Malware in Eight Steam Games Stole $220K in Crypto
FBI: eight Steam games infected about 8,000 devices and led to at least $220,000 stolen from about 80 crypto wallets; investigators traced Bitcoin to Bitrefill gift cards and Uber Eats deliveries.
According to a federal complaint and an FBI notice, eight games distributed on the Steam platform infected about 8,000 devices between May 2024 and January 2026, with related activity alleged through February 2026. Investigators say the campaign resulted in unauthorized access to roughly 80 cryptocurrency wallets and at least $220,000 in losses.
The FBI identified the titles as BlockBlasters, Chemia, Dashverse, DashFPS, Lampy, Lunara, PirateFi and Tokenova. Authorities allege 21-year-old Zyaire Dontaevious Zamarion Wilkins financed and helped market the infected games; he was arrested on July 14 and is presumed innocent unless convicted.
The complaint states the games were promoted on messaging platforms including Discord, Telegram, X and LinkedIn. Automated accounts reportedly scanned for users with large cryptocurrency holdings and sent targeted messages encouraging them to download the games.
Once installed, the software allegedly harvested private data and credentials from infected machines and captured authenticated sessions, creating opportunities to access wallets and approve transfers. A February 2025 advisory noted that PirateFi, available on Steam from Feb. 6 to Feb. 12, 2025, contained the Vidar infostealer, malware designed to extract credentials, session cookies and wallet information. The complaint describes alleged efforts to trick victims into authorizing transactions that emptied accounts.
Investigators traced Bitcoin payments on-chain to purchases made through Bitrefill, a service that converts cryptocurrency to digital gift cards. More than 150 gift cards were purchased, mostly for Uber Eats. A subpoena to the delivery service linked those cards to an account that made deliveries to addresses associated with Wilkins, according to the complaint. The FBI said blockchain records provided a traceable path until the funds reached an identity-linked service.
The documents note that Steam’s developer process includes checks for harmful behavior on initial builds but allows approved games to be updated without a full re-review. The complaint does not specify how the allegedly infected games bypassed platform controls.
The FBI is asking anyone who downloaded any of the eight titles to contact investigators. Wilkins faces charges alleging he procured and financed malware and helped market the infected software.








