Federal agents arrested a 21-year-old Florida man this week for allegedly helping run a scheme that smuggled password- and crypto-stealing malware onto Steam by disguising it as playable video games. Over roughly two years, the operation infected an estimated 8,000 devices, compromised around 80 cryptocurrency wallets, and stole at least $220,000 — and it unraveled because the crew spent its Bitcoin on Uber Eats.

Zyaire Wilkins, of North Lauderdale, was arrested Tuesday and charged the following day with conspiracy to obtain information from a computer for private financial gain. Prosecutors say Wilkins operated under the online alias “Sibel.eth.” He faces up to 10 years in prison if convicted. Multiple accomplices are named but not yet charged; the FBI has interviewed at least one.

Games that were never games

The premise was simple and brutal. Wilkins and his co-conspirators allegedly built or acquired titles that looked like ordinary indie games, pushed them onto Steam, and got them approved for public listing. To a shopper browsing the store, the games looked legitimate — screenshots, a store page, a download button. Under the hood, installing one dropped an infostealer that scraped saved passwords, browser session data, and — the real prize — cryptocurrency wallet credentials off the victim’s machine.

Investigators tie at least eight titles to the scheme, including BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi. The games were promoted across Discord, LinkedIn, and Telegram, funneling gamers and crypto holders toward downloads that quietly emptied their wallets. Because the malware rode inside a “trusted” Steam install rather than a sketchy .exe from a random link, it sailed past the instincts that would normally stop someone from running unknown code.

The BlockBlasters livestream

The scheme’s most public casualty made headlines last September. BlockBlasters was used to drain more than $32,000 from a streamer who was raising money for cancer treatment — live, on air, in front of his audience — as the malware pulled funds out of his wallet mid-broadcast. That single title is estimated to have taken around $150,000 from hundreds of users before it was pulled.

Valve has removed multiple malware-laced games from Steam over the past year as the pattern became clear. PirateFi was one of the earliest publicly flagged cases, yanked from the store after users reported credential theft. But takedowns are reactive: by the time a game is delisted, the installs — and the wallet drains — have already happened.

Followed the money to Uber Eats

The break in the case is the kind of operational-security failure that turns a hard attribution problem into a name and an address. Stolen crypto is pseudonymous on-chain, but it has to become spendable at some point — and this crew cashed out into gift cards.

Agents traced the stolen Bitcoin to more than 150 gift cards, most of them spent on Uber Eats. A subpoena to Uber matched those cards to an account whose food deliveries went to Wilkins’ family home and to addresses associated with him at the University of West Florida. On-chain forensics got investigators to the cash-out; a food-delivery subpoena got them to the door.

The timeline: the FBI publicly confirmed it was investigating malware-embedded Steam games in March 2026. The activity itself is alleged to span May 2024 through February 2026. Wilkins was arrested July 14 and charged July 15.

Why “trusted stores” keep getting weaponized

This case is a clean illustration of a threat that keeps growing: attackers no longer need to trick you into running obviously dangerous files. They compromise the distribution channel you already trust. A malicious game on Steam, a poisoned package on a public registry, a fake app that clears a store review — each borrows the platform’s credibility to disarm the victim.

For crypto holders, the takeaways are practical. Hot wallets sitting on a daily-use machine are one bad install away from being drained; hardware wallets and dedicated devices exist precisely for this. Treat “it’s on Steam” — or any storefront — as a weak signal, not a guarantee. And developers pushing an unusually aggressive, cross-platform marketing campaign for an unknown indie title deserve a second look before you hit install.

For the platforms, the pressure is on review pipelines that clearly let malicious builds through more than once. Post-hoc delisting doesn’t refund a drained wallet.

Wilkins is presumed innocent unless proven guilty. But the investigators’ message is pointed: pseudonymous crypto is not anonymous crypto, and the cash-out is where these schemes die. This one died at an Uber Eats checkout.

Sources