Overview
- The FBI arrested 21‑year‑old Zyaire Dontaevious Zamarion Wilkins on July 14, 2026, and a federal criminal complaint charges him with running a scheme that embedded info‑stealing malware in multiple Steam titles.
- Authorities estimate about 8,000 PCs were infected, roughly 80 cryptocurrency wallets were compromised, and more than $220,000 in crypto was stolen during the campaign that ran from May 2024 to early 2026.
- The malicious games looked playable but contained code that collected passwords, browser cookies and wallet secrets, allowing attackers to access and drain victims’ crypto accounts.
- Investigators say the operators promoted the games on Discord, Telegram, X and LinkedIn and used bots to target users with large crypto holdings, and then followed stolen funds on‑chain to Bitrefill gift‑card purchases tied to Uber delivery records.
- Independent malware researchers helped reverse‑engineer at least one title (BlockBlasters), victims are urged to report downloads and move funds from any wallet whose secrets were stored on an infected device, and the case highlights gaps in digital storefront update review and endpoint custody security.