected into a popular mod Players who installed the mod compromised
PirateFi February 2025 Vidar infostealer hidden in a survival game Up to 1,500 downloads before Valve pulled it within a week
Chemia 2025 HijackLoader malware plus a custom Fickle Stealer Credential and wallet data theft from Early Access players
BlockBlasters August to September 2025 Malware added in a post launch update More than $150,000 stolen from 261 to 478 accounts

Two of those five incidents, PirateFi and BlockBlasters, are named directly in the complaint against Wilkins. The FBI’s Seattle Division first asked the public for help in a notice made public on March 11, listing seven games under investigation for embedded malware, including BlockBlasters, Chemia, Dashverse, Lampy, Lunara, PirateFi, and Tokenova.

Why One Loophole Keeps Letting Malware Back In

Steam’s publishing barrier is low by design. Any studio or individual can list a game for a $100 fee and basic documentation, a structure meant to keep the platform open to small developers. That openness is also the gap every one of these schemes has used.

Valve’s own onboarding materials say new submissions are checked for harmful behavior before they go live. Its review documentation, however, states that an approved game can be updated later without a second review, according to CryptoSlate’s reading of Valve’s published policies. BlockBlasters fits that pattern exactly: a clean initial launch, then a malicious update a month before anyone caught it.

Free listings move fast on the platform, which adds to the problem. Steam pushes no-cost titles constantly, the same appeal behind the free weekend giveaways it runs most months, and that steady churn of no-cost downloads is exactly the traffic a malicious “free” game needs to blend in.

What the complaint confirms:

  • Wilkins faces one federal count, conspiracy to obtain information by computer for private financial gain, carrying up to ten years in prison.
  • The scheme ran from May 2024 through February 2026, hit about 80 wallets, and infected roughly 8,000 devices across eight games.
  • The case is being prosecuted in Seattle federal court, and Wilkins had not entered a public plea as of this writing.

What remains unconfirmed:

  • The identity of the operation’s primary developer, who allegedly sold Wilkins the remote access trojan but has not been charged.
  • Whether more arrests are coming. The FBI has not said.
  • Whether the full list of affected titles extends beyond the eight cited in reporting so far.

Did You Download One of These Games?

Anyone who installed BlockBlasters, Dashverse, Lunara, or PirateFi on any device should treat that machine as compromised. The malware was built to capture browser sessions, saved passwords, and wallet credentials, so any account accessed on that computer during the exposure window may be at risk, no matter when the game itself was removed.

Security researchers and the FBI recommend a specific sequence rather than a quick scan alone:

  • Disconnect the affected computer from the internet before doing anything else on it.
  • Move any cryptocurrency to a new wallet on a clean device, and treat every seed phrase that touched the infected machine as burned.
  • Change passwords for email, exchange, and wallet accounts from a separate, trusted device, and turn on hardware key or app based two factor authentication.
  • Run a full offline antivirus scan, and reinstall the operating system entirely if any credential stealing component turns up.
  • Review and revoke active browser sessions on exchanges, wallet services, and email providers.
  • Report losses, including wallet addresses and transaction hashes, to the FBI’s Internet Crime Complaint Center at ic3.gov.

The Wilkins case is one thread in a much larger tangle. Crypto fraud complaints topped $11 billion in losses last year, per the FBI’s own tally, and gaming platforms are turning into one of the more effective ways in.

Frequently Asked Questions

Is Valve facing any charges over the Steam malware cases?

No. The indictment targets Wilkins and unnamed co-conspirators, the people accused of building, buying, and marketing the malware, not the storefront that hosted the games. No public filing names Valve as a defendant or target of the investigation.

What is Bitrefill, and why did it matter to the investigation?

Bitrefill is a service that converts cryptocurrency into spendable gift cards for everyday purchases. Because the scheme’s proceeds allegedly moved through Bitrefill before turning into Uber Eats orders, it created the exact kind of paper trail that let agents connect an anonymous wallet to a real address.

Were the infected games actually removed from Steam?

Yes, though not on the same timeline. PirateFi was pulled within about a week of its release in February 2025. BlockBlasters stayed listed for roughly a month after its malicious update before the RastalandTV theft forced Valve’s hand in September 2025.

Has Valve changed how it reviews games since these cases?

Not publicly. As of this month’s arrest, Valve had not announced any overhaul to its review process, which still checks initial submissions but allows approved games to update without a second inspection, and it has not responded to media requests for comment on the Wilkins case specifically.

What happens if the malware’s developer is never charged?

Agents have searched that person’s property and reviewed devices seized there, but no charges have been filed against them as of publication. The complaint keeps the individual unnamed, and prosecutors have not said whether that will change as the case against Wilkins moves forward.

Disclaimer: This article is for informational purposes only and does not constitute legal, financial, or cybersecurity advice; anyone who suspects their device or crypto wallet has been compromised should consult a qualified security professional and contact law enforcement directly.

As the founder of Thunder Tiger Europe Media, Dr. Elias Thornwood brings over 25 years of experience in international journalism, having reported from conflict zones in the Middle East, Asia, and Africa for outlets like BBC World and Reuters. With a PhD in International Relations from Oxford University, his expertise lies in geopolitical analysis and global diplomacy. Elias has authored two bestselling books on European foreign policy and received the Pulitzer Prize for International Reporting in 2015, establishing his authoritativeness in the field. Committed to trustworthiness, he enforces rigorous fact-checking protocols at Thunder Tiger, ensuring unbiased, evidence-based coverage of worldwide news to empower informed global audiences.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending