A 21-year-old Florida resident, Zayar Wilkins, has been arrested by the FBI for allegedly operating a two-year scheme that distributed malware disguised as legitimate video games on the Steam platform. According to federal prosecutors cited by TechCrunch, Wilkins and his accomplices embedded malicious software within games to covertly siphon cryptocurrency and sensitive personal data from unsuspecting players.
The criminal complaint highlights several titles used in the operation: BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi. Once downloaded, these games deployed a virus that harvested user passwords, exfiltrated private data, and compromised digital wallets. Investigators estimate the scheme infected roughly 8,000 devices and breached around 80 cryptocurrency wallets, resulting in the theft of at least $220,000.
To lure victims, Wilkins and his team actively marketed the malicious titles across various online communication networks – including Discord, LinkedIn, and Telegram.
Valve, the parent company of Steam, took action over the past year by removing several of the fraudulent titles from its storefront, including PirateFi and BlockBlasters – the latter alone accounting for over $150,000 in stolen funds. Although these applications functioned as complete, fully playable video games, they served as a front for harvesting user information.
This arrest follows a public alert issued by the FBI back in March, when the bureau disclosed its ongoing investigation into a hacker embedding malicious code into Steam games and urged victims to come forward with evidence.
The prosecution’s case gained significant momentum when one of the co-conspirators agreed to cooperate with federal law enforcement. This individual detailed how the group pooled financial resources to launch and market the games in exchange for a percentage of the stolen digital currency.
A breakthrough in the investigation occurred when the FBI tracked a specific cryptocurrency account tied to the operation that was used to purchase gift cards, specifically for UberEats. Data obtained from Uber subsequently linked these transactions to a user account that ordered deliveries directly to Wilkins’ home address.
Federal agents later executed a search warrant at the suspect’s residence, seizing a MacBook, multiple mobile phones, other digital devices, and hardware cryptocurrency wallets. Upon his arrest, Wilkins chose to remain silent and refused to provide any explanations to the investigators.

