FBI traced alleged Steam malware funder through Uber Eats orders and seized wallet seed phrases

FBI traced alleged Steam malware funder through Uber Eats orders and seized wallet seed phrases

N
News Editor
2026-07-25 03:07:06
Federal prosecutors have accused 21-year-old Zyaire Wilkins of helping fund a scheme that placed crypto-stealing malware inside eight games distributed on Steam, according to a 15-page criminal complaint cited by BlockTempo. Wilkins was arrested in Florida on July 14. Investigators say the campaign ran from May 2024 to February 2026, infected about 8,000 devices, opened roughly 80 crypto wallets, and caused at least $220,000 in confirmed losses. The case stands out because investigators did not break Monero’s privacy model to identify the suspect. Instead, the FBI followed a trail that moved from stolen-wallet bitcoin to Bitrefill gift cards, then to more than 500 Uber Eats orders worth over $9,000 sent to three addresses. The complaint also says agents connected browser cookies, email accounts carrying Wilkins’ initials, T-Mobile subscriber data, a Snapchat account that had used his real name, and a family residence in North Lauderdale, Florida. When agents executed a search warrant on July 8, they seized a laptop, a phone, and three wallet seed phrases, including one for a Monero wallet. According to the report, that wallet exposed activity across eight addresses totaling 1,233 XMR, valued at about $382,000 at current prices. Prosecutors have charged Wilkins with one count of conspiracy to obtain information from a protected computer for private financial gain. He is presumed innocent unless convicted.
SteamMoneroFBImalwarecrypto walletsBitrefillUber Eats

Federal prosecutors have charged 21-year-old Zyaire Wilkins in connection with a scheme that allegedly funded crypto-stealing malware hidden in eight Steam games. A 15-page federal criminal complaint says Wilkins was arrested in Florida on July 14.

According to the complaint cited in the source material, the malware campaign ran from May 2024 through February 2026. The infected titles allegedly hit about 8,000 devices, opened around 80 crypto wallets, and caused at least $220,000 in confirmed victim losses.

The FBI did not identify the suspect by defeating Monero’s privacy protections on-chain. Investigators instead pieced together a trail that included Bitrefill gift cards, more than 500 Uber Eats deliveries, and three wallet seed phrases seized during a search.

Eight Steam games allegedly carried the same remote-access trojan

The source says a cancer-stricken streamer had a wallet drained while playing a Steam game called BlockBlasters during a livestream in September 2025, prompting Valve to remove the title. At that stage, the destination of the stolen funds was still unclear.

The complaint now names BlockBlasters, Dashverse, Lampy, Lunara, PirateFi, and three other Steam titles as part of the same operation. Prosecutors say each game carried the same remote-access trojan.

Under the division of roles described in the complaint, an unnamed Subject #1 allegedly handled developer account applications and game submissions to Steam. Wilkins is accused of providing the funding. The filing says he spent about $10,000 in bitcoin to buy the malware, then paid listing and marketing costs in exchange for a share of the proceeds and access to victims’ personal information.

The source says the campaign was marketed through Discord, Telegram, X, and LinkedIn, with bots targeting users believed to have larger holdings.

Gift cards and food delivery orders became the investigative trail

Investigators say the first major stop for the stolen funds was Bitrefill, a platform that lets users buy gift cards with cryptocurrency. More than 150 gift cards were traced through the service, according to the source.

From there, agents followed linked email accounts and browser cookies, identifying several addresses that included Wilkins’ initials. The trail then led to T-Mobile subscriber data, a Snapchat account that had at one point displayed his real name, and a residence in North Lauderdale, Florida, where family members lived.

The source says that between May 6 and May 17, 2026, roughly 15 food deliveries arrived at that North Lauderdale home. Those orders were paid with gift cards, and the gift cards had been purchased with bitcoin tied to 80 compromised wallets.

On a wider timeline, the FBI reviewed more than 500 Uber Eats orders placed between March 2024 and May 2026, with spending of more than $9,000 across three delivery addresses. Agents compared delivery times with the University of West Florida academic calendar and found a pattern: orders went to school during the term and back home during breaks.

Monero itself was not cracked; the seed phrase was seized

The source notes that Wilkins appeared familiar with privacy-focused crypto tools. Agents found a Monero wallet seed phrase at the residence. Monero is widely known for obscuring transaction amounts, sender and receiver addresses, and counterparties.

That privacy model stopped mattering once agents executed a search warrant on July 8 and seized a laptop, a phone, and three crypto wallet seed phrases, including the Monero wallet phrase. With the seed phrase in hand, investigators were able to open the wallet directly.

According to the source, the wallet exposed records tied to eight addresses with total activity of 1,233 XMR, worth about $382,000 at current prices. The report also says that figure was counted separately from the at least $220,000 in confirmed victim losses listed in the complaint.

The source explicitly says the complaint does not claim that all 500-plus food delivery orders, or every payment tied to them, came from stolen funds.

Current charge and responses

Wilkins currently faces one count of conspiracy to obtain information from a protected computer for private financial gain. He is presumed innocent unless convicted.

As of publication in the source material, Wilkins’ lawyer had not responded to media inquiries, and Valve had not commented.

Key case details

  • Suspect: 21-year-old Zyaire Wilkins, arrested in Florida on July 14.
  • Games named: BlockBlasters, Dashverse, Lampy, Lunara, PirateFi, and three other Steam titles.
  • Period cited: May 2024 to February 2026.
  • Impact: about 8,000 devices infected and around 80 crypto wallets opened.
  • Confirmed losses: at least $220,000.
  • Investigative trail: Bitrefill gift cards, browser cookies, T-Mobile records, a Snapchat account, more than 500 Uber Eats orders, and three wallet seed phrases.
  • Monero wallet activity: eight addresses and 1,233 XMR, valued at about $382,000 at current prices.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
800

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.