Eight indie games sat on Steam looking perfectly normal. Players would launch one, grind through a few rounds, maybe leave a review. Meanwhile, an infostealer — malware designed to quietly harvest passwords, session tokens, and crypto wallet data — stripped credentials without a single lag spike or crash. The FBI arrested Zyaire Dontaevious Zamarion Wilkins, 21, of North Lauderdale, Florida, accusing him of financing and marketing malware embedded across at least eight Steam titles that infected roughly 8,000 PCs between May 2024 and February 2026, according to a federal complaint reported by WPLG Local 10.
How Eight Fake Games Drained 80 Crypto Wallets
The operation combined clean initial submissions, malicious post-launch updates, and targeted DMs to reach high-value victims.
- Named titles include BlockBlasters, Dashverse, Lunara, PirateFi, Chemia, Lampy, DashFPS, and Tokenova — all removed from Steam in early 2026
- Some games passed platform review clean, then received updates injecting the infostealer after install
- Bots identified high-value crypto holders; targeted DMs via Discord, Telegram, X, and LinkedIn, and funneled them toward infected games
- BlockBlasters alone enabled theft of over $150,000 from an estimated 261–478 victims, according to forensic researcher ZachXBT and malware repository vx-underground
Twitch streamer RastalandTV lost roughly $32,000 in September 2025 — donations from viewers helping cover cancer treatment costs. That detail alone turned a cybercrime case into something that spread fast across gaming communities.
Wilkins didn’t write the code. Per the FBI complaint, he purchased a $10,000 remote access Trojan under the dark-web handle “Sibel.eth” and coordinated distribution with an unnamed primary developer who remains uncharged.
“Indie games distributed through Steam harbored malware inside… dangerous software that ran silently in the background.” — Bitdefender
The scheme then collapsed with almost comedic precision. The conspirators converted stolen crypto into over 150 Bitrefill gift cards and spent most on Uber Eats orders — the digital equivalent of pulling off a heist and leaving a delivery receipt on the vault floor. That consumer trail linked an Uber Eats account directly to Wilkins, whose on-chain activity showed roughly $382,000 in cryptocurrency flowing through his wallets, per the FBI complaint.
What Steam Users Should Do Right Now
If any named title appears in your Steam purchase history from May 2024 through early 2026, treat that machine as compromised.
Wilkins faces conspiracy to obtain information by computer for private financial gain — up to 10 years in prison. His court appearance was scheduled for July 15. Check your Steam library now. Run a full antimalware scan from a clean device, reset every password and session token, and — for PirateFi specifically — security researchers recommend a complete OS reinstall, according to PCMag. If crypto lives on the same machine used for gaming, that setup deserves serious reconsideration. Hardware wallets exist for exactly this reason.
Two years. That’s how long infected games allegedly sat on the world’s largest PC gaming storefront, some slipping through by submitting clean builds before pushing malicious updates — a tactic that bypasses initial review entirely. Steam’s storefront listing is supposed to signal safety. This case proves that signal means nothing when malicious updates slip past review. The most dangerous malware doesn’t announce itself. It just runs the game, collects the credentials, and orders dinner.





























