Policy & Regulation
FBI arrests man accused of hiding malware in Steam games
The FBI arrested a 21-year-old Florida man accused of uploading malware-laden video games to Steam that allegedly infected around 8,000 victims and drained at least $220,000 in cryptocurrency.
U.S. prosecutors have accused a Florida man of uploading fake video games containing malware to Steam, the popular PC gaming platform. According to a criminal complaint, once victims downloaded and installed the games, the malware was designed to infect their computers, steal their passwords and other data, and drain their cryptocurrency wallets.
The FBI arrested Zyaire Wilkins, a 21-year-old Florida resident and student, on Tuesday. The following day, prosecutors accused him and a number of unnamed co-conspirators of hacking crimes. Over the past two years, Wilkins and his partners allegedly published several malware-laden video games on Steam, including BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi. Using that malware, the FBI alleges, Wilkins and his accomplices infected around 8,000 victims and then hacked around 80 cryptocurrency wallets, stealing at least $220,000 worth of crypto. The group allegedly marketed the malicious games on Discord, LinkedIn, and Telegram. Wilkins’ lawyer did not respond to a request for comment.
In March, the FBI announced it was investigating a hacker suspected of using malware-embedded video games published on Steam to target victims, and asked anyone who had downloaded the malicious games — including titles named in this week’s complaint — to come forward with evidence. Steam’s maker, Valve, has separately removed several games from its platform after finding they contained malware, including PirateFi; all were designed to look legitimate enough that players could install and play them despite the hidden malware.
The complaint describes how investigators built the case. After identifying another person allegedly involved in the scheme, federal agents interviewed them; that person said they had worked with others to raise money to launch and market the malicious games in exchange for a share of the stolen cryptocurrency. The FBI traced payments from a specific crypto account tied to the scheme to purchases of gift cards, including for Uber Eats. A subpoena to Uber linked those gift cards to an account that made deliveries to Wilkins, who allegedly went by the nickname “Sibel.eth” online.
Agents then obtained a search warrant for Wilkins’ residence, where they seized his MacBook laptop, cellphones, other devices, and digital wallets. According to the complaint, he refused to speak or answer any questions.
Why it matters
The case underscores how gaming platforms with large, trusting user bases can double as distribution channels for crypto-stealing malware, and how investigators are increasingly using payment trails — down to food-delivery gift cards — to unmask suspects who transact primarily in cryptocurrency.