The FBI has arrested a 21-year-old accused of orchestrating one of the most curious malware campaigns of recent years: hiding malicious programs inside seemingly harmless video games published on Steam. According to the federal complaint, the operation compromised about 8,000 computers worldwide and enabled the theft of at least $220,000 in cryptocurrencies from about 80 digital wallets.
Fake games, real malware
Between May 2024 and February 2026, the accused — identified as Zyaire Wilkins — and several collaborators published and promoted on Valve’s store a series of titles with a legitimate appearance: PirateFi, Dashverse, Lunara, BlockBlasters, Lampy, Chemia and Tokenova. None was a real game: they were disguised Trojan horses, designed to run an info stealer as soon as they were installed.
The distribution strategy was especially twisted. Instead of relying on people finding the games by chance, the cybercriminals spread them actively through channels such as Discord, Telegram, LinkedIn and even X, focusing on users who boasted of holding significant amounts of cryptocurrency. Once the malware was installed, it collected credentials and other sensitive information to later gain access to the victims’ digital wallets.
The case of the streamer who lost everything
Among those affected is the streamer RastalandTV, who lost about $35,000 raised by his community for a cancer treatment. The case illustrates to what extent these campaigns do not distinguish between big targets and ordinary users: anyone with a digital wallet and a bit of trust in the store could fall into the trap.
The mistake that dismantled the perfect heist
The operation collapsed because of an oversight that proves that, in cybersecurity, the weakest link is usually the human factor. FBI investigators traced part of the stolen cryptocurrency to the purchase of more than 150 Bitrefill gift cards, many of them destined for Uber Eats orders. Those purchases ended up being linked to personal accounts, a phone number and an email address associated with the suspect, which allowed reconstructing the complete trail of the stolen money.
The subsequent search of the young man’s home allowed agents to seize several electronic devices that, according to the accusation, contained evidence of the operation and conversations between those involved. Wilkins now faces charges related to computer crimes, while the authorities continue pulling the thread to locate the rest of the network’s members.
A known problem on Steam
It is not the first time Valve’s platform has been tainted by this kind of incident. In February 2025, Steam had to remove PirateFi, the same title that now appears in the complaint, after it was discovered that it was infected with the info stealer known as Vidar. The game was available for almost a week and recorded between 800 and 1,500 downloads before being removed.
The FBI, for its part, has enabled a section on its website to identify potential victims who installed these titles, as well as a form to collect information relevant to the investigation. The agency’s Seattle division is in charge of coordinating the case.
What we can learn
Although cases like this remain extraordinarily rare, they show that no digital platform is completely safe from malicious actors bypassing its controls. Even a small, seemingly innocuous indie video game can become a Trojan horse for a sophisticated campaign.
The practical lessons are simple but important. First, download software only from trusted developers: on Steam, it is worth reviewing the studio’s history, the account’s age and the ratings before installing anything. Second, be wary of links arriving through Discord, Telegram or social networks inviting you to try a new game, no matter how attractive the offer seems. And third, keep cryptocurrency wallets protected with two-factor authentication and do not store private keys on the same computer where you install software of dubious origin.
The case also leaves a reflection on the digital trail: no matter how much care is put into hiding the origin of a theft, money always leaves a trace. In this case, it was some gift cards and some food delivery orders that gave away an entire cybercriminal.






