A $220,000 Steam Malware Heist Got Solved By An Uber Eats Receipt
- Get link
- X
- Other Apps
Encryption didn't crack this case. Blockchain forensics didn't crack this case. A 21-year-old allegedly stole $220,000 in cryptocurrency by hiding malware inside video games on Steam — and federal agents caught him because he spent the stolen money on food delivery, and had it sent to his own address.
How Did the Malware Reach 8,000 Devices?
The scheme relied on the oldest trick in gaming's malware playbook: make the product look legitimate. Federal investigators say the operation, running from May 2024 to February 2026, published eight infected titles on Steam — among them BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi — that functioned as real, playable games while quietly harvesting data in the background. The listings were promoted across Discord, Telegram, X, and LinkedIn, with bots deployed to identify users who held large cryptocurrency balances and steer them toward the download.
Once installed, the malware pulled private data and saved passwords from the victim's device, giving the operators what they needed to walk straight into linked crypto wallets.
The games didn't need to fool everyone. They just needed to fool the people already sitting on a crypto wallet worth draining.
How Much Did the Scheme Actually Take?
Investigators say the malware reached roughly 8,000 devices and was used to break into about 80 cryptocurrency wallets, draining at least $220,000 total. One suspect's own transaction history reportedly showed over $382,000 in cryptocurrency moving through his accounts across the life of the scheme — a detail that suggests the publicly charged total may be a floor, not a ceiling.
How Did Federal Agents Trace It Back to One Man?
This is the part that turns a routine cybercrime case into a cautionary tale about operational security. Agents followed the stolen Bitcoin to Bitrefill, a gift-card marketplace, where the funds had been used to buy more than 150 gift cards — the overwhelming majority of them for Uber Eats. A subpoena to Uber tied those gift cards to an account with delivery history at two addresses: a home in North Lauderdale, Florida, and a residence tied to the University of West Florida.
Both addresses led back to the same person: Zyaire Dontaevious Zamarion Wilkins, 21, who was arrested on July 14 and charged with conspiracy to obtain information by computer for private financial gain. When agents searched his home, they seized several devices along with three crypto wallet seed phrases, including one for Monero — a currency specifically chosen for its privacy features, undercut entirely by a food delivery habit.
Charge: conspiracy to obtain information by computer for private financial gain
Maximum exposure: up to 10 years in prison if convicted
Games named in the complaint: BlockBlasters, Dashverse, Lampy, Lunara, PirateFi, and three others
Devices infected: approximately 8,000
Wallets breached: approximately 80
What Should Steam Users Do Right Now?
Valve has pulled individual infected titles after the fact, but detection on the platform is reactive, not preventive — researchers have flagged malware in Steam Workshop content as recently as last month. Anyone who holds cryptocurrency and downloads games from third-party or lesser-known Steam listings should treat their wallet credentials as compromised the moment an unfamiliar executable runs on the same machine. Practical steps: keep crypto wallets on a separate, dedicated device; never store seed phrases in plaintext on a gaming PC; and treat any game promoted primarily through Discord bots or unsolicited DMs as a red flag, regardless of how polished the storefront listing looks.
He used Monero for the seed phrases and Bitcoin for Uber Eats. Privacy coin discipline, undone by a lunch order.
The malware was sophisticated enough to fool 8,000 people. The operational security wasn't sophisticated enough to survive a subpoena to a sandwich delivery app.
- Get link
- X
- Other Apps
Comments
Post a Comment