XOOMAR
Dark cybersecurity scene of malware from gaming apps targeting crypto wallets on a PC
CybersecurityJuly 18, 2026· 6 min read· By XOOMAR Insights Team

Steam Malware Hidden in Games Stole $220K, Feds Say

Share
Updated on July 19, 2026

Steam games are supposed to install entertainment. Prosecutors say Zyaire Wilkins used fake titles on Steam to install malware that helped drain crypto wallets.

XOOMAR Intelligence

Analyst Take

57/ 100
Moderate
4 sources analyzedLow confidenceTrend10Freshness96Source Trust90Factual Grounding90Signal Cluster20

The FBI arrested Wilkins, a 21-year-old Florida resident and student, on Tuesday after prosecutors accused him and unnamed co-conspirators of publishing malware-laced games on Valve’s PC games platform, according to TechCrunch. Authorities allege the Steam malware scheme infected around 8,000 victims, compromised around 80 cryptocurrency wallets, and stole at least $220,000 worth of crypto.

FBI arrests Zyaire Wilkins over alleged Steam malware games that stole crypto

Prosecutors said Wilkins and others published several fake or malicious games over the past two years, including BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi. The games were allegedly designed to look legitimate enough that users could install and play them.

That was the hook. The hidden payload, prosecutors allege, was malware built to infect computers, steal passwords and other data, and drain crypto wallets.

The complaint targets Wilkins’ alleged conduct, not ordinary Steam publishing or game development. Still, the case puts Steam at the center of a sharp security question: how did games carrying malware reach users through a familiar storefront?

Local 10 News, citing a 15-page federal criminal complaint, reported that Wilkins is from North Lauderdale, Florida, and that the case is being prosecuted in Seattle federal court. The complaint said Wilkins and others allegedly “gained unauthorized access to approximately 80 cryptocurrency wallets and stole cryptocurrencies worth at least $220,000” by launching eight games embedded with malware and infecting approximately 8,000 individual customers.

“After their victims downloaded the games, the conspirators used the malware to access and steal private user data and credentials,” the complaint states, according to Local 10 News.

Authorities said the games were marketed through Discord, LinkedIn, and Telegram, according to TechCrunch. Local 10 News also reported that the complaint named X among the platforms used to promote the games.

Wilkins’ lawyer did not respond to TechCrunch’s request for comment. According to the complaint, Wilkins refused to speak or answer questions after agents searched his residence.


Fake Steam games expose the trust gap crypto thieves can exploit

The expectation is simple: a user downloads a game from a known PC storefront and gets a game. Prosecutors say the reality in this case was different: some downloads allegedly carried malware that turned entertainment software into a path toward stolen credentials and crypto theft.

That gap matters because crypto theft does not require every infected user to hold meaningful assets. A broad infection base gives attackers more chances to find the smaller subset with wallets worth targeting. In this case, prosecutors allege around 8,000 infections led to around 80 hacked crypto wallets.

The alleged Steam malware campaign also shows why attackers benefit from blending into normal consumer behavior. A fake game promoted on chat and social platforms can look less suspicious than a random executable file sent directly to a victim.

The before-and-after is stark:

  • Assumption: A listed game is mainly a consumer product.
  • Allegation: Several listed games secretly carried malware.
  • Assumption: Marketing on Discord or Telegram is normal game promotion.
  • Allegation: Those channels helped drive victims toward infected downloads.
  • Assumption: Only a few victims need to matter.
  • Reality alleged by prosecutors: Thousands of infections can create enough reach to find dozens of crypto wallets.

This fits a broader pattern XOOMAR readers already know: crypto theft often rewards attackers who get close to private credentials rather than trying to break blockchains themselves. That is why our coverage of Fake Oracle Profits Drain $18M in Ostium Exploit sits in the same risk category for investors, even though the alleged Wilkins case centers on malware-distributed games rather than a DeFi exploit.

The Steam angle is the sharper consumer-security issue. Valve has removed several games from its platform over the last year after they were found to contain malware, including PirateFi, according to TechCrunch. The source material does not say whether Valve has commented on this complaint.

Gift cards, Uber Eats, and the alleged trail to Sibel.eth

Investigators say they identified a specific crypto account involved in the scheme and traced payments from that account to gift card purchases. Those included Uber Eats gift cards, according to TechCrunch.

After subpoenaing Uber, federal agents found the gift cards were tied to an account that made deliveries to Wilkins, who allegedly used the online nickname Sibel.eth. Local 10 News reported that authorities traced cryptocurrency payments to Bitrefill, an online service used to buy more than 150 digital gift cards, predominantly for Uber Eats.

That detail gives the complaint its most concrete attribution thread. The alleged path runs from crypto payments, to gift cards, to delivery records, to Wilkins.

Agents then obtained a search warrant for Wilkins’ residence. They seized his MacBook laptop, cellphones, other devices, digital wallets, and, according to Local 10 News, multiple devices and three cryptocurrency wallet seed phrases.

Local 10 News also reported that the complaint says Wilkins used Sibel.eth on Signal to communicate with the “primary developer” of the programs. That person was not identified in the complaint.

Federal law enforcement is already a major thread across XOOMAR’s breaking coverage, including Trump’s FBI Line Deepens Lindsey Graham Death Furor. Here, the FBI’s role is narrower but technically dense: connecting alleged malware distribution, blockchain activity, subpoenaed platform data, and seized devices.


