Gaming Malware Scam Drains Investors $220K in Cryptocurrency – Federal Probe Expands

How a Steam game malware scheme allegedly drained $220K in crypto — and the practical steps gamers can take to stay safe.

Federal prosecutors say a gaming malware scheme drained roughly $220,000 in cryptocurrency from victims' wallets, and the FBI has charged a 21-year-old Florida man in connection with it. According to a criminal complaint reported by TechCrunch, Zyaire Dontaevious Zamarion Wilkins of North Lauderdale was arrested in mid-July 2026 on a conspiracy charge tied to hidden malware in video games. The "malware" here is software secretly bundled inside real-looking games that, once launched, stole passwords and crypto wallet data. The case is an unproven allegation, the probe is still active, and the FBI is asking more possible victims to come forward.

Table of Contents

What actually happened

Between May 2024 and February 2026, malware buried inside video games allegedly infected about 8,000 devices and let attackers reach roughly 80 cryptocurrency wallets, according to reporting from News.Bitcoin. The complaint puts the confirmed theft at "at least" $220,000, meaning the real total could grow as investigators find more victims. The tainted games were distributed through Steam, Valve's popular PC gaming platform.

Tom's Hardware reports the titles named in the complaint include BlockBlasters, Chemia, Dashverse, Lampy, Lunara, PirateFi, and Tokenova. It is worth being precise about the word "investors." These victims were gamers and crypto holders whose personal wallets were emptied. They did not invest in a fund or a game studio; they downloaded software that betrayed them.

How the malware stole crypto

The scheme relied on trust in a legitimate storefront, then attacked the moment a game ran. Once a player launched an infected title, the malware activated and began harvesting sensitive data from the device. According to Fortune's reporting via Yahoo, the malware collected browser credentials, saved passwords, authentication data, and crypto wallet information.

That combination is dangerous. Saved passwords and authentication tokens can let an attacker bypass logins, while wallet data opens the door to draining funds directly. This is a common pattern in "infostealer" malware — programs that quietly scrape whatever secrets a browser or app has stored. The lesson for readers is blunt: a wallet is only as safe as the device it runs on.

The targeting and the money trail

The conspiracy did not wait for random downloads. Bots on Discord, Telegram, X, and LinkedIn allegedly scouted for people with large crypto holdings, then steered them toward the infected games, Local10 reported. In other words, victims were often selected on purpose because they held real money.

Investigators followed the stolen Bitcoin to cash out the case. Tom's Hardware reports the funds were traced to Bitrefill purchases of more than 150 gift cards, largely for Uber Eats, and a wallet labeled "Sibel.eth" was linked to Wilkins. That kind of blockchain tracing — following coins from theft to spending — is increasingly how these cases get built.

Where the case stands now

Wilkins is charged with conspiracy to obtain information by computer for private financial gain, and he faces up to 10 years in prison if convicted, according to TechCrunch. The case is being prosecuted in Seattle federal court by the FBI's Seattle office. A charge is not a conviction; Wilkins is presumed innocent unless proven guilty.

The complaint references co-conspirators — "and others" — which signals the investigation is not finished. The FBI Seattle office has issued a public plea for victim information in what it calls the "Steam malware investigation," a sign more victims are still being identified. If you played any of the named games and hold cryptocurrency, treat your accounts as potentially exposed. Move funds to a fresh wallet on a clean device, rotate passwords, and enable hardware-based authentication where possible.

Protecting yourself from game-based malware

The stores you trust can still deliver bad software, so a few habits matter more than the storefront's reputation:.

  • Keep significant crypto in a hardware wallet, not a browser extension on a machine you use for gaming.
  • Be suspicious of strangers on Discord, Telegram, X, or LinkedIn who nudge you toward a specific new game.
  • Watch for warning signs after installing a game: unexpected logins, drained balances, or password-reset emails you did not request.
  • Use a separate device or user account for high-value crypto activity when you can.
  • Report crypto and malware fraud to the FBI Internet Crime Complaint Center, which also helps investigators connect victims to open cases.

Frequently Asked Questions

Were the infected games on Steam removed?

The complaint names seven titles distributed via Steam, including PirateFi and BlockBlasters. Treat any of them as unsafe and assume your device may be compromised if you ran one.

Is the $220,000 the final total?

No. The complaint describes "at least" $220,000, and the FBI is still seeking victims, so the confirmed loss may rise.

Has anyone been convicted?

No. Wilkins is charged, not convicted, and is presumed innocent. The complaint also references unnamed co-conspirators still under investigation.


You Might Also Like