HomeGaming NewsFBI Arrests 21-Year-Old Over $220K Steam Malware Scam

FBI Arrests 21-Year-Old Over $220K Steam Malware Scam

The FBI has arrested a 21-year-old accused of helping run a malware operation that used fake Steam games to steal more than $220,000 in cryptocurrency from unsuspecting players.

Zyaire Dontaevious Zamarion Wilkins, of North Lauderdale, Florida, was taken into custody last week and now faces a federal conspiracy charge for obtaining computer information for private financial gain. This offense can carry up to 10 years in prison. He’s accused of working alongside two unnamed co-conspirators to distribute malware embedded in at least eight indie games on Steam, including BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi.

How the scheme worked

According to the federal complaint, the operation ran from May 2024 through February 2026 and infected roughly 8,000 computers. The malware wasn’t hidden in every version of these games from the start — investigators say the titles were often published clean, built up a base of positive reviews, and then had malicious code slipped in through later updates. That’s a particularly nasty trick, because it means the usual advice of “check the reviews first” doesn’t actually protect you here.
Once installed, the malware quietly harvested passwords, login credentials, and cryptocurrency wallet data in the background, all without any obvious sign something was wrong. Wilkins and his associates reportedly promoted the games on Discord, Telegram, X, and LinkedIn and allegedly used bots to identify users with large crypto holdings to target them directly.
Investigators say the group ultimately compromised around 80 crypto wallets, pulling in at least $220,000. Wilkins himself allegedly didn’t write any of the malware — the FBI says he purchased a remote access Trojan for $10,000 under the dark-web handle “Sibel.eth” and coordinated its distribution, while an unnamed developer who built the actual malware remains unchanged.

The RastalandTV connection

If this story sounds familiar, it’s probably because one of the games named in the complaint, BlockBlasters, is the same title that made headlines last September when it drained $32,000 from Twitch streamer RastalandTV — real name Raivo Plavnieks — live on stream. Plavnieks, who has stage 4 cancer, had been raising funds for treatment through a crypto token when a viewer talked him into downloading the game. The moment he realized what had happened, still on camera, became one of the more painful viral clips of the year, though the crypto community did rally afterward and more than covered his losses through donations.
At the time, researchers estimated BlockBlasters alone was responsible for roughly $150,000 stolen from somewhere between 261 and 478 victims. That figure now appears folded into the broader $220,000 total named in this week’s federal complaint, suggesting investigators eventually connected Plavnieks’ case to the wider operation rather than treating it as an isolated incident.

How the FBI actually caught him

This is the part that reads almost like a plot hole in a heist movie. Investigators traced the stolen bitcoin to more than 150 Bitrefill gift cards, the vast majority of which were spent on Uber Eats orders. That food-delivery trail led straight back to an account allegedly tied to Wilkins’ university email address. Add in Google cookie records, Steam developer account activity, and matching browser and device fingerprints, and the FBI says it had enough to build its case.
It’s a reminder of something security researchers say often and criminals keep ignoring converting stolen crypto into spendable, traceable purchases is usually where these schemes fall apart.

What this means for Steam users

Valve pulled the affected games from the store once the malware was identified, but by then the damage was done for thousands of players. If you have any of the named titles in your Steam library or purchase history between May 2024 and February 2026, it’s worth treating that machine as potentially compromised — running a full malware scan and changing passwords for any accounts, especially crypto wallets, that were logged in on that device.
This isn’t an isolated Steam problem, either. If you’re trying to get a sense of how exposed indie storefronts really are right now, our breakdown of what Ubisoft is doing differently with its own digital storefront security is a useful contrast, and it’s worth keeping an eye on how publishers handle platform trust generally heading into gamescom 2026, where storefront security is likely to come up given how much attention this case has drawn.
Wilkins is due in federal court in Fort Lauderdale, and the FBI says the investigation is ongoing — meaning the two unnamed co-conspirators, including whoever actually wrote the malware, could still face charges. For now, this case is a fairly stark reminder that “verified” storefront status doesn’t mean a game is safe forever. A clean launch and good reviews can still turn into a trap a few updates later.
RELATED ARTICLES

Most Popular

Recent Comments