Federal prosecutors have charged 21-year-old Zyaire Wilkins in connection with a scheme that allegedly funded crypto-stealing malware hidden in eight Steam games. A 15-page federal criminal complaint says Wilkins was arrested in Florida on July 14.
According to the complaint cited in the source material, the malware campaign ran from May 2024 through February 2026. The infected titles allegedly hit about 8,000 devices, opened around 80 crypto wallets, and caused at least $220,000 in confirmed victim losses.
The FBI did not identify the suspect by defeating Monero’s privacy protections on-chain. Investigators instead pieced together a trail that included Bitrefill gift cards, more than 500 Uber Eats deliveries, and three wallet seed phrases seized during a search.
Eight Steam games allegedly carried the same remote-access trojan
The source says a cancer-stricken streamer had a wallet drained while playing a Steam game called BlockBlasters during a livestream in September 2025, prompting Valve to remove the title. At that stage, the destination of the stolen funds was still unclear.
The complaint now names BlockBlasters, Dashverse, Lampy, Lunara, PirateFi, and three other Steam titles as part of the same operation. Prosecutors say each game carried the same remote-access trojan.
Under the division of roles described in the complaint, an unnamed Subject #1 allegedly handled developer account applications and game submissions to Steam. Wilkins is accused of providing the funding. The filing says he spent about $10,000 in bitcoin to buy the malware, then paid listing and marketing costs in exchange for a share of the proceeds and access to victims’ personal information.
The source says the campaign was marketed through Discord, Telegram, X, and LinkedIn, with bots targeting users believed to have larger holdings.
Gift cards and food delivery orders became the investigative trail
Investigators say the first major stop for the stolen funds was Bitrefill, a platform that lets users buy gift cards with cryptocurrency. More than 150 gift cards were traced through the service, according to the source.
From there, agents followed linked email accounts and browser cookies, identifying several addresses that included Wilkins’ initials. The trail then led to T-Mobile subscriber data, a Snapchat account that had at one point displayed his real name, and a residence in North Lauderdale, Florida, where family members lived.
The source says that between May 6 and May 17, 2026, roughly 15 food deliveries arrived at that North Lauderdale home. Those orders were paid with gift cards, and the gift cards had been purchased with bitcoin tied to 80 compromised wallets.
On a wider timeline, the FBI reviewed more than 500 Uber Eats orders placed between March 2024 and May 2026, with spending of more than $9,000 across three delivery addresses. Agents compared delivery times with the University of West Florida academic calendar and found a pattern: orders went to school during the term and back home during breaks.
Monero itself was not cracked; the seed phrase was seized
The source notes that Wilkins appeared familiar with privacy-focused crypto tools. Agents found a Monero wallet seed phrase at the residence. Monero is widely known for obscuring transaction amounts, sender and receiver addresses, and counterparties.
That privacy model stopped mattering once agents executed a search warrant on July 8 and seized a laptop, a phone, and three crypto wallet seed phrases, including the Monero wallet phrase. With the seed phrase in hand, investigators were able to open the wallet directly.
According to the source, the wallet exposed records tied to eight addresses with total activity of 1,233 XMR, worth about $382,000 at current prices. The report also says that figure was counted separately from the at least $220,000 in confirmed victim losses listed in the complaint.
The source explicitly says the complaint does not claim that all 500-plus food delivery orders, or every payment tied to them, came from stolen funds.
Current charge and responses
Wilkins currently faces one count of conspiracy to obtain information from a protected computer for private financial gain. He is presumed innocent unless convicted.
As of publication in the source material, Wilkins’ lawyer had not responded to media inquiries, and Valve had not commented.
Key case details
- Suspect: 21-year-old Zyaire Wilkins, arrested in Florida on July 14.
- Games named: BlockBlasters, Dashverse, Lampy, Lunara, PirateFi, and three other Steam titles.
- Period cited: May 2024 to February 2026.
- Impact: about 8,000 devices infected and around 80 crypto wallets opened.
- Confirmed losses: at least $220,000.
- Investigative trail: Bitrefill gift cards, browser cookies, T-Mobile records, a Snapchat account, more than 500 Uber Eats orders, and three wallet seed phrases.
- Monero wallet activity: eight addresses and 1,233 XMR, valued at about $382,000 at current prices.

