Downloading a free video game isn’t something most people associate with losing their life savings. But federal prosecutors say that’s exactly what happened to dozens of cryptocurrency holders after they unknowingly installed malware disguised as legitimate games.
Authorities have arrested a 21-year-old Florida man accused of helping operate a scheme that allegedly stole more than $220,000 in cryptocurrency from victims who downloaded infected games distributed through Steam, Valve’s popular PC gaming platform. According to court documents, the operation infected about 8,000 devices and compromised at least 80 cryptocurrency wallets.
The case highlights a growing threat for gamers and crypto investors alike: malware hidden inside seemingly harmless software that can quietly search a computer for passwords, wallet credentials and other sensitive financial information.
Thanks for subscribing!
The money news that actually matters.
By signing up, you accept Moneywise Terms of Use, Subscription Agreement, and Privacy Policy.
How the alleged Steam malware scheme worked
Prosecutors allege Zyaire Wilkins, 21, worked with co-conspirators to develop and promote at least eight malware-infected games between May 2024 and February 2026. The titles named by the FBI include BlockBlasters, Chemia, Dashverse (also known as DashFPS), Lampy, Lunara, PirateFi and Tokenova.
The 15-page court complaint alleges the group promoted the games across Discord, Telegram, X and LinkedIn, encouraging users to download them. Once installed, prosecutors say the malware searched victims’ computers for sensitive information that could be used to access cryptocurrency wallets before draining digital assets.
Some of the games had already attracted attention before the arrest. Earlier this year, Valve removed several titles from Steam after reports that they contained malware. One game, BlockBlasters, was reportedly linked to more than $150,000 in stolen cryptocurrency, including funds belonging to a streamer who was raising money for cancer treatment.
Federal investigators say they identified Wilkins by tracing cryptocurrency transactions tied to an alleged co-conspirator. According to the complaint, investigators linked a crypto wallet to a Bitrefill account used to purchase more than 150 gift cards, including Uber Eats gift cards. Those purchases allegedly helped investigators identify a phone number and eventually an address connected to Wilkins.
Wilkins was arrested July 14 and charged with conspiracy to obtain information by computer for private financial gain. As with any criminal case, the allegations remain accusations, and Wilkins is presumed innocent unless proven guilty in court.
Must Read
- Jeff Bezos backs a platform that lets anyone invest in rental homes for as little as $100 — 6 ways to build wealth like a landlord without actually being one
- The tax breaks in Trump's 'big beautiful bill' expire after 2028. Here are 4 moves to make before the window closes
How to protect yourself from malware disguised as games
While this case focuses on cryptocurrency, many types of malware are designed to steal a much wider range of personal and financial information.
You can reduce your risk by:
- Download software only from trusted developers and verify publishers before installing new programs.
- Be skeptical of links shared through Discord, Telegram and other messaging platforms, especially if they promise exclusive game access or early releases.
- Keep your operating system, antivirus software and applications up to date so known vulnerabilities are patched.
- Enable multi-factor authentication whenever possible, including on cryptocurrency exchanges and email accounts.
- Never store cryptocurrency recovery phrases or private keys in plain text on your computer. Instead, consider using a hardware wallet or another secure offline storage method for significant holdings.
The FBI’s Internet Crime Complaint Center says investment and cryptocurrency-related fraud remains one of the fastest-growing categories of cybercrime, with Americans reporting billions of dollars in losses each year.
Cases like the alleged Steam malware operation are a reminder that scammers don’t always target victims through fake emails or phone calls.
Sometimes they hide inside software that looks like entertainment.
You May Also Like
- Dave Ramsey warns nearly 50% of Americans are making 1 big Social Security mistake — here’s what it is and 3 simple steps to fix it ASAP
- A single line on your car insurance policy could be inflating your premium by up to 30% — here's what to change
Clay Halton is a Contributing Editor at Moneywise, covering a wide range of consumer-focused financial stories. He has over eight years of experience in digital publishing and has written and edited for outlets including PCMag and Investopedia.
