
Federal prosecutors have Charged 21-year-old Florida resident and student, Zaire Wilkins, for an alleged scheme to hide cryptocurrency-stealing malware inside video games uploaded to Steam. Once victims downloaded and installed the games, the malware quietly collected passwords and personal data and drained their cryptocurrency wallets. On Tuesday, the FBI arrested Wilkins, and on Wednesday prosecutors charged him and a number of unnamed co-conspirators with hacking crimes.
What really happened on Steam?
According to a federal criminal complaint, Wilkins and his alleged accomplices published numerous games containing malware over a period of approximately two years. Over the past two years, Wilkins and his associates allegedly spread numerous malware-laden video games on Steam, including BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi. Some reports on the broader FBI investigation list additional titles including Chemia, DashFPS, and Tokenova.
The games weren’t broken shells, they were designed to pass as real games. The games are all designed to look legitimate, to the point that players can install and play them, but they all contain malware. This is what made the process effective: victims had no apparent reason to suspect that the game they were playing was scraping their credentials in the background.
How much cryptocurrency was stolen?
The numbers are significant for a scheme run by consumer gaming titles. Using this malware, the FBI says, Wilkins and his associates infected about 8,000 victims, then hacked about 80 cryptocurrency wallets to steal at least $220,000 in cryptocurrency. encryption. The alleged campaign lasted between May 2024 and February 2026.
The affected games were pushed aggressively across social channels. The group promoted games on Discord, Telegram, X and LinkedIn while using bots to identify users with large cryptocurrency holdings and send targeted messages to encourage them to install the games, the FBI said. In other words, the operation did not just wait for random downloads, it appears to have deliberately preyed on holders of high-value cryptocurrencies.
How did the FBI track him down?
This is where the issue becomes almost comical. Investigators traced the money from the scheme’s Bitcoin wallet to gift cards. Investigators put a name to the scheme by tracing stolen bitcoin to more than 150 gift cards, most of which were spent on Uber Eats.
From there, the path led directly to Wilkins’ door. A subpoena to Uber matched the cards by account to deliveries at the Wilkins’ home and addresses at the University of West Florida. When agents searched the North Lauderdale residence, they seized several devices and three cryptocurrency wallet statements, one of which belonged to a Monero wallet. The complaint also notes his cryptocurrency history: Wilkins’ transaction history showed $382,000 in cryptocurrencies sent or received, according to the complaint.
What charges is he facing?
Wilkins was arrested Tuesday and charged with conspiracy to obtain information by computer for private financial gain — a charge punishable by up to ten years in prison. The case is being tried in Seattle, near the headquarters of Valve, which owns Steam, in Washington. It’s the first arrest linked to the FBI’s broader investigation into Steam malware, which the bureau announced last March. Wilkins’ attorney did not comment on the allegations.




