GamesGaming NewsHOT

FBI Alleges Steam Malware Campaign Stole More Than $220,000 in Cryptocurrency

Steam users are once again being reminded that even trusted platforms can become targets for cybercriminals. According to a newly unsealed FBI criminal complaint, a Florida man allegedly helped operate a malware campaign that used games published on Steam to infect thousands of computers and steal cryptocurrency from unsuspecting players.

FBI arrests Florida suspect

Federal authorities have arrested 21-year-old Zyaire Dontaevious Zamarion Wilkins of North Lauderdale, Florida. Prosecutors allege that he participated in a conspiracy to distribute malware through Steam games with the goal of stealing cryptocurrency and sensitive account information.

Wilkins currently faces a single charge of conspiracy to obtain computer information for private financial gain. At the time of writing, the case remains at the criminal complaint stage, meaning he has not yet been indicted by a grand jury. As with any criminal case, the allegations have not been proven in court.

Eight Steam games allegedly carried malware

According to investigators, the malware campaign operated between May 2024 and February 2026. During that period, eight different Steam titles allegedly contained malicious software designed to steal credentials and cryptocurrency wallet data.

The publicly identified games include:

  • Dashverse (also known as DashFPS) – May 2024
  • Lunara – November 2024
  • PirateFi – February 2025
  • BlockBlasters – August 2025
  • Lampy – Malicious update released in January 2026

Three additional games were referenced in the complaint but have not been publicly identified. Authorities say those titles have also been removed from Steam.

PirateFi was previously taken down by Valve in February 2025 after security concerns were raised.

Around 8,000 devices reportedly infected

Investigators estimate that the malware infected approximately 8,000 computers. The campaign allegedly compromised around 80 cryptocurrency wallets, resulting in at least $220,000 worth of stolen digital assets.

The malware reportedly focused on collecting passwords, login credentials, and cryptocurrency wallet information before transmitting that data to the attackers.

Cryptocurrency users were specifically targeted

The complaint states that the campaign did not rely solely on Steam for distribution. Instead, the suspects allegedly promoted the infected games across several online communities where cryptocurrency users are active.

Authorities claim the campaign used:

  • Discord
  • Telegram
  • X
  • LinkedIn
  • Automated messaging bots
  • Web3-focused promotions and cryptocurrency-themed advertisements

By targeting users already involved in cryptocurrency, investigators believe the attackers increased their chances of finding valuable wallets to compromise.

FBI outlines Wilkins’ alleged role

According to investigators, Wilkins allegedly operated under the online alias “Sibel.eth.” The complaint claims he helped finance and market the malware operation rather than acting as the developer who uploaded the games.

The FBI also references messages in which Wilkins allegedly discussed purchasing a remote access trojan (RAT) for around $10,000 and conversations about plans to “drain” victims’ cryptocurrency wallets alongside other participants.

Those allegations form part of the evidence supporting the current criminal complaint.

Valve continues to battle malicious uploads

The FBI first revealed this wider investigation in March 2026. Valve actively scans Steam for malicious software and removes harmful games when they are detected. However, this case shows that cyber criminals can still bypass those protections and infect users before Valve identifies and removes the threat.

Steam users should stay cautious when installing newly released games, particularly lesser-known titles with little community feedback. Be especially careful if someone promotes a game through cryptocurrency communities or sends you unsolicited messages on Discord, Telegram, X, LinkedIn, or other social media platforms. Those tactics are common warning signs of scams or malware campaigns, so always verify a game’s legitimacy before downloading it.

Stay cautious when installing unfamiliar games

Steam remains one of the safest PC gaming platforms, no storefront is completely immune to abuse. Players need to avoid downloading games from unsolicited promotions, enable two-factor authentication where possible, keep antivirus software updated, and remain cautious when games request unusual permissions or are heavily promoted through cryptocurrency-related channels.