FBI links Steam malware financier via cookies, Uber Eats, Monero
FBI used Google cookies, phone records, more than 500 Uber Eats orders and a Monero seed phrase to identify and arrest 21-year-old Zyaire Wilkins in a suspected Steam malware financing scheme.
Federal agents arrested 21-year-old Zyaire Dontaevious Zamarion Wilkins in Florida on July 14 and a federal complaint filed the next day charges him with one count of conspiracy to obtain information by computer for private financial gain.
The complaint alleges Wilkins funded and helped market a set of eight malicious games distributed through Steam. Investigators say the campaign infected about 8,000 devices, accessed roughly 80 cryptocurrency wallets and resulted in at least $220,000 in alleged theft.
Prosecutors describe a division of labor in which another participant created developer accounts and uploaded the games while Wilkins supplied launch and marketing funds. The games were promoted on messaging platforms and professional networks, and automated tools were used to identify people with large crypto holdings for targeted messages. Messages included discussions about buying a remote-access trojan and embedding malware in games.
Investigators traced a Bitcoin address shown in messages from an unnamed co-conspirator and verified it received an approximately $10,000 payment on the day it was provided. Payments from that address led to transfers to Bitrefill, a service that sells gift cards for cryptocurrency. Bitrefill records tied those transfers to an account that purchased more than 150 gift cards, including Uber Eats credits.
Records obtained from Google linked the Bitrefill account to other email accounts through browser cookies. One linked account used initials associated with a University of West Florida student account. Another connected account listed a phone number as a recovery option; that number in turn linked to an email containing Wilkins’ name, a Snapchat profile that showed his name, and a mobile carrier account registered to a family address in North Lauderdale.
Uber records for the gift-card account show more than 500 food-delivery orders placed between March 2024 and May 2026, with total spending exceeding $9,000. Every order went to one of three locations: two addresses associated with the University of West Florida and Wilkins’ North Lauderdale family address. The timing of deliveries followed an alleged pattern: orders to the university addresses mostly occurred during academic sessions, while orders outside those windows went to the family address. The complaint notes about 15 deliveries to the North Lauderdale address between May 6 and May 17, 2026. The filing does not assert that every purchase used stolen funds.
FBI agents executed a search warrant at Wilkins’ residence on July 8 and seized laptops, phones and other digital devices along with three cryptocurrency wallet seed phrases. One seed phrase corresponded to a Monero wallet with eight addresses. The filing reports that roughly 1,233 XMR moved through those addresses, a cumulative transaction activity figure the complaint values at about $382,000. The complaint describes that figure as cumulative activity and does not treat it as a current balance or as proof that all funds were stolen.
The identification narrative in the complaint relies on a chain of records from Bitcoin transactions, Bitrefill account data, Google cookies, email accounts, phone records, Snapchat information, Uber data and mobile carrier records. The filing notes investigators used the seized Monero seed phrase rather than tracing Monero on public ledgers to connect the wallet to Wilkins. Wilkins is presumed innocent unless proven guilty.
No response came from Wilkins’ attorney to requests for comment, and Valve did not reply to inquiries about the case and Steam’s security measures.








