Crypto malware in 8 Steam games steals tokens after leaving trail to Uber Eats deliveries

Investigators reportedly followed Bitcoin-funded gift cards to Uber Eats deliveries, showing both sides of software-mediated wallet risk.

A corrupted PC game installer connects eight suspicious game tiles to a crypto dashboard showing rapidly falling wallet balances.
Image by CryptoSlate
2 min read

Quick Take

  1. The FBI says eight Steam games may have infected about 8,000 devices and stolen at least $220,000 from crypto wallets.
  2. The case shows wallet security can fail at download time, before users ever open their wallets or approve transfers.
  3. Investigators traced Bitcoin-funded gift cards and deliveries, but it remains unclear how the games bypassed Steam's checks.

The FBI is seeking potential victims who downloaded eight games named in its Steam malware investigation, a case that shows crypto custody can fail before a wallet ever opens.

In a separate federal complaint reported by Local 10, agents allege an eight-game campaign infected about 8,000 devices, gained unauthorized access to roughly 80 crypto wallets, and stole at least $220,000.

Local 10 reported that agents arrested 21-year-old Zyaire Dontaevious Zamarion Wilkins on July 14 and accused him of financing and procuring malware and helping market the infected games. The complaint describes the venue only as a “popular digital distribution software company.” Wilkins is presumed innocent unless convicted.

The FBI notice lists BlockBlasters, Chemia, Dashverse, DashFPS, Lampy, Lunara, PirateFi and Tokenova, and places the suspected Steam activity between May 2024 and January 2026. Local 10 reported that the complaint dates its broader alleged campaign through February 2026.

Top-ranked Chrome ‘wallet’ sneakily steals crypto seedphrases
Related Reading

Top-ranked Chrome ‘wallet’ sneakily steals crypto seedphrases

A top-ranked Chrome wallet quietly exfiltrated seed phrases using Sui micro-transactions—and no one noticed until it was too late.
Nov 23, 2025 · Andjela Radmilac
An anthropomorphic Bitcoin detective watches a frightened hardware wallet get pulled toward a hooked Install button beside eight suspicious game tiles.
Cartoon showing an anthropomorphic Bitcoin detective watching a frightened hardware wallet get pulled toward a hooked Install button beside eight suspicious game tiles.

Custody begins at software distribution

According to the complaint, the alleged group promoted the games on Discord, Telegram, X, and LinkedIn. Bots identified people with large crypto holdings and sent targeted messages encouraging them to download. Once installed, the malware allegedly captured private data and credentials; the group also discussed tricking victims into authorizing transactions that emptied wallets.

One FBI-listed title shows how a trusted download could expose wallet data. A February 2025 cyber advisory said PirateFi was available on Steam from Feb. 6 to Feb. 12, 2025, and that it contained the Vidar infostealer, which could steal credentials, session cookies, and crypto wallet information.

CryptoBandits malware lets criminals use your USB drive to access crypto wallets – Microsoft warns
Related Reading

CryptoBandits malware lets criminals use your USB drive to access crypto wallets – Microsoft warns

Microsoft says the CryptoBandits malware uses USB shortcuts, clipboard monitoring, and Tor to target wallet workflows before funds move.
Jun 22, 2026 · Liam 'Akiba' Wright

The attack chain creates two control layers. Valve's onboarding documentation says initial builds are checked for harmful behavior, but its review documentation says approved games can later be updated without another review. Those documents do not establish how the games in this case allegedly bypassed controls, but they show that scrutiny must cover both initial and updated builds.

CryptoSlate Daily Brief

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.

5-minute digest 100k+ readers

Free. No spam. Unsubscribe any time.

You’re subscribed. Welcome aboard.

For wallet users, an official marketplace cannot be the only trust boundary. Keeping wallet secrets and authenticated sessions away from gaming endpoints limits what an infostealer can reach, while deliberately reviewing transaction prompts addresses the separate risk of approving a malicious transfer. Neither control replaces marketplace screening.

Infographic showing the FBI notice’s eight Steam titles and dates, complaint-reported device, wallet and theft totals, the alleged trail through Bitrefill gift cards and Uber Eats, and four potential control points.

The alleged payment trail exposes the reverse side of the attack. Local 10 reported that investigators followed Bitcoin payments from a scheme-linked wallet to Bitrefill, an online service used to buy more than 150 digital gift cards, mostly for Uber Eats. A subpoena to Uber then allegedly connected those cards to an account with deliveries to addresses associated with Wilkins.

One crypto wallet tied to a 20-year-old fraudster processed over $122M before Interpol closed in
Related Reading

One crypto wallet tied to a 20-year-old fraudster processed over $122M before Interpol closed in

The Thailand case shows how cross-chain token swaps can complicate tracing across services, assets and borders.
Jul 12, 2026 · Liam 'Akiba' Wright

Blockchain transparency did not prevent the thefts, but it allegedly preserved a traceable path until the funds touched an identity-linked service. Software distribution is therefore part of custody security before an incident; on-chain records and off-ramp data can become investigative evidence after one.