Eilmeldung
Newsgather
ZurückFBI Seeks Victims in Steam Malware Crypto Theft Investigation
FBI Seeks Victims in Steam Malware Crypto Theft Investigation
In Entwicklung
CryptoSlategesternCrime2 Min. Lesezeit

FBI Seeks Victims in Steam Malware Crypto Theft Investigation

Auf einen Blick

  • The FBI is seeking potential victims of a malware campaign involving eight Steam games that allegedly infected 8,000 devices, accessed 80 crypto wallets, and stole over $220,000.
  • Zyaire Dontaevious Zamarion Wilkins was arrested in connection with financing and marketing the infected games.

KI-generierte Zusammenfassung

Warum es wichtig ist

The FBI is investigating a malware campaign that used eight Steam games to infect devices and steal cryptocurrency from approximately 80 wallets, totaling at least $220,000.

Schriftgröße

The FBI is seeking potential victims who downloaded eight games named in its Steam malware investigation, a case that shows crypto custody can fail before a wallet ever opens.

In a separate federal complaint reported by Local 10, agents allege an eight-game campaign infected about 8,000 devices, gained unauthorized access to roughly 80 crypto wallets, and stole at least $220,000.

Local 10 reported that agents arrested 21-year-old Zyaire Dontaevious Zamarion Wilkins on July 14 and accused him of financing and procuring malware and helping market the infected games. The complaint describes the venue only as a “popular digital distribution software company.” Wilkins is presumed innocent unless convicted.

The FBI notice lists BlockBlasters, Chemia, Dashverse, DashFPS, Lampy, Lunara, PirateFi and Tokenova, and places the suspected Steam activity between May 2024 and January 2026. Local 10 reported that the complaint dates its broader alleged campaign through February 2026.

Custody begins at software distribution

According to the complaint, the alleged group promoted the games on Discord, Telegram, X, and LinkedIn. Bots identified people with large crypto holdings and sent targeted messages encouraging them to download. Once installed, the malware allegedly captured private data and credentials; the group also discussed tricking victims into authorizing transactions that emptied wallets.

One FBI-listed title shows how a trusted download could expose wallet data. A February 2025 cyber advisory said PirateFi was available on Steam from Feb. 6 to Feb. 12, 2025, and that it contained the Vidar infostealer, which could steal credentials, session cookies, and crypto wallet information.

The attack chain creates two control layers. Valve's onboarding documentation says initial builds are checked for harmful behavior, but its review documentation says approved games can later be updated without another review. Those documents do not establish how the games in this case allegedly bypassed controls, but they show that scrutiny must cover both initial and updated builds.

For wallet users, an official marketplace cannot be the only trust boundary. Keeping wallet secrets and authenticated sessions away from gaming endpoints limits what an infostealer can reach, while deliberately reviewing transaction prompts addresses the separate risk of approving a malicious transfer. Neither control replaces marketplace screening.

The alleged payment trail exposes the reverse side of the attack. Local 10 reported that investigators followed Bitcoin payments from a scheme-linked wallet to Bitrefill, an online service used to buy more than 150 digital gift cards, mostly for Uber Eats. A subpoena to Uber then allegedly connected those cards to an account with deliveries to addresses associated with Wilkins.

Blockchain transparency did not prevent the thefts, but it allegedly preserved a traceable path until the funds touched an identity-linked service. Software distribution is therefore part of custody security before an incident; on-chain records and off-ramp data can become investigative evidence after one.

Worauf zu achten ist

KI-Ausblick — Möglichkeiten, keine Fakten

  • The FBI will continue to identify and contact potential victims of the malware campaign.

    Sehr wahrscheinlich · Innerhalb von Monaten

  • Zyaire Dontaevious Zamarion Wilkins will face legal proceedings related to the alleged malware financing and marketing.

    Sehr wahrscheinlich · Innerhalb von Monaten

Offene Fragen

  • How did the games bypass Valve's initial security controls?
  • What specific private data and credentials were captured?
  • How many victims will be identified by the FBI?

Verwandte Themen

This article was originally published by CryptoSlate.

Ähnliche Meldungen

South Korea Investigates Over 40 Cases of Unfair Crypto Trading, Including Market Manipulation
Crime·gestern

South Korea Investigates Over 40 Cases of Unfair Crypto Trading, Including Market Manipulation

South Korea's financial authorities investigated over 40 cases of unfair crypto trading, including market manipulation and fraudulent activities, in the last two years. Since the Virtual Asset User Protection Act took effect in July 2024, 30 cases were reported to investigative agencies, leading to 25 identified suspects and average unlawful gains of ₩1.4 billion.

Cointelegraph
1 Min. Lesezeit
Mehr zu diesem Themafbi