Court filings and Steam safeguards now become the pressure points

Wilkins faces a charge of conspiracy to obtain information by computer for private financial gain, a charge that could carry up to 10 years in prison, according to Local 10 News. Federal court records cited by the outlet showed he was scheduled to appear in Fort Lauderdale federal court on Wednesday morning.

The next filings matter. They could clarify whether prosecutors add counts, whether more alleged co-conspirators are named, and how much evidence investigators recovered from seized devices and wallets.

For Steam users, the practical risk is more immediate. Anyone who downloaded BlockBlasters, Dashverse, Lampy, Lunara, PirateFi, or other titles named by investigators should treat the machine as potentially compromised.

Concrete steps, grounded in the alleged behavior described in the complaint:

  • Scan: Run reputable security tools on any device that installed the named games.
  • Separate: Move crypto activity to a clean device and a clean wallet if compromise is suspected.
  • Rotate: Change passwords tied to exchanges, email accounts, and wallet services from an uncompromised device.
  • Revoke: Review and revoke risky wallet permissions tied to accounts that may have been exposed.
  • Report: The FBI previously asked people who downloaded the malicious games to come forward and provide evidence.

The unresolved issue is not whether malware can hide in software downloads. Prosecutors allege it already did here. The watch item is whether court records show how these games passed through Steam long enough to reach thousands of users, and whether Valve changes review or warning procedures after the Wilkins case moves forward.

Impact Analysis

  • The case shows how malware can reach users through familiar platforms that appear trustworthy.
  • Crypto wallet users face heightened risk when installing unverified games or software.
  • The allegations could increase pressure on Steam and other marketplaces to strengthen malware screening.

Scale of alleged Steam malware scheme

Malware-laced games
count8
Compromised crypto wallets
count80
Infected victims
count8,000
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

Close-up of a smartphone wrapped in a chain with a padlock, symbolizing strong security.Cybersecurity

Valve's Shipping Partner Exposes Steam Users' Home Addresses

A cyberattack on Valve's European shipping partner, CEVA Logistics, leaked the personal data of Steam hardware customers, proving physical addresses are now a c

Aug 14, 20267 min
Black and white abstract image with the word 'ENCRYPTION' prominently displayed.Cybersecurity

FBI Agent Stole $1M in Crypto from Monitored Nation State

An FBI agent used his access to steal $1 million in cryptocurrency from wallets his own national security unit was monitoring, leading to his arrest and a major

Aug 4, 202610 min
Chain-locked book, phone, and laptop symbolizing digital and intellectual security.Cybersecurity

DOJ Seizes Chinese Hackers After 300 Financial Hits

The U.S. Department of Justice seized infrastructure used in a widespread Chinese state hacking campaign that compromised over 300 organizations, including fina

Aug 28, 20266 min
Laptop screen showing 'Proxy provider' in a tech office setting, focus on cybersecurity.Cybersecurity

FBI Seizes Beijing's Private Quartermaster in Cyber Espionage Strike

The FBI seized the core infrastructure of a Chinese company that acted as the quartermaster for state-sponsored hackers, disrupting a vast, centralized system u

Aug 26, 20267 min
Laptop displaying a security lock icon on a table with a potted plant and clock.Cybersecurity

FBI Probes North Korean Infiltration of US Payrolls

The FBI confirms a North Korean operative passed US federal background checks for remote IT work, turning a government paycheck into a sanctioned revenue stream

Aug 13, 20266 min
A modern Sun Belt business district at sunset, featuring a digital tablet displaying a financial interface for commercial banking.Fintech

U.S. Bank Deploys Business Bankers to Sun Belt for First Time

U.S. Bank is launching a direct assault on the Sun Belt, placing business bankers in Florida and Georgia for the first time to win commercial clients without bu

Sep 1, 20269 min
Colorful lines of code on a computer screen showcasing programming and technology focus.Technology

QueryStory Raises $6M to Fix AI's Broken Truth Problem

QueryStory raised $6 million to build an AI reporting tool that proves where its conclusions come from, aiming to solve enterprise trust issues with data audits

Aug 30, 20269 min
Symbolic clash between fintech innovation and legal scales with digital payment streams.Fintech

EarnIn Faces Colorado Lawsuit Tearing Down ‘Non-Loan’ Claim

Colorado's Attorney General is suing EarnIn, directly challenging its legal foundation as a 'non-loan' advance. A win for the state would threaten the legal mod

Sep 3, 20268 min
Futuristic modular steadycam and magnetic action camera hovering in a sleek tech environment.Technology

Hohem Tries to Replace Camera Gimbals and Action Cameras

Hohem's new Eyepic camera combines a stabilized gimbal with a magnetic, detachable action cam module, aiming to replace two separate devices for creators.

Sep 3, 20266 min
Sleek TCL smartphone displays dual OLED and monochrome e-reader modes on an innovative tech surface with holographic circuit overlays.Technology

TCL Phone Transforms from OLED Powerhouse to E Ink

TCL's P80 Ultra phone features a single display that can switch between a high-performance OLED mode and a monochrome, paper-like e-reader mode aimed at maximiz

Sep 3, 20267 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.