TL;DR
- Federal prosecutors say malware hidden inside games listed on Steam infected about 8,000 devices, accessed around 80 crypto wallets, and stole at least $220,000.
- Investigators say the games looked legitimate, helping the malware spread through titles promoted across major social and messaging platforms.
- The case follows earlier public reporting on BlockBlasters and may mark the first arrest to emerge from the FBI’s broader Steam malware investigation.
Federal agents have arrested a Florida man accused of helping distribute malware through playable games linked to Steam, a popular PC game distribution platform. The alleged operation infected about 8,000 devices, accessed around 80 crypto wallets and stole at least $220,000, according to a federal complaint.
The filing states the malicious games gave the malware access to passwords, account data and crypto wallets on infected devices. Steam itself didn’t suffer any breach.
Playable games allegedly concealed the malware
Agents arrested 21-year-old Zyaire Dontaevious Zamarion Wilkins, of North Lauderdale, Florida, on July 14. Prosecutors filed the criminal complaint in Washington state the following day. They accused Wilkins of conspiracy to obtain computer information for private financial gain.
The complaint does not name Steam directly, but refers to a popular digital distribution software company. Steam has been identified through contextual details, including the games named in the filing and the location of the case in the Western District of Washington, near Valve’s headquarters in Bellevue.
The filing says Wilkins worked with unnamed co-conspirators between approximately May 2024 and February 2026. They allegedly launched and marketed eight games containing malicious software.
>>> Read more: Microsoft Warns of Crypto Clipper Malware Spreading via USB
How the games gained trust
The FBI’s victim-information page identifies BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi and Tokenova. Investigators say the group promoted the games through Discord, Telegram, X and LinkedIn.
The distribution strategy helped the malware blend in. The attackers used Steam’s reputation as a familiar place to download games, then promoted the titles on established social and messaging platforms. The installed software looked and behaved like normal games, which gave users little reason to suspect it also contained malware.
BlockBlasters had already drawn public scrutiny before Wilkins was charged. In September 2025, independent researchers ZachXBT and vx-underground publicly linked that game to malware when a Twitch streamer raising money for cancer treatment lost roughly $32,000 during a livestream. Researchers tied that episode to more than $150,000 in estimated losses from BlockBlasters at the time.
Valve had already removed several of the flagged titles after they were identified post-launch. PirateFi was taken down in February 2025, followed by a malicious demo for Sniper: Phantom’s Resolution in March 2025, and later by Chemia and BlockBlasters in 2025. Valve has not responded to media requests for comment on that pattern, including on the Wilkins case specifically.
That exposure appears to have overlapped with the FBI Seattle field office’s public investigation into malware on Steam, announced in March 2026. This investigation also named BlockBlasters among the games under review. The July complaint appears to be the first arrest to emerge from that investigation.
The complaint alleges at least $220,000 in losses across the broader case. However, the document does not establish whether the losses reported in September 2025 are included or separate from that total.
Investigators followed the crypto spending trail
Authorities estimate that the malware reached about 8,000 devices. From those, an estimated 80 users suffered losses from their crypto wallets. Hence, not every infection led to cryptocurrency losses.
This investigation into the malware circulating on Steam also shows how blockchain activity can connect other online activities directly to an individual. For example, agents obtained a wallet address from messages involving an alleged co-conspirator. They then traced spending from that address to Bitrefill, a service that sells gift cards for cryptocurrency.
The associated account had purchased more than 150 gift cards, including Uber Eats vouchers. Investigators then obtained account information from Uber and used it to identify a phone number and delivery address connected to Wilkins, according to the complaint.
>>> Read more: Crypto Investor Loses $6.9M in Douyin Cold Wallet Scam
The charges leave major questions open
The identities of the alleged co-conspirators remain undisclosed. Authorities also have not announced any recovery of the stolen cryptocurrency. The final loss could well exceed $220,000 if more victims come forward.
The FBI is now seeking information from people who downloaded the listed titles between May 2024 and January 2026. Its form asks about account compromises, missing funds, wallet addresses and transaction records. Consequently, reporting those details could help investigators identify additional victims and trace further transfers.








