A federal investigation has revealed a malware campaign using video games to infect more than 8,000 devices and steal cryptocurrency. The operation would have taken place from May 2024 to February 2026, targeting people who had downloaded infected games.
Malware hidden in games
Court documents describe eight games containing malicious code designed to collect passwords, wallet credentials, browser data and other sensitive information. After users installed the securities, the malware reportedly searched for cryptocurrency wallet details. Authorities estimate that around 80 wallets were accessed and emptied.
The games mentioned in the complaint include BlockBlasters, Chemia, Dashverse or DashFPS, Lampy, Lunara, PirateFi and Tokenova. Although investigators did not name the distribution platform, details point to Steam. The FBI is collecting information from anyone who downloads these titles. Security researchers previously reported wallet-stealing malware in PirateFi before Steam removed it.
How did the campaign go?
According to the complaint, the malware was promoted through social networks such as Discord, Telegram, X and LinkedIn. Automated bots have reportedly scanned online communities to identify people with large cryptocurrency holdings. These individuals then received targeted messages encouraging them to install the infected games.
Once on a device, the malware looked for login credentials, wallet keys, and authentication data. Members of the alleged conspiracy then reviewed the stolen files and chose which wallets they could access and empty them.
Digital trail leads to suspect
Prosecutors accuse Zyaire Dontaevious Zamarion Wilkins, 21, of North Lauderdale, Florida, of helping finance and promote the malware operation. Encrypted Signal conversations allegedly show Wilkins using the handle “Sibel.eth” while speaking to the alleged lead developer. These discussions included discussions about purchasing a $10,000 remote access Trojan and planning campaigns to empty victims’ wallets.
Bitcoin transactions linked to the operation ultimately led investigators to Bitrefill, a service that converts cryptocurrencies into gift cards. More than 150 digital gift cards were allegedly purchased with stolen cryptocurrencies, most of them exchanged for Uber Eats. Subpoenaed records linked the deliveries to Wilkins’ college addresses and his home in South Florida.
When officers executed a search warrant, they recovered electronic devices and three cryptocurrency wallet seed phrases, including one linked to a Monero wallet. Transaction records show Wilkins allegedly sent or received approximately $382,000 in cryptocurrency.
He now faces one count of conspiracy to obtain computer information for private financial enrichment. If convicted, he could be sentenced to up to 10 years in prison.
![]()



