A Florida man has been arrested following a federal criminal complaint alleging that he participated in a conspiracy to infect Steam users with malware and consequently steal from them. Authorities believe the attacker was not working alone and has stolen at least $220,000 worth of cryptocurrency from thousands of Steam users.
Although Valve has robust, largely automated safeguards for policing malicious code on its platform, malware remains a perpetual game of cat and mouse. Every so often, a Steam game or mod is discovered to have distributed malware after reaching users. The latest such case comes from North Lauderdale, Florida, where the FBI recently arrested 21-year-old Zyaire Dontaevious Zamarion Wilkins on one count of conspiracy to obtain computer information for private financial gain.
FBI Says Steam Malware Scheme Infected 8,000 Devices
According to a 15-page federal complaint filed July 15, 2026, the FBI believes that Wilkins and several known and unknown co-conspirators launched eight malware-embedded games between May 2024 and February 2026. Investigators estimate that approximately 8,000 devices were infected, allowing the conspirators to access around 80 cryptocurrency wallets and steal digital assets worth at least $220,000. The complaint identifies five of the allegedly compromised games as Dashverse, Lunara, PirateFi, BlockBlasters, and Lampy. The other three titles used in the scheme are not named outright but are reportedly no longer available on Valve’s storefront.
Infected Games Allegedly Used in the Latest Steam Malware Scheme
- Dashverse (AKA DashFPS; released May 2024)
- Lunara (released November 2024)
- PirateFi (released February 2025)
- BlockBlasters (released August 2025)
- Lampy (received malicious update in January 2026)
The infected Steam games were allegedly promoted through Discord and Telegram, as well as social networks such as X and LinkedIn. The conspirators also reportedly used automated bots to identify people with substantial cryptocurrency holdings and send them targeted messages. Some titles, including Dashverse, advertised Web3 features, suggesting the attackers were trying to make their ideal victims (people already interested in blockchain technology, therefore more likely to hold cryptocurrency) come to them. Once installed, the malicious games allegedly exfiltrated passwords and other data needed to access victims’ cryptocurrency wallets, according to the July 2026 complaint.
According to the filing, Wilkins operated under the name “Sibel.eth” and allegedly helped finance, acquire, and market the malware rather than developing or uploading the infected games himself. Messages recovered from an unnamed co-conspirator’s devices purportedly show the pair discussing a $10,000 investment in a remote access trojan, ways to increase downloads, and campaigns intended to “drain” cryptocurrency wallets. One title named in the complaint, PirateFi, was removed from Steam in February 2025 after Valve warned affected users that its developer had uploaded builds containing suspected malware.
The July complaint is connected to a broader FBI investigation into Steam-distributed malware that was first disclosed in March 2026. At the time, federal investigators specifically identified Lunara, PirateFi, and Dashverse as titles under scrutiny. The new filing indicates that authorities already had probable cause to connect Wilkins to some of the malware identified during that investigation, although he was not named in federal court documents until July. Wilkins was charged via a federal criminal complaint but had not yet been indicted by a federal grand jury as of July 25, 2026.
Source: Eurogamer








