Florida Man Arrested in $220,000 Steam Malware and Cryptocurrency Theft Scheme
Federal authorities charge a Florida resident with distributing malware disguised as PC video games to drain digital wallets.
Federal authorities in Florida have arrested a 21-year-old man accused of orchestrating a sophisticated cybercrime ring that infected thousands of computers with malware disguised as video games to drain cryptocurrency wallets.
The suspect, identified by the Federal Bureau of Investigation as Zyaire Dontaevious Zamarion Wilkins, faces multiple federal charges after allegedly leading a nearly two-year campaign that compromised approximately 8,000 computers. According to investigators, the scheme successfully drained at least $220,000 from roughly 80 cryptocurrency wallets between May 2024 and February 2026.
The malicious software was hidden inside at least eight titles, including BlockBlasters, Dashverse, Lunara, and PirateFi, which were available on the popular PC gaming storefront Steam before being removed. While Valve officially banned applications built on blockchain technology or issuing cryptocurrency from its platform in late 2021, bad actors have increasingly attempted to smuggle malicious software onto mainstream gaming platforms under the guise of legitimate indie titles.
According to the federal complaint, Wilkins and his co-conspirators used automated bots on social media and messaging platforms—including Discord, Telegram, X, and LinkedIn—to identify and target individuals with substantial cryptocurrency holdings. Once a victim was lured into downloading one of the compromised games, a remote access trojan extracted passwords and sensitive credentials, allowing the group to access and drain online accounts.
Despite the digital sophistication of the malware, investigators tracked the stolen funds through a surprisingly mundane paper trail. The FBI traced the stolen bitcoin to more than 150 Bitrefill gift cards, which were primarily used to purchase Uber Eats deliveries.
Independent blockchain researchers, including ZachXBT and the online malware repository vx-underground, noted that a single title, BlockBlasters, was responsible for roughly $150,000 of the stolen funds. Among the victims was Twitch streamer RastalandTV, who lost $32,000 in viewer donations intended to fund cancer treatment.
Law enforcement identified Wilkins through encrypted Signal chats recovered from an unnamed developer suspected of writing the malware. The messages revealed that Wilkins, operating under the dark web moniker Sibel.eth, purchased a $10,000 remote access trojan and discussed strategies for deceiving victims into authorizing fraudulent transactions. The suspected developer has not been publicly identified or formally charged.









