FBI investigates eight Steam games that infected 8,000 devices, stole $220,000

Editorial illustration for: FBI investigates eight Steam games that infected 8,000 devices and stole $220,000 in crypto

In brief

  • FBI seeks victims who downloaded eight malware-infected games from Steam
  • Campaign infected 8,000 devices and compromised roughly 80 crypto wallets, stealing at least $220,000
  • 21-year-old arrested July 14 for financing malware and marketing infected games
  • Bitcoin payments traced to Bitrefill gift cards and Uber Eats deliveries linked to suspect

The malware campaign

The eight games named in the FBI notice are BlockBlasters, Chemia, Dashverse, DashFPS, Lampy, Lunara, PirateFi and Tokenova. The alleged group promoted the games on Discord, Telegram, X, and LinkedIn. Bots identified people with large crypto holdings and sent targeted messages encouraging them to download the infected games.

Once installed, the malware allegedly captured private data and credentials. PirateFi was available on Steam from February 6 to February 12, 2025, and contained the Vidar infostealer, which could steal credentials, session cookies, and crypto wallet information. The group also discussed tricking victims into authorizing transactions that emptied wallets.

Valve's review documentation states that approved games can later be updated without another review, creating a window for attackers to push malicious code after initial approval.

The arrest and the blockchain trail

Zyaire Dontaevious Zamarion Wilkins, age 21, was arrested on July 14 and accused of financing and procuring malware and helping market the infected games. The FBI's investigative path reveals how blockchain transparency cuts both ways for criminals.

Investigators followed Bitcoin payments from a scheme-linked wallet to Bitrefill, an online service used to buy digital gift cards, mostly for Uber Eats. A subpoena to Uber then connected those cards to an account with deliveries to addresses associated with Wilkins. The payments left a traceable on-chain record until they touched an identity-linked service—the moment the blockchain trail intersected with the real world.

"Blockchain transparency did not prevent the thefts, but it allegedly preserved a traceable path until the funds touched an identity-linked service."

For wallet users, the lesson is clear: an official marketplace cannot be the only trust boundary. Custody risk extends upstream, to the software distribution layer and the social channels that promote it. The infected games show how malware can reach victims through channels they trust, making wallet security a downstream problem in a chain of compromises that starts long before the blockchain.

The FBI is accepting reports from victims at ic3.gov.