Federal investigators have arrested a 21-year-old Florida man accused of helping fund an infostealer campaign that was distributed through eight games on Steam. Prosecutors allege the operation compromised about 8,000 computers and siphoned hundreds of thousands of dollars in cryptocurrency over nearly two years.
How the malware spread
According to the case described by federal authorities, the malicious software was embedded in eight titles released on Steam: BlockBlasters, Dashverse, Lunara, PirateFi, Chemia, Lampy, DashFPS, and Tokenova. Steam later removed the games in early 2026.
The games were able to pass the platform’s initial review process before turning harmful later. Investigators say the malware was introduced through post-launch updates, allowing the titles to bypass early checks and then deliver the payload after they were already available to users. Bitdefender had described the affected releases as indie games on Steam that carried malware.
What prosecutors say the malware did
The software is described as an infostealer, a type of malware designed to quietly extract sensitive data from infected machines. In this case, authorities say it collected saved passwords, active session tokens, and data from cryptocurrency wallets while users were playing.
Federal prosecutors allege that the campaign ran from May 2024 through February 2026. During that period, roughly 8,000 PCs were infected. The short-term objective was credential and wallet theft, but investigators say the broader result was the draining of substantial crypto holdings from victims.
Tracing the operation
Investigators say victims were not chosen at random. Bots allegedly identified wallets holding larger balances, and targets were then steered toward the infected game downloads through direct messages sent on Discord, Telegram, X, and LinkedIn.
Authorities traced around $382,000 in cryptocurrency flows through wallets linked to Zyaire Wilkins of North Lauderdale, Florida, according to the source report. The arrest follows an FBI investigation into the financing behind the malware campaign rather than just its distribution on Steam.
Charges and possible penalty
Wilkins has been charged with conspiracy to obtain information by computer for private financial gain. That charge carries a potential prison sentence of up to 10 years. The source report said his court date was July 15.
The case highlights a growing risk in game marketplaces where software may appear legitimate at launch but later change through updates. In this instance, the allegation is not that Steam’s review directly approved malware at the outset, but that malicious code was pushed after the games had already cleared initial screening and reached players.
Source: Cryptopolitan